Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: ClamAV: win32

Four false positives

 

 

ClamAV win32 RSS feed   Index | Next | Previous | View Threaded


Tim.Clarke at manifest

Feb 18, 2006, 4:45 AM

Post #1 of 3 (2411 views)
Permalink
Four false positives

Suddenly had four false positives from clamav last night. These are the
first false positives I've had.

Signatures:
main.cvd is up to date (version: 35, sigs: 41649, f-level: 6, builder:
tkojm)
daily.cvd is up to date (version: 1292, sigs: 3717, f-level: 7, builder:
diego)

Clamwin 0.88 on fully patched Windows XP Pro SP2

Log:

C:\Program Files\Common Files\GTK\2.0\uninst.exe:
Trojan.Clicker.Small-100 FOUND
C:\Program Files\Common Files\GTK\2.0\uninst.exe: moved to 'C:\Documents
and Settings\All Users\.clamwin\quarantine\\uninst.exe'
C:\Program Files\Gaim\gaim-uninst.exe: Trojan.Clicker.Small-100 FOUND
C:\Program Files\Gaim\gaim-uninst.exe: moved to 'C:\Documents and
Settings\All Users\.clamwin\quarantine\\gaim-uninst.exe'
C:\Resource\Applications\ethereal-setup-0.10.12.exe:
Trojan.Clicker.Small-100 FOUND
C:\Resource\Applications\ethereal-setup-0.10.12.exe: moved to
'C:\Documents and Settings\All
Users\.clamwin\quarantine\\ethereal-setup-0.10.12.exe'
C:\Resource\Applications\gaim-1.5.0.exe: Trojan.Clicker.Small-100 FOUND
C:\Resource\Applications\gaim-1.5.0.exe: moved to 'C:\Documents and
Settings\All
Users\.clamwin\quarantine\\gaim-1.5.0.exe'clamav-win32 [at] lists

Any ideas anyone?

Tim Clarke
_______________________________________________
http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-win32


tmetro+clamwin32 at gmail

Feb 18, 2006, 7:56 AM

Post #2 of 3 (2307 views)
Permalink
Re: Four false positives [In reply to]

Tim Clarke wrote:
> Suddenly had four false positives from clamav last night.
...
> ...\Common Files\GTK\2.0\uninst.exe: Trojan.Clicker.Small-100 FOUND
> ...\Gaim\gaim-uninst.exe: Trojan.Clicker.Small-100 FOUND
> ...\ethereal-setup-0.10.12.exe: Trojan.Clicker.Small-100 FOUND
> ...\gaim-1.5.0.exe: Trojan.Clicker.Small-100 FOUND
>
> Any ideas anyone?

This may not shed much light on the situation, but given that those are
all installers for open source apps., they're probably all instances of
the nullsoft installer (http://nsis.sourceforge.net/), and thus you're
probably seeing one false positive. You could confirm this by running
ClamAV on another machine, first proving that it's clean, then
installing one of these apps. from a fresh downloaded from a trusted source.

No mention on the nullsoft site of a known false positive against their
installer, but if that was a newly added signature, it may be too soon.
Might be worth doing a Google Groups search.

-Tom

--
Tom Metro
Venture Logic, Newton, MA, USA
"Enterprise solutions through open source."
Professional Profile: http://tmetro.venturelogic.com/
_______________________________________________
http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-win32


Tim.Clarke at manifest

Feb 19, 2006, 2:21 PM

Post #3 of 3 (2283 views)
Permalink
RE: Four false positives [In reply to]

Great insight Tom, thanks.
I'll post one on the Clamav false positives page and research some more.

Tim Clarke

-----Original Message-----
From: clamav-win32-bounces [at] lists
[mailto:clamav-win32-bounces [at] lists] On Behalf Of Tom Metro
Sent: 18 February 2006 15:57
To: clamav-win32 [at] lists
Subject: Re: [clamav-win32] Four false positives

Tim Clarke wrote:
> Suddenly had four false positives from clamav last night.
...
> ...\Common Files\GTK\2.0\uninst.exe: Trojan.Clicker.Small-100 FOUND
> ...\Gaim\gaim-uninst.exe: Trojan.Clicker.Small-100 FOUND
> ...\ethereal-setup-0.10.12.exe: Trojan.Clicker.Small-100 FOUND
> ...\gaim-1.5.0.exe: Trojan.Clicker.Small-100 FOUND
>
> Any ideas anyone?

This may not shed much light on the situation, but given that those are
all installers for open source apps., they're probably all instances of
the nullsoft installer (http://nsis.sourceforge.net/), and thus you're
probably seeing one false positive. You could confirm this by running
ClamAV on another machine, first proving that it's clean, then
installing one of these apps. from a fresh downloaded from a trusted
source.

No mention on the nullsoft site of a known false positive against their
installer, but if that was a newly added signature, it may be too soon.
Might be worth doing a Google Groups search.

-Tom

--
Tom Metro
Venture Logic, Newton, MA, USA
"Enterprise solutions through open source."
Professional Profile: http://tmetro.venturelogic.com/
_______________________________________________
http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-win32

_______________________________________________
http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-win32

ClamAV win32 RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.