Discussion:
[clamav-users] Osx.Trojan.AppleJeus-6667011-1 False Positive
Al Varnell
2018-09-02 09:18:34 UTC
Permalink
Found in the current (and probably several previous versions) of Skype for Mac.

Found here /Applications/Skype.app/Contents/Frameworks/Electron Framework.framework/Versions/A/Libraries/libnode.dylib.

I've confirmed that all signature strings are present in this file.

FP form keeps telling me I haven't chosen the file when it's clearly shown next to the "Choose File" button.

MD5 is 397f54f5c906b62e0f3f75712c2b568d:18137760:libnode.dylib, but not sure what good that will do if I can't upload it.

Looks like someone has uploaded it to Virus Total:
<https://www.virustotal.com/#/file/d6f94b5bcab619019117cae320e9472de5c9c22b90f4c31d18c621c777065148/detection>

-Al-
--
Al Varnell
Mountain View, CA




_______________________________________________
clamav-users mailing list
clamav-***@lists.clamav.net
http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq

http://www.clamav.net/contact.html#ml
Alain Zidouemba
2018-09-02 12:08:52 UTC
Permalink
The next CVD should correct this FP. Thanks for reporting.

- Alain
Post by Al Varnell
Found in the current (and probably several previous versions) of Skype for Mac.
Found here /Applications/Skype.app/Contents/Frameworks/Electron
Framework.framework/Versions/A/Libraries/libnode.dylib.
I've confirmed that all signature strings are present in this file.
FP form keeps telling me I haven't chosen the file when it's clearly shown
next to the "Choose File" button.
MD5 is 397f54f5c906b62e0f3f75712c2b568d:18137760:libnode.dylib, but not
sure what good that will do if I can't upload it.
<https://www.virustotal.com/#/file/d6f94b5bcab619019117cae320e947
2de5c9c22b90f4c31d18c621c777065148/detection>
-Al-
--
Al Varnell
Mountain View, CA
_______________________________________________
clamav-users mailing list
http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users
https://github.com/vrtadmin/clamav-faq
http://www.clamav.net/contact.html#ml
Loading...