![]() |
![]() | Many NSIS false positives in ClamAV DB | ![]() |
![]() |
![]() | ![]() |
GuitarBob
![]() |
![]() |
ClamWin uses the scan engine and virus signatures provided by the Clam AV project. The ClamWin project adds a graphical user interface to the Clam AV source code for Linux and ports it over to Windows. It has no sigmaker staff or signature update capability. All false positives should be reported to Clam AV at https://www.clamav.net/fp on the web so they can be corrected. In the meantime, I suggest that you whitelist the falsely detected filenames in the ClamWin tools, preferences, filters, exclude matching filenames option.
It might help speed up false positive correction if you also scan the falsely-detected files with the Virus Total online scanning service, which will also report them to Clam AV. Thank you for using ClamWin. Regards, |
|||||||||||
|
![]() |
![]() | ![]() |
sompaypal
![]() |
![]() |
Thanks for the reply, Bob
![]() I've been scanning the false positives on Virus Total for awhile now, and that seems to have no effect. I've also submitted some of the false positives to ClamAV via their form @ https://www.clamav.net/fp, and this also seems to have no effect. I was hoping you guys would be more closely affiliated with ClamAV's DB maintenance staff and tell them directly of these false positives, which I think are quite serious |
|||||||||||
|
![]() |
![]() | ![]() |
GuitarBob
![]() |
![]() |
ClamWin does not have a close relationship with the Clam AV project like it did when the original Clam AV team ran things. With the various changes in ownership, it has gone away. Clam makes automated virus signatures from Virus Total submissions, but as far as I know, all false positives have to be worked manually--that is why I suggested submission to Virus Total. Unfortunately, there are no full-time sigmakers devoted to Clam--they are reserved for the commercial side, so it might take a while to correct the false positives.
For the present, whitelist the false positive files as I suggested. You could also make a false positive signature yourself with Notepad and put it in the ClamWin DB folder. Put each FP signature on a separate line. Name the file sigfile.fp. A FP signature should have the following form: MD5hash:filesize:SID#_filenamenoextn (Just use the filename--no extension is required). Example: 8fb6c6e66968ccad84ade2df9fea3a9a:18330984:7728603_excel For the submission ID (SID#), just give it the date--each signature with the same date should have its own sequence no.--like 091714xx (xx=01, 02, 03, etc.) Regards, |
|||||||||||
|
![]() |
![]() | ![]() |
sompaypal
![]() |
![]() |
Great,
Thank you, Bob Very helpful ![]() |
|||||||||||
|
![]() |
![]() | Many NSIS false positives in ClamAV DB | ![]() |
|
||
![]() |
![]() |
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.