Re: [clamav-users] PUA detected. False Positive?

2022-07-15 Thread Al Varnell via clamav-users
Yes, just make sure you don't have embedded spaces, carriage returns or other invisible characters. -Al- -- ClamXAV User > On Jul 15, 2022, at 8:43 PM, joe a wrote: > > That error was corrected, but now the error is "Malformed Database". > > Is it not a simple text string on a single line? >

Re: [clamav-users] PUA detected. False Positive?

2022-07-15 Thread joe a
That error was corrected, but now the error is "Malformed Database". Is it not a simple text string on a single line? joe a. On 7/15/2022 6:29 PM, joe a wrote: My ignorance shows. Created file "/my_install_path/ignore_list.ign2" and get this error: "LibClamAV Error: cli_loadign: No signature

Re: [clamav-users] PUA detected. False Positive?

2022-07-15 Thread joe a
My ignorance shows. Created file "/my_install_path/ignore_list.ign2" and get this error: "LibClamAV Error: cli_loadign: No signature name provided" Is the signature name not "PUA.Win.Trojan.Xored-1" joe a. On 7/15/2022 4:59 PM, Maarten Broekman via clamav-users wrote: To turn it off entirely,

Re: [clamav-users] PUA detected. False Positive?

2022-07-15 Thread Maarten Broekman via clamav-users
To turn it off entirely, you would create a file ending in .ign2 and put the signature name in that file. I'm not sure there is a good way to do it only for that particular sender, unless you have a way to send those messages to a differently configured ClamAV setup. I don't do a lot of email scan

Re: [clamav-users] PUA detected. False Positive?

2022-07-15 Thread joe a
Thank you. I believe I understand. I was actually looking for a way to turn off checking for this particular "PUA", hopefully just for this sender, while keeping PUA checks still enabled for other cases. In the past I've not had great success searching entirely on my own. joe a. On 7/15/20

Re: [clamav-users] PUA detected. False Positive?

2022-07-15 Thread Maarten Broekman via clamav-users
A "PUA" is a "potentially unwanted application", not necessarily malicious. You can disable PUA checks by ensuring that your clamd configuration has "DetectPUA" set to no. For reference, the signature is looking for bitwise math on CharCodeAt() operations in HTML files. VIRUS NAME: PUA.Win.Trojan

[clamav-users] PUA detected. False Positive?

2022-07-15 Thread joe a
Clamav is finding this: "X-Virus-Status: Infected (PUA.Win.Trojan.Xored-1)" in emails from a source I trust (well, it is a professional organization anyway). Is there any way to tell clamav not to run the check for this particular client and this particular "trojan"? Just not check for it at