Wireshark-users: Re: [Wireshark-users] False postive on portable Wireshark v1.8.0's msvcp100.dll
From: Gerald Combs <gerald@xxxxxxxxxxxxx>
Date: Fri, 22 Jun 2012 09:02:52 -0700
On 6/22/12 6:58 AM, Ant wrote:
> Hello.
> 
> Is anyone getting msvcp100.dll as a possible malware infection with the 
> updated ClamAV and SuperAntiSpyware? I am using the extracted portable 
> version in my old, updated Windows XP Pro. SP3 machine.
> 
> http://virusscan.jotti.org/en/scanresult/221a9ca9c452deef28f7acb79a34663564f3c56d 
> (ClamAV; PUA.Win32.Packer.Upx-57) and Adware.Vundo/Variant-MSFake (SAS)

Is there a way to find out what ClamAV database version Jotti's Malware
Scan is using? ClamWin 0.97.4 + main 54 + daily 15069 says it's clean.
VirusTotal says it's clean as well:

https://www.virustotal.com/file/193758db483f6a420b00627ba60ec9c77069c2b5295c1df511d07a1ffd5f7d3a/analysis/1340378908/

-- 
Join us for Sharkfest ’12! · Wireshark® Developer and User Conference
Berkeley, CA, June 24-27 · sharkfest.wireshark.org