Volnus
Joined: 01 Feb 2016 |
Posts: 0 |
Location: United States |
|
 |
Posted: Mon Feb 01, 2016 8:48 pm |
|
 |
 |
 |
 |
I believe the recent update of your antivirus engine has caused a sharp increase in false positives particularly with caching plugins on WordPress.
There is a very large thread about this on several false positives tied to.
PUA.Phishing.Bank
Some of the submitted files which when checked against VirusTotal are returning 100% safe from both file submission and url checking so its really odd.
Here are some examples.
https://hindisoch.com/wp-content/cache/page_enhanced/www.hindisoch.com/our-parents/_index.html
https://hindisoch.com/wp-content/cache/page_enhanced/www.hindisoch.com/our-parents/_index.html_gzip
https://www.trendingtop5.com/wp-content/cache/page_enhanced/www.trendingtop5.com/top-educational-websites-in-india/_index.html
https://www.trendingtop5.com/wp-content/cache/page_enhanced/www.trendingtop5.com/best-heart-hospital-in-india/_index.html_gzip.old
https://www.trendingtop5.com/wp-content/cache/page_enhanced/www.trendingtop5.com/top-5-best-trekking-places-in-india/_index.html_gzip
Forum thread in regard: https://wordpress.org/support/topic/w3-total-chache-cached-files-contain-virus?replies=19#post-7969978
Keep in mind its not just this particular plugin people are reporting this for WP Rocket, WP Super Cache (automatic), and more its something consistent with their virus scanner which is likely a false positive. (all which are powered by ClamWin's antivirus engine).
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Mon Feb 01, 2016 11:57 pm |
|
 |
 |
 |
 |
ClamWin uses the scan engine and virus database provided by the Clam AV project. All false positives should be reported to Clam AV via their web page at https://www.clamav.net/contact on the web (be sure to select the false positive reporting option).
However, Clam AV has a policy of not correcting false signatures on PUA. PUA is an optional detection. Many Clam AV PUA signatures are made on packers and installers--which can be used by both goodware and malware. So you will save yourself a lot of grief by getting rid of the --detect-pua configuration in the command line block on the ClamWin Advanced tab.
Regards,
|
|