Re: [clamav-users] FP?

2012-10-16 Thread Al Varnell
Gene, Note that the ClamAV folks do not accept the premise of a PUA being an FP. If you go to the FP submission page you will read: "Please do not report false positives for PUA.* signatures because they are automatically rejected" Before they adopted this policy I was able to slip a bug report

[clamav-users] FP?

2012-10-16 Thread Gene Heskett
I have clam doing a scan of my home dir in the wee hours every morning, and I noted that it was burning up first one core, then the next in my phenom just now. So I tailed the log just for S&G: /home/gene/.wine/drive_c/Program Files/Google/Google SketchUp 8/BsSndRpt.exe: PUA.Win32.Packer.SetupE

Re: [clamav-users] Virus in archive

2012-10-16 Thread Alain Zidouemba
Andre, We are taking a look and will let you know as soon as possible. Thanks, - Alain ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

[clamav-users] Virus in archive

2012-10-16 Thread Andre Hübner
Hello, have a problem here. i do a download of file owncloud-4.5.0.tar.bz2 http://owncloud.org/support/install/ when scanning this archive-file by clamscan a virus is found: PHP.Exploit.CVE_2011_4153-2 After unpacking the file and rescanning structure then no virus is found. Whats that? a virus i

Re: [clamav-users] FYI: Mac OS X Users & PHP.Exploit.CVE_2011_4153-2

2012-10-16 Thread Arthur Douwes
I'm getting the same alerts on multiple Linux servers. Mostly on tar.gz files which have been created a long time ago and have not been changed since (no tripwire alerts). When I unpack the tarballs and scan the content I don't get any alter. Al Varnell wrote: > Daily 15462 today contained the