ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic

Have you got this reported scan on/after January 15th
Yes
50%
 50%  [ 1 ]
No
50%
 50%  [ 1 ]
Total Votes : 2

onestop.mid and town.mid on multiple servers (BC.Exploit.CV)
tony-jennings


Joined: 19 Nov 2010
Posts: 0
Location: Cambridge, England
Reply with quote
Hi,

I'm getting reports on more than one of our servers about virus BC.Exploit.CVE_2012_0003 in two files: onestop.mid and town.mid

Usually when I suddenly see errors reported on multiple servers, it is because clamwin is falsely reporting the infection.

4 errors are displayed:

C:\Windows\Media\onestop.mid: BC.Exploit.CVE_2012_0003 FOUND
C:\Windows\Media\town.mid: BC.Exploit.CVE_2012_0003 FOUND
C:\Windows\winsxs\amd64_microsoft-windows-shell-sounds_31bf3856ad364e35_6.0.6001.18000_none_733117b66de7085d\onestop.mid: BC.Exploit.CVE_2012_0003 FOUND
C:\Windows\winsxs\amd64_microsoft-windows-shell-sounds_31bf3856ad364e35_6.0.6001.18000_none_733117b66de7085d\town.mid: BC.Exploit.CVE_2012_0003 FOUND

The dates on these files are very old and two copies are suddenly shown as infected - it seems very unlikely
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
There has been at least 1 false positive report to Clam AV about an exploit on midi files. They should correct their signature within a day or two, but it might help if you also make a false positive report to them and upload a couple of your midi files. Those byte code detections can be a pain if they don't get it right!

Regards,
View user's profileSend private message
Re: onestop.mid and town.mid on multiple servers (BC.Exploit
swerenfl


Joined: 16 Jan 2012
Posts: 0
Location: Schaumburg, IL
Reply with quote
tony-jennings wrote:
Hi,

I'm getting reports on more than one of our servers about virus BC.Exploit.CVE_2012_0003 in two files: onestop.mid and town.mid

Usually when I suddenly see errors reported on multiple servers, it is because clamwin is falsely reporting the infection.

4 errors are displayed:

C:\Windows\Media\onestop.mid: BC.Exploit.CVE_2012_0003 FOUND
C:\Windows\Media\town.mid: BC.Exploit.CVE_2012_0003 FOUND
C:\Windows\winsxs\amd64_microsoft-windows-shell-sounds_31bf3856ad364e35_6.0.6001.18000_none_733117b66de7085d\onestop.mid: BC.Exploit.CVE_2012_0003 FOUND
C:\Windows\winsxs\amd64_microsoft-windows-shell-sounds_31bf3856ad364e35_6.0.6001.18000_none_733117b66de7085d\town.mid: BC.Exploit.CVE_2012_0003 FOUND

The dates on these files are very old and two copies are suddenly shown as infected - it seems very unlikely



Getting the same errors. Freaked out then I saw the report come to my email over the weekend. Any resolution?
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
The resolution should come when people report the false positive to Clam AV. Each Clam sigmaker is generally responsible for correcting his own false positives, so resolution depends upon the availablility of the sigmaker. In addition, the Sourcefire sigmakers (USA) may be on a holiday (it's MLK day today).

Regards,
View user's profileSend private message
onestop.mid and town.mid on multiple servers (BC.Exploit.CV)
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic