Quite a few months ago, I had a false positive on a file that I ran through VirusTotal. I went through the proper process of submitting it, and it was subsequently cleared in newer clam signature updates, and this was verified by checking the version info.
However, I noticed that it kept coming up as a false positive on VirusTotal. I noticed that the ClamAV version reported on VT is still 0.94.1 while the latest appears to be 0.95.2.
If you are relying on VirusTotal to clear your false positive, you may not be getting the most up to date results. It appears that the clamav version that is being used on VT is using an older signature file.
I contacted Julio who runs VT and he told me the following:
Quote: |
Hello Pet,
I would be more than glad to update the Clam scanner we're using here if
they honour me with sending it. We're not using the normal scanner
(Unix) but a win32 version, and we have to wait for them to send us the
scanner every time they want us to update it.
-- Regards, Julio Canto | VirusTotal.com | Hispasec Sistemas Lab | Tlf: +34.902.161.025 | Fax: +34.952.028.694 | PGP Key ID: EF618D2B | jcanto@hispasec.com |
I've sent in the web form to the ClamWin https://www.clamwin.com/component/option,com_contact/task,view/contact_id,1/Itemid,64/ Contact Us page, assuming that my request was not really a tech support issue, but it wasn't answered. Thus I'm asking here: would whomever is the ClamWin person who normally has updated VirusTotal's scanner in the past please be so kind as to do so again? Or at least provide me or Julio with a contact so we can get this up to date.
Many thanks