files_antivirus icon indicating copy to clipboard operation
files_antivirus copied to clipboard

Enhancement: Add a file/signature exclude/ignore list

Open g6094199 opened this issue 7 years ago • 4 comments

HI,

it would be nice to have the option to ignore file we already know are infected in some way. E.g. i have bought a Humblebundle Books and one of them has some curiosity inside where clam thinks its sort of phishing, which shouldnt be a problem with this file imho. Now the scanner spams the activiy log over and over again with the same error message which i would like to set to ignore:

Die Datei art_of_deception_controlling_the_human_element_of_security.pdf ist infiziert mit Sanesecurity.Phishing.Auction.1690.UNOFFICIAL

And no i wont remove the file from the cloud! :-)

So plz implement some kind of whitelist function. Best would be a button in the acitvity log to select the file and set it to be ignored next time.

...I'm quiet unsure to have file exclude list and/or a whitelist and/or signature ignore/exclude list... while a file list seems much saver though.

THX

Sash

g6094199 avatar Jul 04 '18 12:07 g6094199

Hi Sash,

Interesting request, yes, this could make sense in some cases. We won't have time for this the next ~6 months but perhaps after that it can make it to our roadmap. If you need this urgently, see https://nextcloud.com/enterprise/buy/ and we might be able to prioritize this!

Have a great day, Jos

jospoortvliet avatar Jul 04 '18 13:07 jospoortvliet

I second this! Having some PDFs here clamav erroneously rates as infected. A check via Virustotal shows that it's a clamav false positive.

Question for a workaround: If I use clamav not as daemon, but as application, would it access its own whitelists?

treuss avatar Jul 17 '19 16:07 treuss

+1

dimitrimestdag avatar Apr 07 '20 16:04 dimitrimestdag

+4

melroy89 avatar Mar 01 '24 20:03 melroy89