Re: [clamav-users] Osx.Adware.TotalAdviseSearch-7489207-0 FOUND

2020-01-10 Thread Douglas Stinnette
AI, Thank you for letting me know when it was released. Doug On Fri, Jan 10, 2020 at 5:09 AM Al Varnell via clamav-users < clamav-users@lists.clamav.net> wrote: > daily 25690 was released five minutes ago and included the following entry: > > Dropped Detection Signatures: > >*

Re: [clamav-users] Osx.Adware.TotalAdviseSearch-7489207-0 FOUND

2020-01-10 Thread Al Varnell via clamav-users
daily 25690 was released five minutes ago and included the following entry: > Dropped Detection Signatures: > >* Osx.Adware.TotalAdviseSearch-7489207-0 -Al- ClamXAV User = On Jan 9, 2020, at 10:03, Douglas Stinnette mailto:dstin...@vcu.edu>> wrote: > Could you

Re: [clamav-users] Osx.Adware.TotalAdviseSearch-7489207-0 FOUND

2020-01-09 Thread Al Varnell via clamav-users
On Jan 9, 2020, at 10:03, Douglas Stinnette wrote: > Could you let me know the name of the next update? Should be daily - 25690 released about twelve hours from now. > Any suggestions on how I can restore the files locally? If you are using the basic ClamAV and those files were deleted, you'll

Re: [clamav-users] Osx.Adware.TotalAdviseSearch-7489207-0 FOUND

2020-01-09 Thread Douglas Stinnette
Hi Alain, That is nice to know. I am still trying to learn what files are detected across our systems. /Users/smstiffler/Library/Application Support/ zoom.us/zoom.us.app/Contents/Frameworks/annoter.bundle/Contents/MacOS/annoter Osx.Adware.TotalAdviseSearch-7489207-0 FOUND Could you let me know

Re: [clamav-users] Osx.Adware.TotalAdviseSearch-7489207-0 FOUND

2020-01-09 Thread Alain Zidouemba
Confirming that those are false positives, thanks for reporting. The offending signature has been dropped. This should be reflected in the next signature update. - Alain On Thu, Jan 9, 2020 at 12:29 PM Douglas Stinnette wrote: > This definition is detecting many files that appear to be safe. >

[clamav-users] Osx.Adware.TotalAdviseSearch-7489207-0 FOUND

2020-01-09 Thread Douglas Stinnette
This definition is detecting many files that appear to be safe. Has anyone else seen this? I have had no luck in getting ClamAV to address false positives in the past. Files and paths I have seen so far but it seems to increase: /Library/Application Support/Adobe/Adobe Desktop