Re: [clamav-users] HTML.Exploit.Heap-2 False Positive?

2014-05-19 Thread Shaun Hurley
Complete. I've dropped the signature. daily.cld updated (version: 19002, sigs: 957431, f-level: 63, builder: shurley) After running a freshclam the sample should no longer alert. Shaun On Mon, May 19, 2014 at 3:27 PM, Shaun Hurley wrote: > Thank you. I'll take a look at what the issue is. > >

Re: [clamav-users] HTML.Exploit.Heap-2 False Positive?

2014-05-19 Thread Shaun Hurley
Thank you. I'll take a look at what the issue is. Shaun On Mon, May 19, 2014 at 2:02 PM, Al Varnell wrote: > On May 13, 2014, at 8:19 AM, Shaun Hurley wrote: > > > A ClamXav user complained of having a Google Chrome extension “WebGL > > Inspector” which he has used since 2012 was said to be i

Re: [clamav-users] HTML.Exploit.Heap-2 False Positive?

2014-05-19 Thread Al Varnell
On May 13, 2014, at 8:19 AM, Shaun Hurley wrote: > A ClamXav user complained of having a Google Chrome extension “WebGL > Inspector” which he has used since 2012 was said to be infected with > HTML.Exploit.Heap-2. > > I was able to obtain a later version of that extension and verified that > the

[clamav-users] HTML.Exploit.Heap-2 False Positive?

2014-05-13 Thread Shaun Hurley
A ClamXav user complained of having a Google Chrome extension “WebGL Inspector” which he has used since 2012 was said to be infected with HTML.Exploit.Heap-2. I was able to obtain a later version of that extension and verified that the gli.all.js file in that extension scans as infected. I was no

[clamav-users] HTML.Exploit.Heap-2 False Positive?

2014-05-12 Thread Al Varnell
A ClamXav user complained of having a Google Chrome extension “WebGL Inspector” which he has used since 2012 was said to be infected with HTML.Exploit.Heap-2. I was able to obtain a later version of that extension and verified that the gli.all.js file in that extension scans as infected. I was