Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
miciti
Contributor

FortiClient Malware Protection quarantined a vmware workstation file - false positive?

Hi everyone,

 

yesterday FortiClient Malware Protection decided to flag a vmdk (vmware drive file) as malicious with threat "JS/Phish.A9BF!tr". 

 

Is this clearly a false positive? Or is FortiClient able to analyze virtual drive files in detail?

2 REPLIES 2
sharmar
Staff
Staff

Hello @miciti 

 

You can check the file is false postive or not via using Fortiguard online scanner :

https://www.fortiguard.com/faq/onlinescanner

 

You can also search it through file hash. 

 

Regards

miciti
Contributor

@sharmar 

Hi, 

the vmdk (virtual machine drive file) is about 60 GB in size.

 

That is a whole virtual computer stored in this single file - that is why I was wondering if FortiClient even has the capatiblity to analyze this kind of files. 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors