Description
Sometimes new Virus Definitions will detect legitimate files as a virus. These are called "False Positives".
For further information on how to recover if this false positive is causing issues in your environment, see this article.
In order for the definition to be adjusted, the "False Positive" must be reported and sent to us immediately.
How to report and send a False Positive
If there is a file(s) that are being identified as a False Positive, before submitting the file(s) for analysis make sure that all infected machines are scanning with the latest definition files. Once all machines have been scanned with the latest definition files then follow the steps outlined below to have the infected files analyzed.
For further information on how to ensure your clients are using the latest Antivirus pattern files, see this article.
Open a Management Suite console
Go to Tools | Security | Security and Patch Manager
Expand Settings
Click on LANDesk Antivirus
Double click on the Antivirus settings the client is using.
Click on Real-Time Protection
Check the Allow user to disable Realtime scanning for up to ___ minutes option
Click on Quarantine/Backup
Check "Allow user to restore suspicious objects" and "Allow user to restore infected objects and risky software"
Click Ok
On the client Click Start | Run
Type Vulscan /changesettings /showui, this will download the setting changes you made.
Click Start | Run | LANDesk Management | LANDesk Antivirus
Click Disable next to Real-Time Protection
Click View details next to Quarantine or Backup depending on where the file is located.
Take note of the original location.
Highlight the file.
Click Restore.
Click Restore File.
Collect the file(s) from the Original Location and compile them into a password protected .ZIP file.
- Compile the "infected" file(s) into a password protected .ZIP file. Name the file "FalsePositive(UniqueName).zip". (Where "UniqueName" is a filename of your choosing).
IMPORTANT! The file must be password protected with a password of "infected". The compression type must be a .ZIP.
Other compression types will not be accepted.The file should not be a self-extracting zip file.
Place the file on LANDESK's site: http://avdrop.landesk.com/
Contact LANDESK Support and open a Support Incident and provide the name of the sample file uploaded to the ftp site. (Case sensitive)
Revert the changes made in steps 1-10.
- Current virus definition release activity can be viewed here: http://www.kaspersky.com/viruswatchlite?
Note: Once the antivirus pattern files are updated to correct the false positive, the files within quarantine will be restored to their original locations.