Re: [Clamav-users] [Windows] How does ClamAV compare with closed-source alternatives?

2010-05-14 Thread Török Edwin
On 05/14/2010 08:19 AM, Jason Haar wrote: On 05/14/2010 02:52 PM, Dennis Peterson wrote: On 5/13/10 7:10 PM, Jason Haar wrote: Why is Sourcefire allowing a third-party to use their brandname (and linking to their site) when it doesn't use ClamAV code itself? It supports other AV vendor

[Clamav-users] bytecode.cvd problem again?

2010-05-14 Thread Steve Basford
Hi, Just had clamd 0.96 win32 port crash... LibClamAV debug: 767942.cbc loaded LibClamAV debug: Loading trusted bytecode LibClamAV debug: bytecode using API 66, but highest API known to libclamav is 45 , skipping LibClamAV debug: 767944.cbc loaded LibClamAV debug: Loading trusted bytecode

[Clamav-users] menekrug not detected/ Clean/quarentine virus

2010-05-14 Thread Jean-Paul natola
Hi all, I am running clamav on a bsd box to scan USB drives, I have two questions, now that it found the virus is there a way to clean or quarentine the infected file? also it gave an OK result to menekrug.exe see below /mnt/usb/ISPRED/Desktop.ini: Trojan.Agent-155358 FOUND

Re: [Clamav-users] bytecode.cvd problem again?

2010-05-14 Thread Török Edwin
On 05/14/2010 06:00 PM, Steve Basford wrote: Hi, Just had clamd 0.96 win32 port crash... Is this the 0.96 version, or some later git version? LibClamAV debug: 767942.cbc loaded LibClamAV debug: Loading trusted bytecode LibClamAV debug: bytecode using API 66, but highest API known to

Re: [Clamav-users] menekrug not detected/ Clean/quarentine virus

2010-05-14 Thread Alain Zidouemba
type the following at the command line: clamscan --help It will show you some of the options you have for quarantining file: clamscan --remove[=yes/no(*)] Remove infected files. Be careful! clamscan --move=DIRECTORY Move infected files into DIRECTORY clamscan

Re: [Clamav-users] bytecode.cvd problem again?

2010-05-14 Thread Török Edwin
On 05/14/2010 06:08 PM, Török Edwin wrote: On 05/14/2010 06:00 PM, Steve Basford wrote: Hi, Just had clamd 0.96 win32 port crash... Is this the 0.96 version, or some later git version? I just tested 0.96 ClamAV on win32 and it works. I think you are using a version that is later than

Re: [Clamav-users] bytecode.cvd problem again?

2010-05-14 Thread Steve Basford
Török Edwin wrote: Please update to latest from 0.96 branch/master, and it should work. Just downloading and re-compiling now... I need a faster machine :( Thanks for looking into it... Cheers, Steve Sanesecurity ___ Help us build a

Re: [Clamav-users] menekrug not detected/ Clean/quarentine virus

2010-05-14 Thread Jean-Paul natola
yes it is, see link http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_PALEVO.SMBFVSect=Sn unfortunatley the bsd box has no web browser so I cannot get to the submission page Date: Fri, 14 May 2010 11:14:49 -0400 From:

Re: [Clamav-users] menekrug not detected/ Clean/quarentine virus

2010-05-14 Thread Alain Zidouemba
If you can, please generate the MD5 checksum for that file and paste it here. Thanks, -Alain On Fri, May 14, 2010 at 12:13 PM, Jean-Paul natola jnat...@hotmail.com wrote: yes it is, see link http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_PALEVO.SMBFVSect=Sn

Re: [Clamav-users] menekrug not detected/ Clean/quarentine virus

2010-05-14 Thread MacMullan, Hugh
And you CAN submit with a text-based browser like lynx -- assuming you're allowed to install one on that box. They work fine for the submission program: http://cgi.clamav.net/sendvirus.cgi -Hugh -Original Message- From: clamav-users-boun...@lists.clamav.net

Re: [Clamav-users] menekrug not detected/ Clean/quarentine virus

2010-05-14 Thread Jean-Paul natola
d9fcc755cb4037343eb5d5690a3263a3 Date: Fri, 14 May 2010 12:20:16 -0400 From: azidoue...@sourcefire.com To: clamav-users@lists.clamav.net Subject: Re: [Clamav-users] menekrug not detected/ Clean/quarentine virus If you can, please generate the MD5 checksum for that file and paste it

Re: [Clamav-users] menekrug not detected/ Clean/quarentine virus

2010-05-14 Thread Jean-Paul natola
I will install it now, i created this box for the sole purpose of scan usb drives, I do ALLOW any storage devices to be used on our windows machines. If i can just find a way to automate it so that I dont have to mount and run the scans manually From: hugh...@wharton.upenn.edu To:

Re: [Clamav-users] menekrug not detected/ Clean/quarentine virus

2010-05-14 Thread Jean-Paul natola
correction: I DO NOT ALLOW any mass storage devices on our windows machines From: jnat...@hotmail.com To: clamav-users@lists.clamav.net Date: Fri, 14 May 2010 12:54:33 -0400 Subject: Re: [Clamav-users] menekrug not detected/ Clean/quarentine virus I will install it now, i created this

Re: [Clamav-users] Tiered freshclam updates on port443

2010-05-14 Thread Nathan Gibbs
* Eddie Ekwo wrote: Hello Everyone. I am new to using ClamAV and I have searched through the mail archives for help/pointers on setting up a tired freshclam update environment. I have got a server that has access to the internet on port 80, so updates from internet are not a problem. I

Re: [Clamav-users] Tiered freshclam updates on port443

2010-05-14 Thread Alain Zidouemba
Feature requests are always welcome. Please enter it/them here: https://wwws.clamav.net/bugzilla/ Thanks, -Alain On Fri, May 14, 2010 at 1:01 PM, Nathan Gibbs nat...@cmpublishers.com wrote: * Eddie Ekwo wrote: Hello Everyone. I am new to using ClamAV and I have searched through the mail

Re: [Clamav-users] Tiered freshclam updates on port443

2010-05-14 Thread Matus UHLAR - fantomas
On 10.05.10 16:43, Eddie Ekwo wrote: I am new to using ClamAV and I have searched through the mail archives for help/pointers on setting up a tired freshclam update environment. I have got a server that has access to the internet on port 80, so updates from internet are not a problem. I have

Re: [Clamav-users] menekrug not detected/ Clean/quarentine virus

2010-05-14 Thread Marshall Dudley
Huh? It is impossible to have a windows machine without any mass storage devices. Marshall Jean-Paul natola wrote: correction: I DO NOT ALLOW any mass storage devices on our windows machines From: jnat...@hotmail.com To: clamav-users@lists.clamav.net Date: Fri, 14 May 2010 12:54:33

Re: [Clamav-users] menekrug not detected/ Clean/quarentine virus

2010-05-14 Thread Jean-Paul natola
USB/Removable/Flash etc.. Date: Fri, 14 May 2010 13:23:18 -0400 From: mdud...@king-cart.com To: clamav-users@lists.clamav.net Subject: Re: [Clamav-users] menekrug not detected/ Clean/quarentine virus Huh? It is impossible to have a windows machine without any mass storage devices.

Re: [Clamav-users] Tiered freshclam updates on port443

2010-05-14 Thread Nathan Gibbs
* Alain Zidouemba wrote: Feature requests are always welcome. However a resounding NO after putting in the effort is not. It has been my experience to post a feature request and be told that. 1. The lake short pier are to your right. 2. Take a long walk and or jump. A better experience has

Re: [Clamav-users] Tiered freshclam updates on port443

2010-05-14 Thread Nathan Gibbs
* Matus UHLAR - fantomas wrote: Why? is there an aggresive firewall on the machine? Or is the machine maintained by a moron? He is no moron who would dream of doing things differently. He is just not like you. To call another a moron because they are not like you, would imply that the name

Re: [Clamav-users] Tiered freshclam updates on port443

2010-05-14 Thread Török Edwin
On 05/14/2010 09:42 PM, Nathan Gibbs wrote: * Alain Zidouemba wrote: Feature requests are always welcome. However a resounding NO after putting in the effort is not. It has been my experience to post a feature request and be told that. 1. The lake short pier are to your right. 2. Take

Re: [Clamav-users] Tiered freshclam updates on port443

2010-05-14 Thread Chuck Swiger
On May 14, 2010, at 11:42 AM, Nathan Gibbs wrote: * Alain Zidouemba wrote: Feature requests are always welcome. However a resounding NO after putting in the effort is not. It has been my experience to post a feature request and be told that. 1. The lake short pier are to your right. 2.

[Clamav-users] How does ClamAV compare with

2010-05-14 Thread Syed Zubair
IMO the logical premiss for the discussion have no basis in fact. There is no av software which could claim one hundred per cent detecton rate either because of its db or heruistic capability. Additionally there is no av software which is better than others all the time. Dscussion about av

Re: [Clamav-users] Tiered freshclam updates on port443

2010-05-14 Thread Nathan Gibbs
* Török Edwin wrote: On 05/14/2010 09:42 PM, Nathan Gibbs wrote: 1. Is moving updates over https a good idea? For the ClamAV update infrastructure at large, probably not. For the public mirrors no. https has extra overhead (ssl setup), Thats what I thought, more complicated for you guys.

Re: [Clamav-users] Tiered freshclam updates on port443

2010-05-14 Thread Nathan Gibbs
* Chuck Swiger wrote: On May 14, 2010, at 11:42 AM, Nathan Gibbs wrote: In summary I refuse to waste my time and the ClamAV Team's time submitting a feature request that they will refuse to implement. While I have concerns and even complaints that I might make about ClamAV, the ClamAV