[clamav-users] False positive
Groach
groachmail-stopspammingme at yahoo.com
Sat Aug 4 07:00:55 UTC 2018
I don't know. I am an administrator of the server following the procedure given by your website (ie, reporting the fp to your website) and now currently sat in a field on a (supposed) vacation. I don't have the time our will to research extra tools or install software to do further research beyond that of the instructions of use in the clamav documentation. I can tell you that the fp happened again last night:
winscp551.zip: Win.Trojan.Generic-6629296-0 FOUND
(I won't bother uploading the fp to the website again).
Does the report help?
On 3 August 2018 14:31:28 BST, "Joel Esler (jesler)" <jesler at cisco.com> wrote:
>What is the md5?
>
>On Aug 3, 2018, at 2:36 AM, Groach
><groachmail-stopspammingme at yahoo.com<mailto:groachmail-stopspammingme at yahoo.com>>
>wrote:
>
>An overnight scan has just pulled out a false positive on a program.
>Its against Winscp (file transfer program) that is a genuine download
>and been used for years. It's not the first time it has been hit as a
>FP and took several attempts previously to get it whitelisted before
>but now its back as an FP detection again.
>
>Ive uploaded/reported against http://www.clamav.net/reports/fp.
>
>Is there a chance of it being picked up and and actioned? If so, how
>long will it take?
>
>Thanks
>_______________________________________________
>clamav-users mailing list
>clamav-users at lists.clamav.net<mailto:clamav-users at lists.clamav.net>
>http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users
>
>
>Help us build a comprehensive ClamAV guide:
>https://github.com/vrtadmin/clamav-faq
>
>http://www.clamav.net/contact.html#ml
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.clamav.net/pipermail/clamav-users/attachments/20180804/72ebcd93/attachment.htm>
More information about the clamav-users
mailing list