[clamav-users] FP Detection / Reclassify Request
Al Varnell
alvarnell at mac.com
Thu Jul 16 23:43:35 UTC 2015
Strange, that’s a very old signature and the size and MD5 for the .text PE portion of the file you uploaded to VirusTotal is an exact match. Wouldn’t be the first time an FP went undetected for that long, but still unusual.
-Al=
On Thu, Jul 16, 2015 at 04:35 PM, Joel Esler (jesler) wrote:
>
> On Jul 16, 2015, at 6:30 PM, Daphne Galme (daphgalm) wrote:
>
> Hi,
>
> I submitted these info several days ago (and someone also did, several weeks ago) for FP.
>
> File MD5: 574e52839d9453a0c0b9c32c11f6157e
> File SHA1: 8530c174909e06ebfde906b94a7c4777aa9dd4a6
>
> I’m still seeing it on VirusTotal though as Win.Trojan.Genpack-445 for ClamAV.
>
> If it’s ok, I’d like to know how long do you process FP request? And once it’s processed, do you publish the result/change in VT right away?
>> Usually it’s pretty fast, but I don’t see the file marked as an FP in the system. I’ve so marked it.
More information about the clamav-users
mailing list