[clamav-users] Win.Malware.Krucky-7009041-0 false positive

Groach groachmail-help at yahoo.com
Sat Jul 20 19:19:23 UTC 2019



On 20/07/2019 19:02, Joel Esler (jesler) via clamav-users wrote:
> Signature has already been dropped.
>
> Sent from my ??? iPhone
>

Thanks Joel.

But I just updated the database and retested but it still records:

Scan Started Sat Jul 20 20:14:04 2019
-------------------------------------------------------------------------------


C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe: 
Win.Malware.Krucky-7009041-0 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 6346742
Engine version: 0.99.4
Scanned directories: 0
Scanned files: 1
Infected files: 1

Data scanned: 0.93 MB
Data read: 0.89 MB (ratio 1.04:1)
Time: 51.933 sec (0 m 51 s)

--------------------------------------
Completed
------------------------------------

Latest update:

ClamAV update process started at Sat Jul 20 20:13:28 2019
main.cld is up to date (version: 58, sigs: 4566249, f-level: 60, 
builder: sigmgr)
Downloading daily-25516.cdiff [100%]
daily.cld updated (version: 25516, sigs: 1663900, f-level: 63, builder: 
raynman)
bytecode.cld is up to date (version: 330, sigs: 94, f-level: 63, 
builder: neo)
Database updated (6230243 signatures) from database.clamav.net (IP: 
104.16.219.84)


When does the latest definition record the dropped signature?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.clamav.net/pipermail/clamav-users/attachments/20190720/2c68eade/attachment.htm>


More information about the clamav-users mailing list