dave-theunsub / clamtk

An easy to use, light-weight, on-demand virus scanner for Linux systems
https://gitlab.com/dave_m/clamtk/wikis/home
Other
352 stars 44 forks source link

Clam Issue #42

Closed rcmmulti closed 9 years ago

rcmmulti commented 9 years ago

I'm just trying to let Clam know that it found this (PUA.Win.Exploit.CVE_2012_0110) on my system Ubuntu 14.04LTS but I can not delete or quarantine it! Also 36 other virus software's see it as not a virus. That's one (Clam) says it is and 36 others saying it is not a virus. Only you can set things right.! Thanks RM

dave-theunsub commented 9 years ago

Hi RM,

A PUA is "just" a potentially unwanted application. It can mean any number of things, but they are not necessarily bad. Because it can be so misleading, I actually recommend disabling that option with ClamTk.

You cannot delete it because you likely do not have the permissions to do so. I would recommend you upload it to ClamAV maintainers to report it as a false positive, but they do not accept PUAs - see here: http://cgi.clamav.net/sendvirus.cgi

Also, you can whitelist specific directories, which may be handy in this situation.

I am curious - what kind of file is it, anyway?

Thanks, Dave M

dave-theunsub commented 9 years ago

On second thought, here's a newer ClamAV page where you probably can submit a false positive:

http://www.clamav.net/report/report-fp.html

Thanks, Dave M