![]() |
| Reporting FP of PUA .lnk? |
|
GuitarBob
|
Don't worry about reporting PUA false positives. Potentilally Unwanted Application detection is an optional detection selected by the user to warn him/her about a file that could be a malware tool (packer, remote administration tool, etc.) or a file that has been created by such a tool (packer, keylogger, etc.). The user selects to use the PUA detection, and the user can de-select it. Additionally, the user can exclude categories from PUA detection (--exclude-pua=pua.Pif.Downloader.Gen). Since PUA detection is up to the user, Clam does not adjust PUA false positives.
PUAs don't mean as much as they used to anyway. Lots of "good" software uses the same tools as malware now. If PUA detection is activated, you can get lots of benign scripts and other detections from the web. Regards, |
||||||||||||
|
|
|||||||||||||
|
danq
|
I just recently started adding PUAs to the scan parameters, as well as the unofficial sigs via Clamsup.
I know that it's more of a guide (e.g. packed installers, PDFs with Javascript), but the phrase "Pif.Downloader" doesn't sound like something one would call a PUA. |
||||||||||||
|
|
|||||||||||||
|
GuitarBob
|
Well, I suppose a PIF could either be "good" or malicious. Both good and bad files can download. All the PUA does is bring it to the attention of the user who has enabled PUA detection. If the user is aware of the file, that is okay. If he was not aware of it, then the PUA detection has brought it to his/her attention.
Most users should just leave PUA detection disabled, which is the ClamWin default. I think it generally causes more problems than it should. That's probably why it doesn't seem to be used in some AVs now--it's probably been replaced by more specific heuristics. Regards, |
||||||||||||
|
|
|||||||||||||
| Reporting FP of PUA .lnk? |
|
||
|
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.


