![]() |
| CVE-2016-1091 PDF's showing as being infected |
|
GuitarBob
|
Upload the file to Virus Total where it will be scanned by 50+ AVs, including the Clam AV engine that runs ClamWin. It is likely to be a false positive, but there are a couple of new PDF viruses around just now.
If it turns out to be a false positive, Virus Total will notify Clam AV so they can fix their virus signature, but it might speed things along if you also upload it to Clam AV via their Contact page. Regards, |
||||||||||||
|
|
|||||||||||||
|
denmalOLA
|
I had already posted it on Virus Total and it came out clean. I have over 32 pdf's that ClamAv said were infected. Why are pdf's being flagged for being infected when it's and Acrobat issue?
These files have time stamps from the last 2 years. |
||||||||||||
|
|
|||||||||||||
|
denmalOLA
|
These 'infected' pdf's were created from 2014 to present. I also tried re-saving the most current pdf using the most current Acrobat and ClamAv still flagged it.
|
||||||||||||
|
|
|||||||||||||
|
GuitarBob
|
No doubt there is a recent Clam AV virus signature that triggers on the PDF file(s). As I said, you might speed up a corrected Clam AV signature if you upload a sample of the file(s) that are detected in error. It looks to me like they may have a new sigmaker. It may take Clam several days before they correct it. All signatures were corrected manually when I worked for Clam as a sigmaker, and I don't think it has changed.
In the meantime, you can whitelist the file(s) that are triggered in error--or you may want to exclude the PDF extension in some folders. Regards, |
||||||||||||
|
|
|||||||||||||
|
denmalOLA
|
Thanks so much for your help.
|
||||||||||||
|
|
|||||||||||||
| PDF's showing as being infected |
|
Lopata
Guest
|
Removing the threat: Users of Enfocus PitStop Professional and Enfocus PitStop Server can remove all embedded files from a PDF document by running an Action List.
Alternatively, users of Enfocus PitStop Professional, Enfocus PitStop Server and Enfocus Certify PDF can remove embedded files during preflight. To do this, they must preflight using a Preflight Profile that has the check for annotations (the last check on the "Varia" tab) set to "Remove" or "Remove and Log". Be aware that doing this will remove all annotations from your PDF documents, not just embedded file annotations. |
||||||||||||
|
|
|||||||||||||
| CVE-2016-1091 PDF's showing as being infected |
|
||
|
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.


