Error: ClamAV False Positive Detection for JavaScript Files on CAS
search cancel

Error: ClamAV False Positive Detection for JavaScript Files on CAS

book

Article ID: 451398

calendar_today

Updated On:

Products

ISG Content Analysis ISG Proxy

Issue/Introduction

This article addresses instances where the Content Analysis System (CAS) incorrectly identifies legitimate JavaScript (.js) files as malicious threats. When browsing websites through the CAS, users may experience blocked content or blank pages due to ClamAV engine false-positive detections.

Environment

Content Analysis System (CAS) Antivirus Vendor: ClamAV

Cause

The ClamAV engine on the CAS is triggering a false-positive detection for legitimate JavaScript files required for website rendering. This often occurs when specific virus signatures are updated, leading to the misclassification of standard web components.

Resolution

To restore functionality, follow these steps to configure an exclusion rule on your CAS:

  1. Access your CAS management console.
  2. Services > AV File Types settings.
  3. Add files extensions that do not need to be scanned (like .js)
  4. Or go to Global Options and click radio button for ignore 
  5. Save and apply the configuration.
  6. Clear your browser cache and re-test access to the affected site.

For details on how to retrieve logs, please refer to the CAS Documentation.

A second option would be to bypass the affected website from SSL interception on the Edge SWG (formerly ProxySG). 

How to bypass SSL interception on the ProxySG in transparent mode

Disable SSL interception for single URL

If the issue persists or if you identify a pattern of false positives, please report this to Submit to ClamAV

Additional Information

For general troubleshooting of AV issues, refer to the CAS: Configuring Antivirus Exclusions documentation