Re: [clamav-users] How to clean infection by Docx.Exploit.CVE_2015_1770

2015-07-23 Thread Noel Jones
On 7/23/2015 1:15 PM, JD Ackle wrote: > > On Wed, 7/22/15, G.W. Haywood wrote: > > Subject: Re: [clamav-users] How to clean infection by > Docx.Exploit.CVE_2015_1770 > To: clamav-users@lists.clamav.net > Date: Wednesday

Re: [clamav-users] How to clean infection by Docx.Exploit.CVE_2015_1770

2015-07-23 Thread Al Varnell
Ackle wrote: > > On Wed, 7/22/15, G.W. Haywood wrote: > > Subject: Re: [clamav-users] How to clean infection by > Docx.Exploit.CVE_2015_1770 > To: clamav-users@lists.clamav.net > Date: Wednesday, July 22, 2015, 5:45 PM > > Hi there, > > On Wed, 22 Jul 2015, J

Re: [clamav-users] How to clean infection by Docx.Exploit.CVE_2015_1770

2015-07-23 Thread JD Ackle
On Wed, 7/22/15, G.W. Haywood wrote: Subject: Re: [clamav-users] How to clean infection by Docx.Exploit.CVE_2015_1770 To: clamav-users@lists.clamav.net Date: Wednesday, July 22, 2015, 5:45 PM Hi there, On Wed, 22 Jul 2015, JD Ackle wrote

Re: [clamav-users] How to clean infection by Docx.Exploit.CVE_2015_1770

2015-07-22 Thread Al Varnell
On Jul 22, 2015, at 9:38 AM, JD Ackle wrote: > On Wed, 7/22/15, Noel Jones wrote: >> I would suspect a false positive if a MS Office >> document virus is >> reported in anything other >> than an MS Office document. > Thank you for the reply, Noel. > Should I submit the concerrning files to the Fa

Re: [clamav-users] How to clean infection by Docx.Exploit.CVE_2015_1770

2015-07-22 Thread G.W. Haywood
Hi there, On Wed, 22 Jul 2015, JD Ackle wrote: I would like to know how can I remove Docx.Exploit.CVE_2015_1770 from Windows/System32/config/SOFTWARE As others have said, you might have found a false positive. You need to find out if that is the case or not before you do anything else. If i

Re: [clamav-users] How to clean infection by Docx.Exploit.CVE_2015_1770

2015-07-22 Thread JD Ackle
On Wed, 7/22/15, Noel Jones wrote: I would suspect a false positive if a MS Office document virus is reported in anything other than an MS Office document. Thank you for the reply, Noel. Should I submit the concerrning files to the False Posit

Re: [clamav-users] How to clean infection by Docx.Exploit.CVE_2015_1770

2015-07-22 Thread Noel Jones
On 7/22/2015 7:23 AM, JD Ackle wrote: > Hello, > > Currently, ClamAV run from Linux reports Docx.Exploit.CVE_2015_1770 in my > Windows 8.1 install, in files: > - pageFile.sys > - Windows/System32/config/SOFTWARE (a piece of the Windows registry) > > If I understand it correctly, pageFile.sys wor

[clamav-users] How to clean infection by Docx.Exploit.CVE_2015_1770

2015-07-22 Thread JD Ackle
Hello, Currently, ClamAV run from Linux reports Docx.Exploit.CVE_2015_1770 in my Windows 8.1 install, in files: - pageFile.sys - Windows/System32/config/SOFTWARE (a piece of the Windows registry) If I understand it correctly, pageFile.sys works much like a Linux swap, hence basically containing