![]() |
| Php.Exploit.CVE |
|
GuitarBob
|
Well, maybe they can render it. Some AVs on Virus Total can spot it, however, so you can verify the file there if you have one.
Most AVs don't do too well at detecting php and other non-Windows PE file malware, except for the commercially-oriented ones. Regards, |
||||||||||||
|
|
|||||||||||||
|
ROCKNROLLKID
|
If you are concerned there may be an exploit within Java, you might want to consider downloading and install Microsoft's EMET tool. It is designed for stopping exploits and it shields Java by default, but you will need to configure it to shield other applications.
You can download it from here: https://www.microsoft.com/en-us/download/details.aspx?id=50766 Please note, if you are on a Windows 10 system, you must use 5.5 or later as Microsoft added full compatibility for Windows 10 in 5.5. |
||||||||||||
|
|
|||||||||||||
|
davebit
|
PHP is a server-side language; so you're saying Chrome is serving up PHP files from a server on my phone? How would that even work? |
||||||||||||||
|
|
|||||||||||||||
|
davebit
|
Main question is whether I should delete these files or quarantine them or something else or just not worry about them.
|
||||||||||||
|
|
|||||||||||||
|
ROCKNROLLKID
|
I don't use Java, so I do not know what those files are. Do what Bob said, submit them to Virustotal and see what other AVs say before deleting them. https://www.virustotal.com/
As Bob said though, some AVs do not detect exploits. ClamAV usually detects exploits because they get the exploit signatures from Snort and now YARA as of version .99. |
||||||||||||
|
|
|||||||||||||
|
davebit
|
VirusTotal found nothing, even ClamAV gives it a green checkmark: https://www.virustotal.com/en/file/0a01e1f33b0dd6af5d71fd26261b97eda1f9da77553704afd0a9d176de733c11/analysis/ Yet ClamWin again said infected: Php.Exploit.CVE_2015_2331-1 FOUND So... is this an infection or what? |
||||||||||||||
|
|
|||||||||||||||
|
GuitarBob
|
If ClamWin spots an exploit and other AVs do not, then it is most likely a false postitive. It is also very unusual to spot several infections of the same type--malware usually tries to be unnoticeable, and this certainly looks noticeable. Another tip: look at the date of a file. If it is more than a month old, lots of AVs should spot it if it is real malware.
Regards, |
||||||||||||
|
|
|||||||||||||
|
davebit
|
So it's a false positive? It's shown up over several updates; now what? |
||||||||||||||
|
|
|||||||||||||||
|
GuitarBob
|
It's funny that ClamWin spots it but Clam AV does not, since ClamWin uses the signatures/scan engine from Clam AV. Are you also using Clam Sentinel? If you are, and if the "infected" file is detected by Clam Sentinel, you can whitelist the file via Files Not Scanned in the Clam Sentinel advanced options.
If you are not using Clam Sentinel, then it will do not good to report the false positive to Clam AV since Clam did not detect an infection on Virus Total. In that case, whitelist the file in ClamWin via the Tools, Preferences, Filters, Exclude Matching Filenames. Sometimes ClamWin can have a false positive if it is using an older version of the Clam AV scan engine than Clam AV. Clam AV is now using version .99.2, while ClamWin is still using version .99.1--it has not yet updated to the current scan engine. This may be the reason for your problem. Regards, |
||||||||||||
|
|
|||||||||||||
| Should we report this somewhere? |
|
goldie
|
Detected this on my PC with fresh virusDB, in Java installcache. Good, bad, maybe? How to proceed... Ignore?
!OK, uploaded the 68mb file to clamav as false positive. fingers crossed.. |
||||||||||||
|
|
|||||||||||||
|
GuitarBob
|
It may take Clam AV a while to correct a false positive signature. Did you check the file with Virus Total? If not, I suggest that you do so. Virus Total will send any false positives to the AV the detects it--this will probably make the signature more important to Clam AV.
Regards, |
||||||||||||
|
|
|||||||||||||
|
goldie
|
"This file was last analysed by VirusTotal on 2016-09-10 08:49:14 UTC (15 hours, 36 minutes ago) it was first analysed by VirusTotal on 2014-10-28 10:57:59 UTC. Detection ratio: 0/50"
Weird... |
||||||||||||
|
|
|||||||||||||
|
ROCKNROLLKID
|
Is your ClamWin up-to-date? Do a manual update to make sure. I am pretty this was fixed some time ago.
|
||||||||||||
|
|
|||||||||||||
|
goldie
|
Downloaded and installed CW just yesterday, also checked that DB is up to date.
|
||||||||||||
|
|
|||||||||||||
| Php.Exploit.CVE |
|
||
|
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.


