False positive?

Discussion in 'WormGuard' started by Q Section, Jun 12, 2003.

Thread Status:
Not open for further replies.
  1. Q Section

    Q Section Registered Member

    Joined:
    Feb 5, 2003
    Posts:
    771
    Location:
    Headquarters - London & Field Offices -Worldwide
    Hello Everyone
    When we use Explorer and look in our Outpost Firewall ini file WormGuard shows the folowing:

    Risk Assessment: Medium

    *> Suspicious strings detected.
    WormGuard has found a few strings in this file that are suspicious.

    *> Contains suspicious string: virus
    LINE=......


    We have done a current scan with an up-to-date NOD32 and TDS3 but they show nothing out of the ordinary. We believe this is a false positive. We will be happy to send the small file (8K) but our zip program seems only to be able to unzip and not zip.
     
  2. Paul Wilders

    Paul Wilders Administrator

    Joined:
    Jul 1, 2001
    Posts:
    12,472
    Location:
    The Netherlands
    Hi QSection,

    No it isn't. This is the way WG functions by design; detecting - amongst others - suspicious strings.

    In case you haven't done so, configure WG with the option to "safely view..." and press that button, and the contents of the file will be shown.

    regards.

    paul
     
Thread Status:
Not open for further replies.