![]() |
![]() | False positive on Disktective | ![]() |
![]() |
![]() | ![]() |
GuitarBob
![]() |
![]() |
A PUA detection on ClamAv/ClamWin is not an indication of a virus. PUA detection is optionally selected by the user, and it is just informative--nothing else. What the PUA detection indicates is that the file is packed with a packer frequently used to pack/obfuscate/hide malware. There are also PUA signatures for malware tools, scripts, etc. Because of this, Clam AV will not adjust/correct/drop a PUA signature.
I notice that the PUA detection is a little bit out of favor now--I don't see it as often as I used to among AVs. If the detection bothers you, you can exclude the filename.extension from ClamWin's scans or delete the PUA selection in the advanced tab. Regards, |
|||||||||||
|
![]() |
![]() | ![]() |
philgoetz
![]() |
![]() |
The PUA is detected by the online multi-virus-detection-program sites.
My local copy of ClamWin, on the disktec.zip I downloaded in August 2010, instead says: D:\data\code\hardware\disk\Disktec\disktective.exe: Trojan.Agent.ND-7 FOUND ----------- SCAN SUMMARY ----------- Known viruses: 905166 Engine version: 0.97 Scanned directories: 1 Scanned files: 4 Infected files: 1 Data scanned: 0.64 MB Data read: 0.50 MB (ratio 1.29:1) Time: 8.500 sec (0 m 8 s) BUT, on a fresh download today, it says: ----------- SCAN SUMMARY ----------- Known viruses: 905166 Engine version: 0.97 Scanned directories: 0 Scanned files: 1 Infected files: 0 Data scanned: 1.02 MB Data read: 0.50 MB (ratio 2.02:1) Time: 3.453 sec (0 m 3 s) -------------------------------------- Completed -------------------------------------- |
|||||||||||
|
![]() |
![]() | ![]() |
GuitarBob
![]() |
![]() |
The online scanners probably have PUA detection enabled on Clam--the average user probably does not need PUA enabled, as it could scare them needlessly. Since you had no detection on the last scan, it looks like maybe a false positive was corrected.
Always keep ClamWin updated to the latest engine, as older engines may register false positives when they can't completely process an enhanced signature, and each new version has additonal enhanced signatures. Regards, |
|||||||||||
|
![]() |
![]() | False positive on Disktective | ![]() |
|
||
![]() |
![]() |
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.