Re: [clamav-users] False positive - CRDF.Malware-Generic.3661413036.UNOFFICIAL

2014-01-14 Thread Tomala Pawel
ssage- From: clamav-users-boun...@lists.clamav.net [mailto:clamav-users-boun...@lists.clamav.net] On Behalf Of Steve Basford Sent: Tuesday, January 14, 2014 2:32 PM To: ClamAV users ML Subject: Re: [clamav-users] False positive - CRDF.Malware-Generic.3661413036.UNOFFICIAL > Finally I fou

Re: [clamav-users] False positive - CRDF.Malware-Generic.3661413036.UNOFFICIAL

2014-01-14 Thread Steve Basford
> Finally I found where this signature is located > sigwhitelist.ign2:CRDF.Malware-Generic.3661413036 > Does someone know how can I bypass this signature? Which command? Hi Pawel, Just to add, that seeing the signature in sigwhitelist.ign2 means that signature is in your whitelist already.. Ho

Re: [clamav-users] False positive - CRDF.Malware-Generic.3661413036.UNOFFICIAL

2014-01-14 Thread Steve Basford
> Hello, > > I found a problem with false positive malware > CRDF.Malware-Generic.3661413036.UNOFFICIAL. I wanted to decode and bypass > this signature but it looks like this can be an image signature or another > type of signature Hi Pawel CRDF.Malware-Generic.3661413036 was whitelisted/removed

[clamav-users] False positive - CRDF.Malware-Generic.3661413036.UNOFFICIAL

2014-01-14 Thread Tomala Pawel
Hello, I found a problem with false positive malware CRDF.Malware-Generic.3661413036.UNOFFICIAL. I wanted to decode and bypass this signature but it looks like this can be an image signature or another type of signature /usr/local/sbin/clamav-unofficial-sigs.sh -d Input a third-party signatur