[clamav-users] False positive

Groach groachmail-stopspammingme at yahoo.com
Sat Aug 4 07:00:55 UTC 2018


I don't know.  I am an administrator of the server following the procedure given by your website (ie, reporting the fp to your website) and now currently sat in a field on a (supposed) vacation. I  don't have the time our will to research extra tools or install software to do further research beyond that of the instructions of use in the clamav documentation.  I can tell you that the fp happened again last night: 

winscp551.zip: Win.Trojan.Generic-6629296-0 FOUND 


(I won't bother uploading the fp to the website again).

Does the report help? 


On 3 August 2018 14:31:28 BST, "Joel Esler (jesler)" <jesler at cisco.com> wrote:
>What is the md5?
>
>On Aug 3, 2018, at 2:36 AM, Groach
><groachmail-stopspammingme at yahoo.com<mailto:groachmail-stopspammingme at yahoo.com>>
>wrote:
>
>An overnight scan has just pulled out a false positive on a program. 
>Its against Winscp (file transfer program) that is a genuine download
>and been used for years.  It's not the first time it has been hit as a
>FP and took several attempts previously to get it whitelisted before
>but now its back as an FP detection again.
>
>Ive uploaded/reported against http://www.clamav.net/reports/fp.
>
>Is there a chance of it being picked up and and actioned?  If so, how
>long will it take?
>
>Thanks
>_______________________________________________
>clamav-users mailing list
>clamav-users at lists.clamav.net<mailto:clamav-users at lists.clamav.net>
>http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users
>
>
>Help us build a comprehensive ClamAV guide:
>https://github.com/vrtadmin/clamav-faq
>
>http://www.clamav.net/contact.html#ml
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.clamav.net/pipermail/clamav-users/attachments/20180804/72ebcd93/attachment.htm>


More information about the clamav-users mailing list