Hi All !
My last scan, using clamav 0.99.1, this day returns some files named
"omni.ja". Looks like, more or less all my browsers use it, like firefox and palemoon
and they are all located within the brwoser profile directory tree.
For example:
>C:\Program Files\Pale Moon\browser\omni.ja: Html.Exploit.CVE_2017_8757-6336185-0 FOUND<
I restored the files from backup, even month ago, but they all look infected.
That probably a wrong alarm, because my scans run all around the clock
and would have found them earlier.
The database update is:
Downloading daily-23928.cdiff [100%]
daily.cld updated (version: 23928, sigs: 1748676, f-level: 63, builder: neo)
bytecode.cld is up to date (version: 313, sigs: 73, f-level: 63, builder: neo)
Database updated (6314998 signatures) from database.clamav.net (IP: 5.9.253.237)
|
I uploaded the file to virustotal and they say, everything is fine with it!
Anyone out there, having the same problem?
For me, this looks like a problem with the signatures, but I am not sure.
Thanks anyway,
Manfred
Using:
Windows Server 2008 R2, en
clamav 0.99.1