Re: [clamav-users] Heuristics, only on or off?

2021-03-23 Thread Andrew C Aitchison via clamav-users
On Tue, 23 Mar 2021, Joe Acquisto-j4 wrote: In log find (snipped) ". . .infected by Heuristics.OLE2.ContainsMacros.VBA" and ". . .infected by Heuristics.Phishing.Email.SpoofedDomain" I love the first one but loathe the second one. Is there some secret sauce to allow discriminating between t

Re: [clamav-users] Heuristics, only on or off?

2021-03-23 Thread Al Varnell via clamav-users
Sent from my iPad > On Mar 23, 2021, at 18:29, Joe Acquisto-j4 wrote: > > The "spoofed domain" is the one I would rather allow to pass through without > comment or quarantine as some are "legitmate". But the docs did warn > about "false posititves". Although pedantic types (who me?) might arg

Re: [clamav-users] Heuristics, only on or off?

2021-03-23 Thread Joe Acquisto-j4
> On Tuesday, March 23, 2021 at 5:02 PM, G.W. Haywood wrote: >> On Tue, 23 Mar 2021, Joe Acquisto-j4 wrote: >> >> > In log find (snipped) >> >> Full marks for reading your logs. :) >> >> > ". . .infected by Heuristics.OLE2.ContainsMacros.VBA" >> > >> > and >> > >> > ". . .infected by Heuristics.

Re: [clamav-users] Heuristics, only on or off?

2021-03-23 Thread Mark Pizzolato - Clamav-Win32 via clamav-users
On Tuesday, March 23, 2021 at 5:02 PM, G.W. Haywood wrote: > On Tue, 23 Mar 2021, Joe Acquisto-j4 wrote: > > > In log find (snipped) > > Full marks for reading your logs. :) > > > ". . .infected by Heuristics.OLE2.ContainsMacros.VBA" > > > > and > > > > ". . .infected by Heuristics.Phishing.Emai

Re: [clamav-users] Heuristics, only on or off?

2021-03-23 Thread G.W. Haywood via clamav-users
Hi there, On Tue, 23 Mar 2021, Joe Acquisto-j4 wrote: In log find (snipped) Full marks for reading your logs. :) ". . .infected by Heuristics.OLE2.ContainsMacros.VBA" and ". . .infected by Heuristics.Phishing.Email.SpoofedDomain" I love the first one but loathe the second one. That's y

[clamav-users] Heuristics, only on or off?

2021-03-23 Thread Joe Acquisto-j4
In log find (snipped) ". . .infected by Heuristics.OLE2.ContainsMacros.VBA" and ". . .infected by Heuristics.Phishing.Email.SpoofedDomain" I love the first one but loathe the second one. Is there some secret sauce to allow discriminating between them? joe a __

Re: [clamav-users] Need Help | Clamav installation on SUSE Linux Enterprise Server 12

2021-03-23 Thread Joel Esler (jesler) via clamav-users
Looks like your error is right here. Sent from my  iPhone On Mar 23, 2021, at 01:08, amit.a.singh--- via clamav-users wrote: /usr/local/clamav/bin/freshclam ERROR: Please edit the example config file /usr/local/clamav/etc/freshclam.conf ___ clamav

Re: [clamav-users] Need Help | Clamav installation on SUSE Linux Enterprise Server 12

2021-03-23 Thread Matus UHLAR - fantomas
On 23.03.21 05:07, amit.a.singh--- via clamav-users wrote: I am looking for a help to install and configure clamav, I tried 2 ways to get it done:- 1) Using repo able to install ( zypper install -y clamav) but not able to start the service Error logs :- clamd[26656]: Received 0 file descript

Re: [clamav-users] Number of signatures downloaded has reduced significantly

2021-03-23 Thread Andrew C Aitchison via clamav-users
On Tue, 23 Mar 2021, Pierre Olivier KAPLAN wrote: A few days ago, it seems that you have changed your hosts and your signatures file base format. Since, we noticed that the amount of included signatures has been divided by 3 (from 1.904 M to 641 k). A lot of hashes have disappeared. Did the ge

Re: [clamav-users] Number of signatures downloaded has reduced significantly

2021-03-23 Thread G.W. Haywood via clamav-users
Hi there, On Tue, 23 Mar 2021, Pierre Olivier KAPLAN wrote: G.W. Haywood wrote: > On Tue, 23 Mar 2021, Pierre Olivier KAPLAN wrote: > >> A few days ago, it seems that you have changed your hosts and your >> signatures file base format. Since, we noticed that the amount of >> included signatures

Re: [clamav-users] Number of signatures downloaded has reduced significantly

2021-03-23 Thread Pierre Olivier KAPLAN
Hello, thank you for your message. We are actually using freschlam to retrieve the sigs base. So were there significant changes on the files format on those previous days ? Kind regards, Pierre-Olivier Kaplan De: "clamav-users" À: "clamav-users" Cc: "G.W. Haywood" Envoyé: Mardi 23 M

Re: [clamav-users] Number of signatures downloaded has reduced significantly

2021-03-23 Thread G.W. Haywood via clamav-users
Hi there, On Tue, 23 Mar 2021, Pierre Olivier KAPLAN wrote: A few days ago, it seems that you have changed your hosts and your signatures file base format. Since, we noticed that the amount of included signatures has been divided by 3 (from 1.904 M to 641 k). A lot of hashes have disappeared. D

Re: [clamav-users] Need Help | Clamav installation on SUSE Linux Enterprise Server 12

2021-03-23 Thread G.W. Haywood via clamav-users
Hi there, On Tue, 23 Mar 2021, amit.a.singh--- via clamav-users wrote: ... LibClamAV Error: cli_loaddbdir(): No supported database files found in /var/lib/clamav ... This error message is perfectly clear. You did not have the required databases in the configured database directory. If you

[clamav-users] Number of signatures downloaded has reduced significantly

2021-03-23 Thread Pierre Olivier KAPLAN
Hello ! A few days ago, it seems that you have changed your hosts and your signatures file base format. Since, we noticed that the amount of included signatures has been divided by 3 (from 1.904 M to 641 k). A lot of hashes have disappeared. Did the get replace by something else ? Thanks in