Re: [clamav-users] False Positive not being corrected

2013-12-12 Thread mcmurchy1917-clamav
I too reported the false positive. I supplied the offending file was that correct? I have 18 other different files that report the same exploit like so - 559 /root$ freshclam ClamAV update process started at Thu Dec 12 08:54:47 2013 main.cvd is up to date (version: 55, sigs: 2424225, f-level:

Re: [clamav-users] False Positive not being corrected

2013-12-12 Thread Al Varnell
On Wed, Dec 11, 2013 at 06:56 AM, Douglas Goddard wrote: When was your last signature update? Could you run freshclam and then rescan? That version of the bytecode signature has been dropped and should no longer be alerting, the current version is BC.Exploit.CVE_2013_3906-3. If that version is

Re: [clamav-users] False Positive not being corrected

2013-12-12 Thread Douglas Goddard
It was an oversight on our end. Thank you for being persistent. The offending bytecode has been dropped and the fixed code has been published. On Thu, Dec 12, 2013 at 4:22 AM, Al Varnell alvarn...@mac.com wrote: On Wed, Dec 11, 2013 at 06:56 AM, Douglas Goddard wrote: When was your last

Re: [clamav-users] False Positive not being corrected

2013-12-12 Thread Andrew Carter
Hi Douglas, I have tested the file now and it is testing as clean. Thank you for resolving this. Kind regards, Andrew On 13/12/13 11:40, Douglas Goddard wrote: It was an oversight on our end. Thank you for being persistent. The offending bytecode has been dropped and the fixed code has

Re: [clamav-users] False Positive not being corrected

2013-12-12 Thread Alain Zidouemba
Thanks Andrew. - Alain On Thu, Dec 12, 2013 at 6:01 PM, Andrew Carter andrew.car...@smxemail.comwrote: Hi Douglas, I have tested the file now and it is testing as clean. Thank you for resolving this. Kind regards, Andrew On 13/12/13 11:40, Douglas Goddard wrote: It was an oversight

[clamav-users] False Positive not being corrected

2013-12-11 Thread Andrew Carter
Hi, I have submitted a file several times (email and Excel attachment) to be corrected at http://www.clamav.net/lang/en/sendvirus/submit-fp/ however this is still being marked as a virus. In testing it against other scanners Clam is the only one picking it up as a virus. It is coming up

Re: [clamav-users] False Positive not being corrected

2013-12-11 Thread Al Varnell
On Wed, Dec 11, 2013 at 02:19 AM, Andrew Carter wrote: I have submitted a file several times (email and Excel attachment) to be corrected at http://www.clamav.net/lang/en/sendvirus/submit-fp/ however this is still being marked as a virus. In testing it against other scanners Clam is the

Re: [clamav-users] False Positive not being corrected

2013-12-11 Thread Joel Esler (jesler)
On Dec 11, 2013, at 6:12 AM, Al Varnell alvarn...@mac.commailto:alvarn...@mac.com wrote: On Wed, Dec 11, 2013 at 02:19 AM, Andrew Carter wrote: I have submitted a file several times (email and Excel attachment) to be corrected at http://www.clamav.net/lang/en/sendvirus/submit-fp/ however this

Re: [clamav-users] False Positive not being corrected

2013-12-11 Thread Douglas Goddard
When was your last signature update? Could you run freshclam and then rescan? That version of the bytecode signature has been dropped and should no longer be alerting, the current version is BC.Exploit.CVE_2013_3906-3. If that version is still alerting after an update then we will do some deeper