This article addresses instances where the Content Analysis System (CAS) incorrectly identifies legitimate JavaScript (.js) files as malicious threats. When browsing websites through the CAS, users may experience blocked content or blank pages due to ClamAV engine false-positive detections.
Content Analysis System (CAS) Antivirus Vendor: ClamAV
The ClamAV engine on the CAS is triggering a false-positive detection for legitimate JavaScript files required for website rendering. This often occurs when specific virus signatures are updated, leading to the misclassification of standard web components.
To restore functionality, follow these steps to configure an exclusion rule on your CAS:
For details on how to retrieve logs, please refer to the .
A second option would be to bypass the affected website from SSL interception on the Edge SWG (formerly ProxySG).
How to bypass SSL interception on the ProxySG in transparent mode
Disable SSL interception for single URL
If the issue persists or if you identify a pattern of false positives, please report this to Submit to ClamAV
For general troubleshooting of AV issues, refer to the documentation