Re: [clamav-users] Osx.Adware.TotalAdviseSearch-7489207-0 FOUND

2020-01-09 Thread Al Varnell via clamav-users
On Jan 9, 2020, at 10:03, Douglas Stinnette wrote: > Could you let me know the name of the next update? Should be daily - 25690 released about twelve hours from now. > Any suggestions on how I can restore the files locally? If you are using the basic ClamAV and those files were deleted, you'll

Re: [clamav-users] freshclamcron output

2020-01-09 Thread Chris via clamav-users
On Thu, 2020-01-09 at 17:14 +, Micah Snyder (micasnyd) wrote: > Hi Chris, > > Do you have the LogVerbose option enabled enabled in your > freshclam.conf file? 0.102 introduced the use of libcurl for HTTP(S) > connections. Libcurl's output is logged when LogVerbose is enabled > and it can be

Re: [clamav-users] Why clamdscan and clamscan may give different results

2020-01-09 Thread Paul Kosinski via clamav-users
Yes of course you can pass options to clamscan on the command line (it's what I did in my 4th example). But my point is that it makes clamscan much harder to use in practice, as with only the default values for the options, clamscan can be very misleading. For now, I guess I'll have to write a

Re: [clamav-users] Osx.Adware.TotalAdviseSearch-7489207-0 FOUND

2020-01-09 Thread Douglas Stinnette
Hi Alain, That is nice to know. I am still trying to learn what files are detected across our systems. /Users/smstiffler/Library/Application Support/ zoom.us/zoom.us.app/Contents/Frameworks/annoter.bundle/Contents/MacOS/annoter Osx.Adware.TotalAdviseSearch-7489207-0 FOUND Could you let me know

Re: [clamav-users] Osx.Adware.TotalAdviseSearch-7489207-0 FOUND

2020-01-09 Thread Alain Zidouemba
Confirming that those are false positives, thanks for reporting. The offending signature has been dropped. This should be reflected in the next signature update. - Alain On Thu, Jan 9, 2020 at 12:29 PM Douglas Stinnette wrote: > This definition is detecting many files that appear to be safe. >

[clamav-users] Osx.Adware.TotalAdviseSearch-7489207-0 FOUND

2020-01-09 Thread Douglas Stinnette
This definition is detecting many files that appear to be safe. Has anyone else seen this? I have had no luck in getting ClamAV to address false positives in the past. Files and paths I have seen so far but it seems to increase: /Library/Application Support/Adobe/Adobe Desktop

Re: [clamav-users] freshclamcron output

2020-01-09 Thread Micah Snyder (micasnyd) via clamav-users
Hi Chris, Do you have the LogVerbose option enabled enabled in your freshclam.conf file? 0.102 introduced the use of libcurl for HTTP(S) connections. Libcurl's output is logged when LogVerbose is enabled and it can be quite verbose. Micah On 1/8/20, 6:27 PM, "clamav-users on behalf of

Re: [clamav-users] Why clamdscan and clamscan may give different results

2020-01-09 Thread Matus UHLAR - fantomas
On Jan 8, 2020, at 18:25, Paul Kosinski via clamav-users wrote: It seems to be because clamscan does not respect the options in clamd.conf... On 08.01.20 18:38, Al Varnell via clamav-users wrote: That's correct and AFAIK, has always been the case. clamscan configurations is accomplished