CFF KB - Carrz-Fox-Fire Promotions Knowledge Base

CFF KB is all about 1 thing: The Sharing of Knowledge and the Power we gain from it.
  • Breadrumbs:
  • Suspect.Bredozip-zippwd-3 FOUND

  • CFF Knowledge Base - Share With Facebook CFF Knowledge Base - Share on Twitter CFF Knowledge Base - Share on Reddit CFF Knowledge Base - Share on Digg It CFF Knowledge Base - Share on Stumble Upon It CFF Knowledge Base - Share on Delicious
    Share With Friends (Updated 6-8-2010)
  • Article ID:
    168
  • Date Created
    Friday, January 27, 2012
  • This Article Has been Viewed
    3083 times
  • Short Desc
    When ClamWin scans zip archives that have facebook type of names, the scanner may give a false positive alert on the file(s). Renaming the files, can sometimes fix this issue.
  • Details
    When ClamWin scans certain zip files that contain Facebook names files within the zip file, a False Positive alarm is created, thinking that the zip file has an enclosed virus named: Suspect.Bredozip-zippwd-3

    This is tested with files that are included in the Facebook Wallscript
    facebook_wall_script.php

     

    Scan Started Fri Jan 27 08:03:22 2012
    -------------------------------------------------------------------------------


    D:\Tutorials\FB_Comments\3\php\facebook_WallScript_2.zip: Suspect.Bredozip-zippwd-3 FOUND
    ----------- SCAN SUMMARY -----------
    Known viruses: 1121810
    Engine version: 0.97.3
    Scanned directories: 0
    Scanned files: 1
    Infected files: 1

    Data scanned: 0.01 MB
    Data read: 0.01 MB (ratio 1.00:1)
    Time: 19.879 sec (0 m 19 s)

    --------------------------------------
    Completed
    --------------------------------------
  • Recreate Issue
    To recreate this issue.

    ClamWin assumes that the file located within the [facebook_WallScript_2.zip]
    Is a virus, when it is not.
    The file is: [facebook_wall_script.php]
    With this file being inside of the zip archive, ClamWin will continue to assume that it is an affected file.
  • Resolve Issue
    To resolve this issue.
    Unzip the file that are in the zip archive.
    Rename the facebook_wall_script.php to wall_script.php
    Create a new archive with the renamed file inside, and delete the original zip file.