Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

" is infected with Suspicious"

This is misleading. It seems that valid files are labeled as being " infected with Suspicious" . Is this just because we have a Fortigate 60 & anything over 10 MB cannot be scanned &, therefore, is flagged as " suspicious" ??? A lot of Windows update files are flagged this way. It is like seeing a lot of false positives in IDS reporting... Regards, Will
7 REPLIES 7
vanc
New Contributor II

If you don' t want to see a lot of Suspicious warnings, you can disable Heuristics AV scanning.
Not applicable

If you don' t want to see a lot of Suspicious warnings, you can disable Heuristics AV scanning.
Thanks. I' ll look into this option! Regards, Will
gbaharoff
New Contributor

But the question still remains as to why is it happening? Why is it just a notice and not a warning? I wouldn' t recommend disabling Heuristics AV scanning, so does anyone know why this is occuring and what it means.
Greg Baharoff Fortinet Certified System Engineer MTBW Services, Inc. 327 E Ridgeville Blvd 154 Mount Airy MD 21771 301-829-5925
Greg Baharoff Fortinet Certified System Engineer MTBW Services, Inc. 327 E Ridgeville Blvd 154 Mount Airy MD 21771 301-829-5925
Not applicable

I have not disabled Heuristics AV scanning & would also like to the reason behind these notices. I just don' t like seeing notices that something is infected with " suspicious" when it is a legitmate file, not infected with anything. Perhaps that is why these are flagged at the " notice" level? Might as well read: " Notice" false positive identified... Will
Not applicable

I face the same thing too. Have scanned the file with few virus scanners and the result showed no infected files, yet fortigate shows it' s infected with Suspicious. If this is a false alarm, then when there is a file really infected with the virus we will all suffer. Anyone has any clue?
Not applicable

I' m not sure this answers a question. But, it seems that ANY executable, zip, cab file is flagged as suspicious. I haven' t tested that theory yet. But it looks possible.
mickstrick_FTNT

Suspicious Files are Windows Portable Executable files that make a high amount of changes to the windows registry. AV Heuristic scanning detects these files. The option for AV scanning are Pass/Block/Disable. Pass will scan for suspicious file forward the file, make a log entry, and quarantine the file if hdd is available; block will not forward the file, make a log entry, and quarantine the file if hdd is available; disable switches this scanning off. #config antivirus heuristic set mode pass/block/disable end
Labels
Top Kudoed Authors