> Hence, my question or curiosity over how ClamAV determines > the *true* threat level of a malicious file.
If the virus pattern is in one of the database files, then you are alerted... If it's not, then no alert... That's how every antivirus works... You are more than welcome to report files for the clamav team to check out and add to the db: https://www.clamav.net/reports/malware _______________________________________________ clamav-users mailing list clamav-users@lists.clamav.net https://lists.clamav.net/mailman/listinfo/clamav-users Help us build a comprehensive ClamAV guide: https://github.com/vrtadmin/clamav-faq http://www.clamav.net/contact.html#ml