Skip to main content

What to do About ClamAV False Positives

Comments

5 comments

  • Infopro
    Yes, I could add each file to the ignore file but that is a major pain because this happening all the time.

    What is happening all the time, you only give one example.
    FCKEditor

    You probably shouldn't be using it any longer. This post is from 2005: drupal.org/project/fckeditor CKEditor is the successor to FCKeditor and has its own CKEditor module. The FCKeditor module will not receive any new features, nor will it be updated for Drupal 7. Upgrading to CKEditor is recommended for all users of FCKeditor.
    0
  • Steve Kessler
    Right now the only files that are being identified as viruses are from FCKEditor. However, the age of the editor should not mean that a virus detection program will see the files as viruses. That is an absurd statement. It is being used on a legacy site that is not going to be updated until that company closes. This has happened before with other JS and PHP files from reputable up to date sources like Drupal and CiviCRM. It has also happened with DOC/X and XLS/X files that were uploaded to the server. I am just trying to find an option with fewer false positives if possible because this becomes the software that cried wolf. Thanks, Steve
    0
  • Infopro
    the age of the editor should not mean that a virus detection program will see the files as viruses. That is an absurd statement.

    Absurd? You might re-read the link I posted. The statement is what it is.
    ...is not going to be updated until that company closes.

    Good luck with that. In the meantime, you might need to white list that file to stop the alerts.
    0
  • Erika Rangel
    Those entries seem to be false positives, not infected files. Now, I can't tell why it appears so slow.
    0
  • rpvw
    I wonder if your clamav is actually detecting these files as Potentially Unwanted Applications (PUA) You might want to read their Documentations, and decide if you are going to block what might be good detections just because it is irritating, or if you are going to choose another A/V solution that doesn't warn you about potentially vulnerable scripts with known and published exploits.
    0

Please sign in to leave a comment.