Overview
This article outlines the procedure for reporting malware that bypasses ClamAV detection and provides guidance on configuring third-party signatures to improve overall detection rates.
Reporting Undetected Malware
If you identify a virus or malware sample that is not currently detected by ClamAV, submit the file for analysis through the official reporting portal:
The ClamAV Detection Content Team will evaluate your submission. Upon approval, a new signature will be published to the virus database, enabling detection across all supported environments.
Improving Detection Rates with Third-Party Signatures
To enhance malware identification capabilities, enable third-party signatures within your configured security modules. Follow the procedures below based on your active service:
- Warden Anti-spam and Virus Protection: Refer to Enabling Third-Party Anti-Virus Signatures in Warden for step-by-step configuration instructions.
- Sentinel Anti-malware: Refer to Enabling Third-Party Anti-Virus Signatures in Sentinel for step-by-step configuration instructions.
Troubleshooting & Common Issues
If third-party signatures fail to activate or detection rates remain unchanged after enabling the feature, verify the following:
- Confirm that your service subscription includes access to external signature repositories.
- Ensure the security daemon has been restarted to apply configuration changes immediately.
- Validate that submitted malware samples are unmodified and match the original threat file exactly.