Re: [clamav-users] More fp's. Now its almost everything that has been zipped.

2016-12-26 Thread Al Varnell
Four have already been dropped and I’m sure there will be more to come. It will go faster if you submit samples to and post a hash back here of the file(s) you uploaded. -Al- On Mon, Dec 26, 2016 at 02:43 AM, Frank Sfalanga Jr. wrote: > > This includes .jar

[clamav-users] More fp's. Now its almost everything that has been zipped.

2016-12-26 Thread Frank Sfalanga Jr .
This includes .jar zips. I am seeing this across dozens of GNU/Linux servers. Other than --exclude=*.jar what else can be done to fix these fp's? === /home/ddale/.gradle/wrapper/dists/gradle-1.10-

Re: [clamav-users] More fp's. Now its almost everything that has been zipped.

2016-12-25 Thread Al Varnell
Here’s another: sigtool --find Win.Trojan.Toa-5370297-0|sigtool --decode-sigs VIRUS NAME: Win.Trojan.Toa-5370297-0 CONTAINER TYPE: CL_TYPE_ZIP CONTAINER SIZE: ANY FILENAME REGEX: ^[a-z0-9\-_]{1,30}_[a-zA-Z0-9\-]{1,15}\.js$ COMPRESSED FILESIZE: ANY UNCOMPRESSED FILESIZE: ANY ENCRYPTION: IGNORED

Re: [clamav-users] More fp's. Now its almost everything that has been zipped.

2016-12-25 Thread Steve Basford
On Sun, December 25, 2016 10:40 am, Al Varnell wrote: > A handful of ClamXav users can confirm the Firefox > omni.ja:Win.Trojan.Toa-5370234-0. It also identified some Adobe products > as infected when run through QA. Firstly, Merry Christmas to all. Onto the FP's... basically they are too

Re: [clamav-users] More fp's. Now its almost everything that has been zipped.

2016-12-25 Thread Al Varnell
A handful of ClamXav users can confirm the Firefox omni.ja:Win.Trojan.Toa-5370234-0. It also identified some Adobe products as infected when run through QA. Reported as FP. -Al- On Dec 24, 2016, at 9:08 PM, Gene Heskett wrote: > Hi all. I am drowning in these for a

[clamav-users] More fp's. Now its almost everything that has been zipped.

2016-12-24 Thread Gene Heskett
Hi all. I am drowning in these for a couple days now. /home/gene/Download/firefox/omni.ja: Win.Trojan.Toa-5370234-0 FOUND /home/gene/Download/7i43.zip: Win.Trojan.Toa-5372190-0 FOUND /home/gene/Download/5i25.zip: Win.Trojan.Toa-5372190-0 FOUND /home/gene/firefox/omni.ja: Win.Trojan.Toa-5370234-0