On 7/23/2015 1:15 PM, JD Ackle wrote:
>
> On Wed, 7/22/15, G.W. Haywood wrote:
>
> Subject: Re: [clamav-users] How to clean infection by
> Docx.Exploit.CVE_2015_1770
> To: clamav-users@lists.clamav.net
> Date: Wednesday
Ackle wrote:
>
> On Wed, 7/22/15, G.W. Haywood wrote:
>
> Subject: Re: [clamav-users] How to clean infection by
> Docx.Exploit.CVE_2015_1770
> To: clamav-users@lists.clamav.net
> Date: Wednesday, July 22, 2015, 5:45 PM
>
> Hi there,
>
> On Wed, 22 Jul 2015, J
On Wed, 7/22/15, G.W. Haywood wrote:
Subject: Re: [clamav-users] How to clean infection by
Docx.Exploit.CVE_2015_1770
To: clamav-users@lists.clamav.net
Date: Wednesday, July 22, 2015, 5:45 PM
Hi there,
On Wed, 22 Jul 2015, JD Ackle wrote
On Jul 22, 2015, at 9:38 AM, JD Ackle wrote:
> On Wed, 7/22/15, Noel Jones wrote:
>> I would suspect a false positive if a MS Office
>> document virus is
>> reported in anything other
>> than an MS Office document.
> Thank you for the reply, Noel.
> Should I submit the concerrning files to the Fa
Hi there,
On Wed, 22 Jul 2015, JD Ackle wrote:
I would like to know how can I remove Docx.Exploit.CVE_2015_1770
from Windows/System32/config/SOFTWARE
As others have said, you might have found a false positive. You need to
find out if that is the case or not before you do anything else.
If i
On Wed, 7/22/15, Noel Jones wrote:
I would suspect a false positive if a MS Office
document virus is
reported in anything other
than an MS Office document.
Thank you for the reply, Noel.
Should I submit the concerrning files to the False Posit
On 7/22/2015 7:23 AM, JD Ackle wrote:
> Hello,
>
> Currently, ClamAV run from Linux reports Docx.Exploit.CVE_2015_1770 in my
> Windows 8.1 install, in files:
> - pageFile.sys
> - Windows/System32/config/SOFTWARE (a piece of the Windows registry)
>
> If I understand it correctly, pageFile.sys wor
Hello,
Currently, ClamAV run from Linux reports Docx.Exploit.CVE_2015_1770 in my
Windows 8.1 install, in files:
- pageFile.sys
- Windows/System32/config/SOFTWARE (a piece of the Windows registry)
If I understand it correctly, pageFile.sys works much like a Linux swap, hence
basically containing