![]() |
| False Positives |
|
GuitarBob
|
Strange!
I don't know if it will help but try excluding the full location: C:\DOCUME~1\bhenson\LOCALS~1\Temp\*.clamtmp Regards, |
||||||||||||
|
|
|||||||||||||
|
ROCKNROLLKID
|
Would be best to upload the file to virustotal. Then submit the file and virustotal report to ClamAV false positive support here: https://www.clamav.net/contact
However, I think some of these false positives are happening because of incompatibility with the YARA and Snort rules that are being introduced in .99. The YARA and Snort rules do not work with .98.7 and under. |
||||||||||||
|
|
|||||||||||||
|
GuitarBob
|
Virut is an old virus now, and I'm sure the authors have moved on. The Clam AV Virut signatures were subject to many false positives.
Regards, |
||||||||||||
|
|
|||||||||||||
|
ROCKNROLLKID
|
That looks like a generic signature. I didn't know ClamAV was writing generic signatures. Would explain why I haven't seen any new bytecode signatures in a long time now. Generic signatures can last weeks to months before it would need to be updated. Generic signatures can detect families of malware.
|
||||||||||||
|
|
|||||||||||||
|
GuitarBob
|
Problem with the generic stuff is that it should be really tested extensively. Clam AV does not/did not have many Windows system/app files on its false positive farm, so the Virut sigs always zapped valid Windows files (Office, some system files) that had been changed since the last Virus sig. Clam was always so glad to get the latest Virut sig that they never bothered to change their very simple Virut signature process. There's more to a good generic signature than wildcards! Every Clam Sentinel heuristic signature is a generic signature which can detect a very broad category of malware.
Regards |
||||||||||||
|
|
|||||||||||||
|
ROCKNROLLKID
|
Well I don't know how true that is today, but at least ClamWin has a false positive safe guard for valid digitally signed Microsoft files.
|
||||||||||||
|
|
|||||||||||||
|
GuitarBob
|
I haven't seen it yet (in ClamWin's v.98.7) as of about a week ago. ClamWin had this protection years ago. Clam Sentinel starting using digital sigs in its detection process when Clam AV was scared of them back in 2012.
There's more to a good generic sig than a few wildcards. That is 2008 technology. Regards, |
||||||||||||
|
|
|||||||||||||
| False Positives |
|
||
|
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.


