![]() |
![]() | Exploit.Linux.Gv found | ![]() |
![]() |
![]() | ![]() |
Matthew
![]() |
![]() |
Hallo!
My Clamwin 0.88.5 also found this malware tonight: D:\BROWSER\Flock\flock\gm.exe: Exploit.Linux.Gv FOUND In Online-Scan on https://www.virustotal.com/en/indexf.html https://www.virustotal.com/en/indexf.html the Virus-Scanners didn`t find anything, only the ClamWin-scanner did. Greetings from Matthew |
|||||||||||
|
![]() |
![]() | ![]() |
sherpya
![]() |
![]() |
it seams to be a false positive, report it directly to clamav team https://www.clamav.net/sendvirus.html https://www.clamav.net/sendvirus.html
|
|||||||||||
|
![]() |
![]() | RE: Exploit.Linux.Gv | ![]() |
wvpv
![]() |
![]() |
Got the same thing. I think it's a false positive.
c:\Program Files\Macromedia\Flash 8\GhostScript.dll: Exploit.Linux.Gv FOUND c:\WINDOWS\Downloaded Installations\Macromedia Flash 8\Data1.cab: Exploit.Linux.Gv FOUND I'm runing 0.88.5 with with the latest defs. |
|||||||||||
|
![]() |
![]() | ![]() |
gkb
![]() |
![]() |
Same problem with 0.88.5 this morning :
C:\CutePrinter\Ghostscript\gsdll32.dll: Exploit.Linux.Gv FOUND ----------------- NOTE: I also have 2 other computer with ClamWin, but version 0.88.4 or older, and with the same CutePrinter program installed. On these computer, ClamWin doesn't detect a falsfe viruse there ??? Very strange ! ClamWin use the same Virus Database for any version... |
|||||||||||
|
![]() |
![]() | ![]() |
srosa
![]() |
![]() |
We are using clamwin 0.88.5 and we are receiving reports of this same exploit:
C:\Program Files\Ghostgum\gsview\gsview32.exe: Exploit.Linux.Gv FOUND C:\Program Files\Ghostgum\gsview\epstool.exe: Exploit.Linux.Gv FOUND We have scans and virus definition updates scheduled to run daily early in the morning (1 am EST). After trying to uninstall and re-install the application to no avail, I updated our virus definitions and tried the scan again. Voila! The original virus reported was gone. |
|||||||||||
|
![]() |
![]() | ![]() |
sherpya
![]() |
![]() |
I'm just thinking that Exploit.Linux.Gv signature in clamav db needs really to be revised and/or removed
![]() |
|||||||||||
|
![]() |
![]() | And another one... | ![]() |
Gremnebulin
![]() |
![]() |
I:\installers\lnx_pkges\common_src\ghostscript-8.54\src\dscparse.c: Exploit.Linux.Gv FOUND
I:\installers\lnx_pkges\common_src\ghostscript-8.54\src\dscparse.h: Exploit.Linux.Gv FOUND |
|||||||||||
|
![]() |
![]() | ![]() |
Matthew
![]() |
![]() |
Some minutes ago I did a new scan with my own updated ClamWin 0.88.5 and it didn`t find anything. I did a new scan at virustotal and this time only the Ikarus-Scanner did find the "Exploit.Linux.Gv", ClamWin says ok.
Matthew |
|||||||||||
|
![]() |
![]() | ![]() |
sherpya
![]() |
![]() |
clamav team removed the signature probably it was wrong made
|
|||||||||||
|
![]() |
![]() | Exploit.Linux.Gv found | ![]() |
|
||
![]() |
![]() |
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.