Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

ClamAV exclude file extension?

Discussion in 'Security' started by teknom, Nov 6, 2017.

Tags:
  1. teknom

    teknom Member

    Joined:
    May 20, 2016
    Messages:
    23
    Likes Received:
    0
    Trophy Points:
    1
    Location:
    Turkey
    cPanel Access Level:
    Root Administrator
    hello guys, some of my clients have excel documents included macros and ClamAV gives false positive for this files. therefor emails could not deliver gives an error: 550 (Doc.Dropper.Agent-6342721-0)
    - Removed Link No Need Here -

    i want to know may i exclude excel files from ClamAV scanner?
     
    #1 teknom, Nov 6, 2017
    Last edited by a moderator: Nov 6, 2017
  2. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    42,802
    Likes Received:
    1,714
    Trophy Points:
    363
    cPanel Access Level:
    Root Administrator
    Hello,

    You can create the following file in order to whitelist virus definitions with ClamAV:

    Code:
    /usr/local/cpanel/3rdparty/share/clamav/local.ign2
    For example, if ClamAV detected a virus on a test.swf file like this:

    Code:
    # /usr/local/cpanel/3rdparty/bin/clamscan /home/123
    /home/123/test.swf: Swf.Exploit.CVE_2016_0968-1 FOUND
    You would run the following commands to whitelist that definition:

    Code:
    echo Swf.Exploit.CVE_2016_0968-1 >> /usr/local/cpanel/3rdparty/share/clamav/local.ign2
    /scripts/restartsrv_clamd
    Thank you.
     
    rpvw likes this.
Loading...

Share This Page