[clamav-users] Win.Malware.Krucky-7009041-0 false positive

Al Varnell alvarnell at mac.com
Sat Jul 20 19:47:05 UTC 2019


I can confirm that it's still in the database thru today's daily 25516 update.

-Al-

On Sat, Jul 20, 2019 at 11:02 AM, Joel Esler (jesler) via clamav-users wrote:
> Signature has already been dropped.  
> 
> Sent from my  iPhone
> 
> On Jul 20, 2019, at 07:37, Groach via clamav-users <clamav-users at lists.clamav.net <mailto:clamav-users at lists.clamav.net>> wrote:
> 
>> Already have done. But I have never (no exaggeration) had any success with it being actioned when reported only on that website. So I am also sending this notification to the mail list on the hope that that is more productive.
>> 
>> Thanks
>> 
>> 
>> 
>> On 20/07/2019 12:22, Matus UHLAR - fantomas wrote:
>>> On 20.07.19 11:53, Groach via clamav-users wrote: 
>>>> C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe: Win.Malware.Krucky-7009041-0 FOUND 
>>>> 
>>>> The file is from Adobe Acrobat (genuine file from 2011). Virustotal hash: https://www.virustotal.com/gui/file/5821567d7dd99623257aea794023ef4200e6e17fd09656b40d97c44a35c701bb <https://www.virustotal.com/gui/file/5821567d7dd99623257aea794023ef4200e6e17fd09656b40d97c44a35c701bb>
>>>> 
>>>> Can we get the definition reviewed/removed please? 
>>> 
>>> you should report false positive on: 
>>> 
>>> https://www.clamav.net/reports/fp <https://www.clamav.net/reports/fp> 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.clamav.net/pipermail/clamav-users/attachments/20190720/b4a5deb2/attachment.htm>


More information about the clamav-users mailing list