![]() |
| NB |
|
cshorter
|
Note to self, write a virus into chrome.dll and post on forums.
|
||||||||||||
|
|
|||||||||||||
| Chrome no like |
|
GuitarBob
|
Email luca at clamav dot net for instructions on uploading a file to Clam that is too large for the regular submission process.
Remember that if Clam Sentinel detects a "suspicious" file, Clam AV can do nothing about it. You should whitelist all false positive Sentinel suspicious detections in the Sentinel program, as they are heuristic detections by the Sentinel heuristic engine--not actual virus detections by the ClamWin Clam engine. The heuristic engine does not have signatures, so this is the only way to handle the Sentinel suspicious files that are false positives. Regards, |
||||||||||||
|
|
|||||||||||||
|
ReclaiMe
|
Hello,
Looks like we getting ClamAV positive for any .NET application, reporting PUA.Win32.Packer.NetExecutable See for example https://www.virustotal.com/file/0466895bd24a3b6ca1708471e790898478db665e72829ce325e5af2a887adc5e/analysis/1339064066/ which is pretty much a standard Microsoft Web Platform Installer module; however, VirusTotal produces a warning for seemingly any .NET application. Further, the ClamAV false positive form says "do not report PUA.*". But, declaring any .NET application potentially unwanted looks like a bit overkill? Can someone please clarify if it is the issue with ClamAV, a policy decision for ClamAV, or Virustotal just set up something incorrectly? |
||||||||||||
|
|
|||||||||||||
|
GuitarBob
|
This is an overzealous use of the PUA for some packers. I have brought it to Clam's attention. There has been a recent signature update, so it may be fixed, but they may decide not to.
As you say, Clam has always said that since PUA detections are optional per the user, they do not adjust the PUA signatures. In my personal opinion, you do not need PUA detection, so I suggest that you turn it off. Many "good" web sites now use scripts (including javascript--packed and otherwise) that are detected by some PUA signatures. Many "good" programs now use packers that are detected by some some PUA signatures. Many users are confused by a PUA detection. Some AVs do not seem to even use PUA now--I do not see as many PUA detections from other AVs as I used to. So, I suggest you turn off PUA detection and confine your AV to the detection of actual viruses/malware. Regards, |
||||||||||||
|
|
|||||||||||||
| False positives? |
|
||
|
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.


