Advice Request Scanned with ClamAV after AVG, is this a FP or malware?

Please provide comments and solutions that are helpful to the author of this topic.

Status
Not open for further replies.

hamdy

Level 1
Thread author
Feb 10, 2017
13
I scanned my computer by AVG Internet Security unlimited. it gave me no infected files. and, it's okay you are safe. after that i used ClamAV to scan gave me this

C:\ProgramData\Oracle\Java\installcache_x64\baseimagefam8: Php.Exploit.CVE_2015_2331-1 FOUND
i want to know what is wrong in this file. i scanned it via VirusTotal - Free Online Virus, Malware and URL Scanner the file is safe. i upload the file for you to analyze the file.
baseimagefam8.infected
 
  • Like
Reactions: Wave
W

Wave

Well for what it's worth I downloaded the .infected, extracted it and took a browse through the files - the PE's are digitally signed by Oracle and are therefore genuine, however the signing stamp was from 2014 therefore the problem is most likely due to it being outdated like @Spawn suggested.

As for VirusTotal, the engine versions there are not always the same as the ones used in the actual Home/Enterprise products - they may be more aggressive or tuned to be weaker on VT.
 
  • Like
Reactions: hamdy
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top