Mailing List Archive

Registering a false positive
Hi

I have just installed ClamAV with Immunet and have run a full scan on my machine. It picked up a false positive on file Off2k3\extras\math type 5.1\mtype_v5_1_keygen.exe. When I tried reporting this to Clam the report was not accepted, the error message displayed was:

"This file is not detected by ClamAV. Please update your CVD database before reporting false-positives. If you are using third-party databases/unofficial signatures, please contact the author of the signature. We can only process false-positives generated by ClamAV Official signatures."

As far as I am aware my CVD database is completely up to date and I am certainly not using a 3rd party database so I can only assume that either there is a problem with the report or I have done something wrong when submitting it. I restored the file from quarantine and attached that to the form, was that correct?

Any advice would be welcome.

Ian




Ian Homewood Group IT Manager

Plantec Holdings Ltd | Calderhurst House | 143-149 Bispham Road | Southport | PR9 7BL
T: +44 (0)1704 508 024 X : 1216
E: ianh@plantecholdings.co.uk
W: www.PlantecHoldings.co.uk<http://www.plantecholdings.co.uk/>





________________________________
If you are not the intended recipient of this confidential transmission, it may be unlawful for you to use the information it contains in ANY way. No de facto endorsement, or contractual liability is intended or should be construed from any statement herein. Similarly no liability can be accepted by us for the content (including any attachments) of this message. We perform up-to-date screening on all electronic communication but the responsibility for virus detection and removal remains with the receiver. Replies and all incoming mail is scanned by keyword technology in addition to virus detection to eliminate spam.
Plantec Holdings Ltd - Co Number 05512544 - Registered Office - Sumner House, St Thomas's Rd, Chorley, PR7 1HP
_______________________________________________
http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-win32
Re: Registering a false positive [ In reply to ]
On Dec 18, 2012, at 3:46 AM, Ian Homewood <IanH@plantecholdings.co.uk> wrote:

> Hi
>
> I have just installed ClamAV with Immunet and have run a full scan on my machine. It picked up a false positive on file Off2k3\extras\math type 5.1\mtype_v5_1_keygen.exe. When I tried reporting this to Clam the report was not accepted, the error message displayed was:
>
> "This file is not detected by ClamAV. Please update your CVD database before reporting false-positives. If you are using third-party databases/unofficial signatures, please contact the author of the signature. We can only process false-positives generated by ClamAV Official signatures."
>
> As far as I am aware my CVD database is completely up to date and I am certainly not using a 3rd party database so I can only assume that either there is a problem with the report or I have done something wrong when submitting it. I restored the file from quarantine and attached that to the form, was that correct?
>
> Any advice would be welcome.

What is the alert it generated?

--
Joel Esler
Senior Research Engineer, VRT
OpenSource Community Manager
Sourcefire
_______________________________________________
http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-win32
Re: Registering a false positive [ In reply to ]
The alert was that it had detected 'MalwareF.Trojan-tpd' and had quarantined the file.



Ian Homewood Group IT Manager

Plantec Holdings Ltd | Calderhurst House | 143-149 Bispham Road | Southport | PR9 7BL
T: +44 (0)1704 508 024 X : 1216
E: ianh@plantecholdings.co.uk
W: www.PlantecHoldings.co.uk



-----Original Message-----
From: clamav-win32-bounces@lists.clamav.net [mailto:clamav-win32-bounces@lists.clamav.net] On Behalf Of Joel Esler
Sent: 18 December 2012 16:54
To: clamav-win32@lists.clamav.net
Subject: Re: [clamav-win32] Registering a false positive

On Dec 18, 2012, at 3:46 AM, Ian Homewood <IanH@plantecholdings.co.uk> wrote:

> Hi
>
> I have just installed ClamAV with Immunet and have run a full scan on my machine. It picked up a false positive on file Off2k3\extras\math type 5.1\mtype_v5_1_keygen.exe. When I tried reporting this to Clam the report was not accepted, the error message displayed was:
>
> "This file is not detected by ClamAV. Please update your CVD database before reporting false-positives. If you are using third-party databases/unofficial signatures, please contact the author of the signature. We can only process false-positives generated by ClamAV Official signatures."
>
> As far as I am aware my CVD database is completely up to date and I am certainly not using a 3rd party database so I can only assume that either there is a problem with the report or I have done something wrong when submitting it. I restored the file from quarantine and attached that to the form, was that correct?
>
> Any advice would be welcome.

What is the alert it generated?

--
Joel Esler
Senior Research Engineer, VRT
OpenSource Community Manager
Sourcefire
_______________________________________________
http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-win32

If you are not the intended recipient of this confidential transmission, it may be unlawful for you to use the information it contains in ANY way. No de facto endorsement, or contractual liability is intended or should be construed from any statement herein. Similarly no liability can be accepted by us for the content (including any attachments) of this message. We perform up-to-date screening on all electronic communication but the responsibility for virus detection and removal remains with the receiver. Replies and all incoming mail is scanned by keyword technology in addition to virus detection to eliminate spam.
Plantec Holdings Ltd - Co Number 05512544 - Registered Office - Sumner House, St Thomas's Rd, Chorley, PR7 1HP
_______________________________________________
http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-win32