kakashi_12
Joined: 08 Mar 2009 |
Posts: 0 |
|
|
 |
Posted: Sun Mar 08, 2009 7:10 pm |
|
 |
 |
 |
 |
Is there a way I can configure ClamWin to skip a file that I don't want it to remove. It thinks that my one game is a virus, but I scanned it with two other scanners and it is fine! Can I tell it to skip that file somehow or deny it access or encrypt it or????
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Sun Mar 08, 2009 11:10 pm |
|
 |
 |
 |
 |
See the temporary fix below, but what you should really do is report the file as a false positive virus recognition to the Clam AV people at https://www.clamav.net/sendvirus/ on the web. Fill out the form, upload the file, and be sure to check the proper box to indicate that the file is a false positive. The Clam people will adjust their signature within a couple of days.
You can exclude files from scheduled scans by using ClamWin's Filters preferences configuration screen. Put the directory location and filename in the Exclude Matching Filenames section on the left hand side of the screen. Click on the square box to go down to the end of the list. Once there, you can insert the directory location/filename, then OK it. As an example, here is what I put to exclude the ClamWin quarantine directory from my scans: C:\ProgramData\.clamwin\quarantine . You will still be able to scan the file individually, but this will exclude the file from ClamWin's scheduled scans until the false positive is fixed.
Regards,
|
|
kakashi_12
Joined: 08 Mar 2009 |
Posts: 0 |
|
|
 |
Posted: Mon Mar 09, 2009 2:17 am |
|
 |
 |
 |
 |
Thanks for the excellent help, but when I reported the virus it said Clam has already recognized it. Now what?
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Mon Mar 09, 2009 2:53 am |
|
 |
 |
 |
 |
Of course Clam already detects a virus in your file, but you want them to know that there is a false positive detection in it. It sounds like you may have reported the file just like it was a regular virus. You use the same form to report both, but there is a false positive block to check if applies. You can also make some comments in the comment block. I always put something in the comments section like "This is a false positive detection on a file I have been using for XX months."
Regards,
|
|
kakashi_12
Joined: 08 Mar 2009 |
Posts: 0 |
|
|
 |
Posted: Mon Mar 09, 2009 3:09 am |
|
 |
 |
 |
 |
That is what I did. It didn't work.
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Mon Mar 09, 2009 3:49 am |
|
 |
 |
 |
 |
"A false positive: it is detected as a virus by ClamAV, but it is not malware (please do NOT encrypt the sample as it makes the review process slower)"
The info pasted above from the Clam Submission form has a little radio button to the left of it. You have to click on the radio button to indicate it is a false positive. Again...of course it is already detected by Clam, but by clicking the radio button, you are telling them it applies to a false positive, and not a real virus to the file you are going to upload to them.
Regards,
|
|