Re: [clamav-users] /bin/mkdir: cannot create directory ‘/run/clamav’: File exists

2018-10-18 Thread Reindl Harald
Am 17.10.18 um 18:21 schrieb Dino Edwards: > ExecStartPre=-/bin/mkdir /run/clamav > ExecStartPre=/bin/chown clamav /run/clamav you don't get an error, an error is when the service don't start "If I delete the /var/run/clamav directory, I don’t get the error, but if I restart clamd again I get

Re: [clamav-users] /bin/mkdir: cannot create directory ‘/run/clamav’: File exists

2018-10-18 Thread Reindl Harald
ut /run and how to handle it properly and frankly: when you don#t undertsan dthe "directory already exists" message and ask here insetad jump on the packager with did this bullshit and *pretty clear* did even not try to restart his damned unit a single time how should one help you? >

Re: [clamav-users] /bin/mkdir: cannot create directory ‘/run/clamav’: File exists

2018-10-18 Thread Reindl Harald
er as "ExecStartPre=-/bin/mkdir /run/clamav" which don't fail the whole service in case the directory already exists > -----Original Message- > From: Reindl Harald [mailto:h.rei...@thelounge.net] > Sent: Wednesday, October 17, 2018 8:29 AM > To: ClamAV users ML ; Dino Edwar

Re: [clamav-users] /bin/mkdir: cannot create directory ‘/run/clamav’: File exists

2018-10-18 Thread Reindl Harald
Am 17.10.18 um 13:12 schrieb Dino Edwards: > Good morning? what about read posted links and don't strip context? /run was introduced 7 years ago and the discussion about it made it to every it news portal and that's what i mean when somebody is surprised that /run is a tmpfs available at

Re: [clamav-users] /bin/mkdir: cannot create directory ‘/run/clamav’: File exists

2018-10-18 Thread Reindl Harald
Am 16.10.18 um 19:12 schrieb Dino Edwards: > Answering my own question on the /var/run and the /run directories. > There is a link between the two good morning in 2018 http://www.h-online.com/open/news/item/Linux-distributions-to-include-run-directory-1219006.html

Re: [clamav-users] whitelist with clamav-milter

2018-10-04 Thread Reindl Harald
Am 27.09.18 um 11:04 schrieb Arnaud Jacques: >> I then restarted the milter. Unfortunately, the email is still marked as >> Spam. I thought that clamav-milter would simply ignore the file. >> >> X-Virus-Status: Infected (SecuriteInfo.com.Spam-4701.UNOFFICIAL) > > You can whitelist the

Re: [clamav-users] whitelist with clamav-milter

2018-10-04 Thread Reindl Harald
Am 27.09.18 um 01:53 schrieb Ted Hatfield: > On Thu, 27 Sep 2018, Reindl Harald wrote: >> >> Am 27.09.18 um 00:34 schrieb Ted Hatfield: >>> None of these says anything about what headers are added to the message. >>> >>> X-Virus-Status: and X-Virus-Sc

Re: [clamav-users] whitelist with clamav-milter

2018-10-04 Thread Reindl Harald
Am 27.09.18 um 00:34 schrieb Ted Hatfield: > None of these says anything about what headers are added to the message. > > X-Virus-Status: and X-Virus-Scanned: may be added to all of the messages > regardless of how the milter is configured no the whole purpose of this header is to signal if

Re: [clamav-users] Client disconnected (FD 82)

2018-09-26 Thread Reindl Harald
Am 21.09.18 um 07:07 schrieb ZEMEN Dragana: > I'd like to know what does this clamav's log message mean: "Client > disconnected (FD 82)". I suppose the client broke the connection, but what is > the meaning of "FD 82"? https://en.wikipedia.org/wiki/File_descriptor

Re: [clamav-users] secure download of .cvd files ?

2018-09-04 Thread Reindl Harald
Am 31.08.18 um 14:37 schrieb Michael Orlitzky: > To fix it: if you're going to use a file under /tmp, then use a secure > function like mktemp() to obtain it. But if you're running this job as a > specific user, you might as well give him a special place to work like > /var/tmp/clamav-updates

Re: [clamav-users] Malwarepatrol false positive

2018-08-31 Thread Reindl Harald
Am 27.08.2018 um 20:16 schrieb Mark G Thomas: > This seems to be an ongoing trend. > > I can't believe someone thought this would be a good idea! > > # sigtool --find-sigs MBL_13087222 | sigtool --decode-sigs > VIRUS NAME: MBL_13087222 > DECODED SIGNATURE: >

Re: [clamav-users] FP Heuristics.Phishing.Email.SpoofedDomain with amazon

2018-08-27 Thread Reindl Harald
Am 23.08.2018 um 20:08 schrieb Marcus Schopen: > Hi, > > Am Dienstag, den 14.11.2017, 11:20 +0100 schrieb Hajo Locke: >> Hello, >> >> based on my working whitelist regex i would say the 2nd part should >> not >> look only for amazon\.com >> >> >> If i understood it the correct way it should

Re: [clamav-users] Malformed database issue

2018-07-30 Thread Reindl Harald
Am 29.07.2018 um 19:23 schrieb Jay Hart: > Just got notified that Clamav 0.100.1 is released for Centos 6.10. I'm > wondering if I upgrade to > that release, will my malformed database issue get resolved? what about just update and report? you need to update anyways for security reasons

Re: [clamav-users] Is ClamAV available on the hypervisor?

2018-07-05 Thread Reindl Harald
Am 05.07.2018 um 07:59 schrieb 조정환: > Hello, I am using ClamAV for my organization, but I am using it only on > the VM server. > > Here is the question. > >   > > 1. My supervisor asks, "Is ClamAV available on the hypervisor?" > > I can not answer the question of what other VM servers do

Re: [clamav-users] We STILL cannot reliably get virus updates (since new mirrors)

2018-07-05 Thread Reindl Harald
Am 04.07.2018 um 17:26 schrieb Paul Kosinski: > Using DNS TXT records is great when they work, but a bandwidth disaster > when they don't. > > I don't think Cloudflare per se is the problem -- I think having > different computers serving the DNS vs the big files is the problem. > Back in the

Re: [clamav-users] We STILL cannot reliably get virus updates (since new mirrors)

2018-07-05 Thread Reindl Harald
Am 03.07.2018 um 22:51 schrieb Joel Esler (jesler): >> On Jul 3, 2018, at 4:46 PM, Reindl Harald > <mailto:h.rei...@thelounge.net>> wrote: >> >> Am 03.07.2018 um 22:42 schrieb Joel Esler (jesler): >>>> On Jul 3, 2018, at 3:59 PM, Reindl

Re: [clamav-users] We STILL cannot reliably get virus updates (since new mirrors)

2018-07-05 Thread Reindl Harald
Am 03.07.2018 um 18:39 schrieb Joel Esler (jesler): >> On Jul 2, 2018, at 1:17 PM, Reindl Harald > <mailto:h.rei...@thelounge.net>> wrote: >> >> on a typical setup freshclam is running once or twice *daily* while a >> webserver these days can spit out

Re: [clamav-users] We STILL cannot reliably get virus updates (since new mirrors)

2018-07-05 Thread Reindl Harald
Am 03.07.2018 um 18:28 schrieb Paul Kosinski: > It's not a matter of using DNS TXT records, it's a matter of sourcing > them on a *different* computer than the actual files. This separation > virtually begs for synchronization problems. it is! simply because DNS knowns nothing about your

Re: [clamav-users] We STILL cannot reliably get virus updates (since new mirrors)

2018-07-03 Thread Reindl Harald
gt;> The problem is when a given set of mirrors are not available for a >>> particular requester, eventually you completely run out of mirrors and >>> no updates happen at all. There should be fall backs to prevent this... > > On 02.07.18 13:27, Reindl Harald wrote: &g

Re: [clamav-users] We STILL cannot reliably get virus updates (since new mirrors)

2018-07-03 Thread Reindl Harald
ntwort an: ClamAV users ML Organisation: The Fool and Bladder Face-Jumping Team An: ClamAV users ML On Mon, 2 Jul 2018 19:50:55 +0200 Reindl Harald wrote: > > For me freshclam runs roughly every 2 hours, so I think that the > > load is an order of magnitude higher than you

Re: [clamav-users] We STILL cannot reliably get virus updates (since new mirrors)

2018-07-03 Thread Reindl Harald
Am 02.07.2018 um 20:10 schrieb Brian Morrison: > On Mon, 2 Jul 2018 19:50:55 +0200 > Reindl Harald wrote: > >>> For me freshclam runs roughly every 2 hours, so I think that the >>> load is an order of magnitude higher than you state. I will confess >>> th

Re: [clamav-users] We STILL cannot reliably get virus updates (since new mirrors)

2018-07-03 Thread Reindl Harald
Am 02.07.2018 um 19:45 schrieb Brian Morrison: > On Mon, 2 Jul 2018 19:17:32 +0200 > Reindl Harald wrote: > >> Am 02.07.2018 um 19:07 schrieb Brian Morrison: >>> On Mon, 2 Jul 2018 10:26:34 +0200 >>> Reindl Harald wrote: >>> >>>> Am 02

Re: [clamav-users] update report

2018-07-03 Thread Reindl Harald
Am 02.07.2018 um 19:38 schrieb Benny Pedersen: > Gene Heskett skrev den 2018-07-02 19:20: >> On Monday 02 July 2018 13:12:12 Gene Heskett wrote: >> However, a network restart did not get rid of the ipv6 stuff in the >> ifconfig lo report. ?  /etc/network/interfaces is also clean of any >>

Re: [clamav-users] update report

2018-07-03 Thread Reindl Harald
Am 02.07.2018 um 19:20 schrieb Gene Heskett: >> And since that stuff did exist in my /etc/hosts file, I just stuck a # >> in front of all those, just for S of course. Watching log too. But >> its seems like an every other update run, and since I am not a >> paying/supporting customer, I only

Re: [clamav-users] We STILL cannot reliably get virus updates (since new mirrors)

2018-07-03 Thread Reindl Harald
Am 02.07.2018 um 19:07 schrieb Brian Morrison: > On Mon, 2 Jul 2018 10:26:34 +0200 > Reindl Harald wrote: > >> Am 02.07.2018 um 08:44 schrieb Bill Maidment: >>> Maybe these are dumb questions; if so, please ignore. >>> But doesn't it make more sense to update

Re: [clamav-users] We STILL cannot reliably get virus updates (since new mirrors)

2018-07-02 Thread Reindl Harald
Am 02.07.2018 um 13:22 schrieb Brian Morrison: > On Mon, 02 Jul 2018 04:02:58 -0700 > Al Varnell wrote: > >> Does the evidence available infivsyr that it's the mirrors that are >> out-of-date or is it DNS? Everything I've seen shows that they are >> not in sync, but I'm not sure which get's

Re: [clamav-users] We STILL cannot reliably get virus updates (since new mirrors)

2018-07-02 Thread Reindl Harald
Am 02.07.2018 um 08:44 schrieb Bill Maidment: > Maybe these are dumb questions; if so, please ignore. > But doesn't it make more sense to update all the mirrors first, before > changing the DNS? Is there some mechanism to do it that way round? i wonder why all the linux distributions with

Re: [clamav-users] update report

2018-07-02 Thread Reindl Harald
Am 01.07.2018 um 14:22 schrieb Gary R. Schmidt: > On 01/07/2018 21:05, Reindl Harald wrote: >> >> Am 01.07.2018 um 08:17 schrieb Gary R. Schmidt: >>> On 01/07/2018 10:22, Gene Heskett wrote: >>>> I'm still logging this about every other freshclam run

Re: [clamav-users] update report

2018-07-02 Thread Reindl Harald
Am 01.07.2018 um 08:17 schrieb Gary R. Schmidt: > On 01/07/2018 10:22, Gene Heskett wrote: >> I'm still logging this about every other freshclam run: >> >> Sat Jun 30 18:49:53 2018 -> nonblock_connect: connect(): fd=4 errno=101: >> Network is unreachable >> Sat Jun 30 18:49:53 2018 -> Can't

Re: [clamav-users] clamav list spf problem

2018-06-24 Thread Reindl Harald
Am 21.06.2018 um 15:29 schrieb Gene Heskett: > On Thursday 21 June 2018 06:54:43 Andrew McGlashan wrote: > >> On 21/06/18 17:54, Tilman Schmidt wrote: >>> Am 20.06.2018 um 19:14 schrieb Andrew McGlashan: This is an opportunity to fix things, such an opportunity should not lost,

Re: [clamav-users] off topic Re: clamav list spf problem

2018-06-24 Thread Reindl Harald
Am 23.06.2018 um 06:56 schrieb Andrew McGlashan: > On 23/06/18 00:37, Gene Heskett wrote: >> On Friday 22 June 2018 06:15:42 Reindl Harald wrote: >> >>> Am 22.06.2018 um 05:36 schrieb Gene Heskett: >>>> I get what I would call minimum spam, just enough to

Re: [clamav-users] clamav list spf problem

2018-06-24 Thread Reindl Harald
Am 22.06.2018 um 05:36 schrieb Gene Heskett: > I get what I would call minimum spam, just enough to train SA with. > A bad day is 10. When I was using my old account at the tv station, > several years ago, the spam count was often 200+ a day. Whatever > barracuda is trained to do, its doing

Re: [clamav-users] WARNING: Local version: 0.99.4 Recommended version: 0.100.0

2018-06-20 Thread Reindl Harald
Am 20.06.2018 um 02:06 schrieb Philip: > Has this been released yet by the major Distros? I'm using Debian 9 and > can't get any higher than 0.99.x debian don't raise numbers normally, Fedora does and since EPEL is a Fedora maintained repo it does too clamav-0.100.0-2.fc27.x86_64

Re: [clamav-users] Errors compiling ClamAV

2018-05-29 Thread Reindl Harald
Am 28.05.2018 um 16:53 schrieb CoDDoC > I try compile ClamAV 0.100.0 under CentOS 6.9 (kernel 4.16.11 x86_64) > After './configure --enable-milter' I got: > >     fanotify    : no (disabled) > and >     llvm    : no (disabled) > > But: >     yum list installed | grep llvm >     llvm.x86_64 

Re: [clamav-users] Configure Assistance

2018-05-09 Thread Reindl Harald
Am 05.05.2018 um 23:42 schrieb Christopher Tissot: > I'm currently trying to utilize the ./configure command with Debian > Stretch. I keep getting the error towards the end "configure: error: Your > OpenSSL installation is misconfigured or missing." I have looked online, > and I can't seem to

Re: [clamav-users] safebrowsing.cvd causing clamd to stop functioning

2018-05-09 Thread Reindl Harald
Am 01.05.2018 um 04:40 schrieb Rafael Ferreira: > It seems that the latest safebrowsing.cvd update is causing clamd daemons > with version 0.99 to get into a broken state (100% cpu and rampant memory > growth) no - but hey, who knows what is "the latest" for you May 1 07:25:57 buildserver

Re: [clamav-users] error while loading shared libraries

2018-04-18 Thread Reindl Harald
Am 16.04.2018 um 18:00 schrieb Micah Snyder (micasnyd): > Someone else has pointed out that the `make install` is placing libclammspack > in usr/lib/ instead of /usr/lib64/ (they are using --prefix=/usr, instead of > the default /usr/local). > https://bugzilla.clamav.net/show_bug.cgi?id=12093

Re: [clamav-users] error while loading shared libraries

2018-04-18 Thread Reindl Harald
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Am 15.04.2018 um 17:45 schrieb Andreas Meyer: > "Gary R. Schmidt" schrieb am 16.04.18 um > 00:48:10 Uhr: > Hmm, I just built it on an OpenSUSE system (I mainly use Solaris), and had the same problem. Which is

Re: [clamav-users] error while loading shared libraries

2018-04-18 Thread Reindl Harald
Am 15.04.2018 um 16:48 schrieb Gary R. Schmidt: > On 16/04/2018 00:10, Reindl Harald wrote: >> Am 15.04.2018 um 16:02 schrieb Gary R. Schmidt: >>> On 15/04/2018 22:56, Andreas Meyer wrote: >>>> Hello! >>> [SNIP} >>>> I did not specify any co

Re: [clamav-users] error while loading shared libraries

2018-04-18 Thread Reindl Harald
Am 15.04.2018 um 16:02 schrieb Gary R. Schmidt: > On 15/04/2018 22:56, Andreas Meyer wrote: >> Hello! > [SNIP} >> >> I did not specify any configure options. >> > [SNIP] > >> Libraries have been installed in: >>     /usr/local/lib64 >> >> When I call freshclam I get: >> ./freshclam: error while

Re: [clamav-users] --foreground=true

2018-04-13 Thread Reindl Harald
amav.net/cgi-bin/mailman/listinfo/clamav-users > > > Help us build a comprehensive ClamAV guide: > https://github.com/vrtadmin/clamav-faq > > http://www.clamav.net/contact.html#ml > -- Reindl Harald the lounge interactive design GmbH A-1060 Vienna, Hofmühlgasse 17 CTO / CISO / Soft

Re: [clamav-users] --foreground=true

2018-04-13 Thread Reindl Harald
Am 12.04.2018 um 18:04 schrieb Matus UHLAR - fantomas: > On 11.04.18 10:24, paul.gu...@gmail.com wrote: >> On my Raspbian system htop reports clamd runs with the -foreground=true >> option, although I have commented that out in the configs. > > your raspbian apparently uses systemd, process

Re: [clamav-users] ERROR: This tool requires libclamav with functionality level 91 or higher (current f-level: 85)

2018-04-13 Thread Reindl Harald
Am 11.04.2018 um 21:09 schrieb Alberto José García Fumero: > I'm trying to install clamav-0100 in the office Linux box (Debian 9.4). > > The compilation process goes as a breeze, but when I try to launch > clamscan, the only result I have is that error message: "ERROR: This > tool requires

Re: [clamav-users] --foreground=true

2018-04-13 Thread Reindl Harald
Am 11.04.2018 um 10:24 schrieb paul.gu...@gmail.com: > On my Raspbian system htop reports clamd runs with the -foreground=true > option, although I have commented that out in the configs. > > What does that option mean? Is background better? And if so, how can I get > the clam moving there?

[clamav-users] [Heuristics.Encrypted.PDF(e555f48bc6539cac03976b450b3a33e0:114630)]

2018-04-05 Thread Reindl Harald
[Heuristics.Encrypted.PDF(e555f48bc6539cac03976b450b3a33e0:114630)] hits also non-enrycpted PDF attachemnts andno i can't report the sample because it contains private informations of a 3rd party ___ clamav-users mailing list

Re: [clamav-users] Missing /etc/clamd.conf on fedora

2018-04-02 Thread Reindl Harald
Am 26.03.2018 um 22:37 schrieb marcos sr: I have installed clamav from epel yum install -y clamav clamav-update and I notice is missing the /etc/clamd.conf And when i run clamconf gets the message: clamd.conf not found I note that there is a /etc/clamd.d directory with no files I'm

Re: [clamav-users] Difference in ClamAV libs when installing from YUM repo & building from Source

2018-03-24 Thread Reindl Harald
because unrar is a forbidden item https://fedoraproject.org/wiki/Licensing:Unrar?rd=Licensing/Unrar Am 23.03.2018 um 10:30 schrieb Ravi: When installing ClamAV from yum repo(yum install clamav), we see that that only 1 lib exist i.e libclamav.so in /usr/lib64. But when we build from ClamAV

Re: [clamav-users] Difference in ClamAV libs when installing from YUM repo & building from Source

2018-03-24 Thread Reindl Harald
that mean rar libs are removed when posting to the repo? And also can some one share how the ClamAV source is built and posted to the repo? Thanks Ravi On Fri, Mar 23, 2018 at 3:57 PM, Reindl Harald <h.rei...@thelounge.net <mailto:h.rei...@thelounge.net>> wrote: because unrar is a fo

Re: [clamav-users] ClamAV(R) blog: ClamAV 0.99.4 has been released!

2018-03-07 Thread Reindl Harald
8, at 2:05 PM, Reindl Harald <h.rei...@thelounge.net<mailto:h.rei...@thelounge.net>> wrote: if only the OP would have taken time to mention the exact message unasked in his original post - i love people starting with "I just subscribed to the list in the hopes of understanding

Re: [clamav-users] ClamAV(R) blog: ClamAV 0.99.4 has been released!

2018-03-07 Thread Reindl Harald
nding the issue with the warning being logged by freshclam" On Mar 7, 2018 9:33 AM, "Reindl Harald" <h.rei...@thelounge.net> wrote: Am 07.03.2018 um 18:29 schrieb Brian Fluet: Here's the most recent freshclam log entry: Wed Mar 07 12:19:08 2018 -> ClamAV update process s

Re: [clamav-users] ClamAV® blog: ClamAV 0.99.4 has been released!

2018-03-07 Thread Reindl Harald
Am 07.03.2018 um 18:29 schrieb Brian Fluet: Here's the most recent freshclam log entry: Wed Mar 07 12:19:08 2018 -> ClamAV update process started at Wed Mar 07 12:19:08 2018 Wed Mar 07 12:19:08 2018 -> WARNING: Your ClamAV installation is OUTDATED! Wed Mar 07 12:19:08 2018 -> WARNING: Local

Re: [clamav-users] ClamAV® blog: ClamAV 0.99.4 has been released!

2018-03-07 Thread Reindl Harald
Am 07.03.2018 um 18:05 schrieb Brian Fluet-Denver Equip of Chlt: I just subscribed to the list in the hopes of understanding the issue with the warning being logged by freshclam. The discussion indicates that the issue is resolved but the warning is still being logged here. Is there

[clamav-users] Heuristics.Encrypted.PDF hits unencrypted PDF

2018-03-03 Thread Reindl Harald
5.5 CLAMAV_JNK ClamAV detected malware/phishing/junk [Heuristics.Encrypted.PDF(4b0c49140b7e9ca11c82f24d02a125a2:233495)] bad enough that you can't distinct in the config between encrypted zip arhgcives and encrypted PDF attachments but fact is that Heuristics.Encrypted.PDF hits on ordinary PDF

Re: [clamav-users] No updates since Monday 26th - daily 24352 ?

2018-02-28 Thread Reindl Harald
Am 28.02.2018 um 13:52 schrieb Mark Allan: Hi there, I just noticed that there don't appear to have been any updates to daily.cvd since v24352 on Monday 26th, which seems unlikely. Is this correct or has something gone wrong with the update process? Could it be related to the update of

Re: [clamav-users] Centos 7 dependencies

2018-02-27 Thread Reindl Harald
, that is not the case. he don't understand the sub-packaging and that the packages in question just provide the systemd unit-templates and nothing else On 2/27/18, 7:52 AM, "clamav-users on behalf of Reindl Harald" <clamav-users-boun...@lists.clamav.net on behalf of h.rei...@theloun

Re: [clamav-users] Centos 7 dependencies

2018-02-27 Thread Reindl Harald
Am 27.02.2018 um 12:32 schrieb Emanuel: Hello, when I try to update clamav in Centos 7, dependencies I do not know appear. what is your problem? [root@mail-gw:~]$ rpm -q --filesbypkg clamav-server-systemd clamav-server-systemd /usr/lib/systemd/system/clamd@.service [root@mail-gw:~]$

Re: [clamav-users] ClamAV 0.99.3 and GCC Patch

2018-02-21 Thread Reindl Harald
Am 21.02.2018 um 16:06 schrieb Bill S: On Wed, Feb 21, 2018 at 9:35 AM, SCOTT PACKARD wrote: Bill S - I found it confusing also; I've only gone through the website's downloads verbiage. I was able to find these -4 versions by Googling on the full package name.

Re: [clamav-users] ClamAV 0.99.3 and GCC Patch

2018-02-21 Thread Reindl Harald
Am 21.02.2018 um 15:48 schrieb Emanuel: Is possible to install via yum? surely when you are at RHEL/CentOS/Fedora clamav for RHEL/CentOS is maintained in the EPEL repo which is also part of the Fedora project and you get a working 0.99.3 even for CentOS6

Re: [clamav-users] ClamAV 0.99.3 and GCC Patch

2018-02-21 Thread Reindl Harald
Am 21.02.2018 um 15:35 schrieb SCOTT PACKARD: I found it confusing also; I've only gone through the website's downloads verbiage. .fc26 clearly indicates Fedora 26 .el7 would be RHEL7 point was that there are binary packages which working fine all over distributions and since they simply

Re: [clamav-users] ClamAV 0.99.3 and GCC Patch

2018-02-21 Thread Reindl Harald
Am 21.02.2018 um 14:51 schrieb Bill S: On Wed, Feb 21, 2018 at 8:12 AM, Reindl Harald <h.rei...@thelounge.net> wrote: why not use distribution packages whci seems to can handel the issues properly: Again my apologies. I was not aware there were revised -4 flavors available. When

Re: [clamav-users] ClamAV 0.99.3 and GCC Patch

2018-02-21 Thread Reindl Harald
Am 21.02.2018 um 14:06 schrieb Bill S: I think there was a patch issued over a week ago for the problem 0.99.3 has with newer versions of GCC. Based on that I have two questions. 1. Will version 0.99.3 ever be revised so you do not have to use the patch? 2. If the answer to question 1 is

Re: [clamav-users] Please guide me

2018-02-13 Thread Reindl Harald
ot;too advanced for me" but if you even don't try the builtin one with the excuse "scared of malware" and yes i expect that clamd is correctly implemented when compiled for winodws, if not it#s worth a bugreport Sent from Mail<https://go.microsoft.com/fwlink/?LinkId=550

Re: [clamav-users] Please guide me

2018-02-13 Thread Reindl Harald
Am 13.02.2018 um 17:29 schrieb teo peishen: Wow, too advanced for me..Anyway, thanks for your guide. Appreciate that. what exactly is advanced there? Sent from Mail for Windows 10 From: Yuri Sent: Wednesday,

Re: [clamav-users] Just updated to 99.3, but: "Your ClamAV installation is OUTDATED!"

2018-02-03 Thread Reindl Harald
Am 03.02.2018 um 12:59 schrieb Ralf Hartings: Hi all, Just updated my ClamAV to version 99.3 on my up-to-date CentOS 7.4 server: ● clam-freshclam.service - freshclam scanner   Loaded: loaded (/usr/lib/systemd/system/clam-freshclam.service; enabled; vendor preset: disabled)   Active:

Re: [clamav-users] Can't Install ClamAV

2018-02-02 Thread Reindl Harald
Am 03.02.2018 um 05:29 schrieb Paul B.: (Sorry to keep breaking threading. I'm on digest here, and I know of no way to Reply directly to a post.) Keep in mind that Debian itself cherry-picked the relevant fixes into a patch update to 0.99.2. If you are on Debian stable or a direct

Re: [clamav-users] Can't Install ClamAV

2018-02-02 Thread Reindl Harald
Am 02.02.2018 um 22:14 schrieb Paul B.: Ok, thanks. I did the Synaptic uninstall, and it did break the manual install. I've asked over at MX Linux and will see if they have any insight WTF - and *that* is the reason that you either use packages or handbuilt stuff and even if you build from

Re: [clamav-users] Can't Install ClamAV

2018-02-02 Thread Reindl Harald
Am 02.02.2018 um 12:27 schrieb Paul B.: Hi guys, I had ClamAV up and running fine, but there was a problem and I had to restore the system from an earlier image. Everything is running fine, but now I can't install ClamAV. The system is MX Linux 17 (Debian 9.3) x64. I tried installing from

Re: [clamav-users] ERROR: NotifyClamd: Can't connect to clamd on 127.0.0.1:3310: Connection refused

2018-02-01 Thread Reindl Harald
Am 01.02.2018 um 19:49 schrieb Chris: I'm not sure if that's correct or not since I never had a reason to monitor the start of the clamav-daemon before. Doing more Googling I came across https://serverfault.com/questions/798587/debian-8-cant-get- clamav-to-listen-on-tcp-3310 which is somewhat

Re: [clamav-users] ERROR: NotifyClamd: Can't connect to clamd on 127.0.0.1:3310: Connection refused

2018-02-01 Thread Reindl Harald
Am 01.02.2018 um 18:23 schrieb Chris: nc -zv 127.0.0.1 3300-3400 nc: connect to 127.0.0.1 port 3300 (tcp) failed: Connection refused nc: connect to 127.0.0.1 port 3301 (tcp) failed: Connection refused nc: connect to 127.0.0.1 port 3302 (tcp) failed: Connection refused nc: connect to 127.0.0.1

Re: [clamav-users] 0.99.3 upgrade

2018-02-01 Thread Reindl Harald
Am 01.02.2018 um 14:35 schrieb Eric Broch: I have user who has upgraded clamav to the most recent version (0.99.3) but is still getting the warning when doing 'freshclam' as below: *how* did he upgrade WARNING: Your ClamAV installation is OUTDATED! WARNING: Local version: 0.99.1

Re: [clamav-users] Daily version 24256

2018-01-30 Thread Reindl Harald
Am 30.01.2018 um 17:50 schrieb Joel Esler (jesler): This shouldn't be necessary, we're way past that on Daily.cvd files now, and the issue has been corrected. yes, *that* issue was corrected, but that don#t mean that soemthing similar won't happen tomorrow and hence he likes to code

Re: [clamav-users] ClamAV failed to scan files in /tmp folder

2018-01-30 Thread Reindl Harald
years ago somebody who insulted me used the same webhoster with shared session-dir and had his database credentials in the PHP session - bad mistake leading to a "re-design" some drunken night later :-) 2018-01-29 16:55 GMT-05:00 Reindl Harald <h.rei...@thelounge.net>: Am 2

Re: [clamav-users] ClamAV failed to scan files in /tmp folder

2018-01-29 Thread Reindl Harald
Am 29.01.2018 um 20:27 schrieb cpass test: configured a Moodle LMS to use the ClamAV. They have a plugin in Moodle for it. Here are the parameters for connecting to ClamAV: Unix domain socket: /var/run/clamd.scan/clamd.sock The clamd server is running and the socket really exist in specified

Re: [clamav-users] clamav-0.99.3 on fedora 27

2018-01-29 Thread Reindl Harald
tps://forums.fedoraforum.org/showthread.php?316527-Cannot-install-both-compat-openssl10-devel-and-openssl-devel-at-the-same-time On Jan 29, 2018, at 10:00 AM, Reindl Harald <h.rei...@thelounge.net<mailto:h.rei...@thelounge.net>> wrote: Am 29.01.2018 um 15:56 schrieb Micah Snyder (micasny

Re: [clamav-users] clamav-0.99.3 on fedora 27

2018-01-29 Thread Reindl Harald
Am 29.01.2018 um 15:56 schrieb Micah Snyder (micasnyd): Fedora must have an install location for openssl-devel that isn’t found by the configure script. the install location on Fedora is fine for every software out there which supports openssl 1.1 and according to the changelog there are

Re: [clamav-users] clamav-0.99.3 on fedora 27

2018-01-29 Thread Reindl Harald
* Mon Jul 17 2017 Sérgio Basto <ser...@serjux.com> - 0.99.2-9 - Add patch for openssl-1.1 no idea what sane reasons are there to compile at your own but why don#t you then just start with the feodra src.rpm and it's patches Am 29.01.2018 um 15:56 schrieb Reindl Harald: Am 29.01.2018

Re: [clamav-users] clamav-0.99.3 on fedora 27

2018-01-29 Thread Reindl Harald
Am 29.01.2018 um 15:44 schrieb Frank Elsner: I try to compile clamav on my fulle updates fedora 27 system but it fails with why in the world? dnf --enablerepo=updates-testing upgrade clamav\* https://koji.fedoraproject.org/koji/buildinfo?buildID=1021024 Package Name clamav Version 0.99.3

Re: [clamav-users] Read the signature in cdiff file.

2018-01-29 Thread Reindl Harald
Am 29.01.2018 um 11:24 schrieb Arul Raj: Yes after downloaded they are immediately integrated into the appropriate .cld file. Just to my knowledge, i want to know what type of signature content added. For Example. In version 22445 contains some signature and the next version 22446 version

Re: [clamav-users] Fwd: Undelivered Mail Returned to Sender

2018-01-26 Thread Reindl Harald
Am 26.01.2018 um 17:35 schrieb Matus UHLAR - fantomas: On 26.01.18 15:04, Reindl Harald wrote: which f**g idiot is responsible for that? guess... Received: from mucha.arges.net.pl (mucha.arges.net.pl [87.98.235.141]) by fantomas.fantomas.sk (8.14.4/8.14.4/Debian-4+deb7u1

Re: [clamav-users] 99.3 for Ubuntu

2018-01-26 Thread Reindl Harald
Am 26.01.2018 um 16:15 schrieb Chris: On Fri, 2018-01-26 at 15:37 +0100, Tilman Schmidt wrote: Ubuntu doesn't have 0.99.3 release yet. You need to go to http://www.clamav.net/downloads That will get me the newest source however I need this as I don't really want to install from source:

Re: [clamav-users] ClamAV® blog: ClamAV 0.99.3 has been released!

2018-01-26 Thread Reindl Harald
Am 26.01.2018 um 15:40 schrieb Joel Esler (jesler): As previously mentioned, if you downloaded the beta version of ClamAV 0.99.3, you will need to completely uninstall it and do a fresh install with the production version of 0.99.3 as there are significant code differences when i read

[clamav-users] Fwd: Undelivered Mail Returned to Sender

2018-01-26 Thread Reindl Harald
which f**g idiot is responsible for that? This is the mail system at host lists.clamav.net. I'm sorry to have to inform you that your message could not be delivered to one or more recipients. It's attached below. For further assistance, please send mail to postmaster. If you do so, please

Re: [clamav-users] URGENT: Clamd is wedged on multiple installations

2018-01-26 Thread Reindl Harald
Am 26.01.2018 um 13:50 schrieb Ralf Hildebrandt: * Reindl Harald <h.rei...@thelounge.net>: Am 26.01.2018 um 13:40 schrieb Ralf Hildebrandt: * maxal <m...@sbg.at>: nobody of clamav/cisco reading this list? It's 7:45AM on the east coast so what - i don't get how such

Re: [clamav-users] URGENT: Clamd is wedged on multiple installations

2018-01-26 Thread Reindl Harald
Am 26.01.2018 um 13:40 schrieb Ralf Hildebrandt: * maxal : nobody of clamav/cisco reading this list? It's 7:45AM on the east coast so what - i don't get how such updates slip through at all - it's not rocket science load them on a test-machine and fire up a script that pies

Re: [clamav-users] URGENT: Clamd is wedged on multiple installations

2018-01-26 Thread Reindl Harald
Am 26.01.2018 um 13:17 schrieb maxal: nobody of clamav/cisco reading this list? as the impact is heavy and probably worldwide - anyone with personal contacts or any other channel to reach someone there? contact info on clamav.net is only referring to mailing lists and not very useful the

Re: [clamav-users] URGENT: Clamd is wedged on multiple installations

2018-01-26 Thread Reindl Harald
Am 26.01.2018 um 11:28 schrieb Andreas Schulze: Am 26.01.2018 um 10:01 schrieb Ralf Hildebrandt: * Reindl Harald <h.rei...@thelounge.net>: sounds like an issue with the official signatures given that you are not the first reporter and that we don't use them and have no problems Thou

Re: [clamav-users] open file descriptors

2018-01-26 Thread Reindl Harald
besides that such signatures are braindead on a public list please look at the other threads - the daily sigs are fucked up currently Am 26.01.2018 um 11:13 schrieb Johan Loubser: The integrity and confidentiality of this email is governed by these terms / Die integriteit en vertroulikheid

Re: [clamav-users] reduce memory footprint by removing some virus definitions on a low memory server

2018-01-26 Thread Reindl Harald
Am 26.01.2018 um 09:41 schrieb Sophie Loewenthal: Hi everybody, Would removing some of the virus definitions on a memory sparse server still leave a semi-usable clamav scanner? e.g if I just left main.cvd bytecode.cvd and dropped daily.cvd? Or some other config. e.g just kept the

Re: [clamav-users] URGENT: Clamd is wedged on multiple installations

2018-01-26 Thread Reindl Harald
Am 26.01.2018 um 09:19 schrieb Marco: Il 26/01/2018 09:00, Reindl Harald ha scritto: freshclam and a custom script downloads anything to /var/lib/clamav-download and then for the two "/var/lib/clamav" and "/var/lib/clamav-sa" basend on file-lists hardlinks are set - fro

Re: [clamav-users] URGENT: Clamd is wedged on multiple installations

2018-01-26 Thread Reindl Harald
Am 26.01.2018 um 08:32 schrieb Dianne Skoll: Something went badly wrong with clamd recently; it's stuck with hundreds/thousands of open files per process and interrupting mail flow. When a scanning thread finishes, I see this in the strace output. (I ran clamdscan /etc/hosts as a test): [pid

Re: [clamav-users] Is this an issue to worry about?

2018-01-22 Thread Reindl Harald
Am 22.01.2018 um 15:08 schrieb Personal: I have a clamscan running once a week as:'clamscan -rv --exclude-dir="^/sys" / | grep FOUND >> filename.txt' I have gotten the following hits back for the last three weeks and wondered, if this is something I need to worry about or sould I try and

Re: [clamav-users] crypto currency miner

2018-01-02 Thread Reindl Harald
Am 02.01.2018 um 18:40 schrieb lejeczek: new to the list I'm, hi everyone. I'd like to ask if your minder, if you mine crypto conins that is, often pop up in clamav? I have this one: https://github.com/sammy007/cpuminer-multi and it gets flagged as: ./cpuminer-multi/minerd:

Re: [clamav-users] How to download and update main.cvd and daily.cvd manually AND update mirrors

2017-12-15 Thread Reindl Harald
Am 15.12.2017 um 15:27 schrieb Micah Snyder (micasnyd): Hang on, did you just say that clamav doesn’t have write permissions to the databases? That /would/ explain why freshclam can’t save the new database files. well, people should really stop using idiotic "sudo" in front of every

Re: [clamav-users] Extradatabase import foxhole database

2017-12-13 Thread Reindl Harald
Am 13.12.2017 um 10:21 schrieb Benny Pedersen: Emanuel skrev den 2017-12-12 17:47: what would be the correct way to execute the rsync command? *--files-from=filelist.txt???* why does download scripts exists ?, do you want unsigned signatures ? when does sigtool allow 3dr party signing ?

Re: [clamav-users] Extradatabase import foxhole database

2017-12-12 Thread Reindl Harald
man rsync El 12/12/17 a las 11:48, Reindl Harald escribió: Am 12.12.2017 um 15:44 schrieb Emanuel: it's possible import only the foxhole database from http://sanesecurity.com/usage/linux-scripts/?? just download the files and put them into the signature folder - on most systems /var/

Re: [clamav-users] Extradatabase import foxhole database

2017-12-12 Thread Reindl Harald
Am 12.12.2017 um 15:44 schrieb Emanuel: it's possible import only the foxhole database from http://sanesecurity.com/usage/linux-scripts/?? just download the files and put them into the signature folder - on most systems /var/lib/clamav rsync --no-motd -ctuzS --files-from=filelist.txt

Re: [clamav-users] Local Mirror error "Can't download daily.cvd"

2017-12-11 Thread Reindl Harald
Am 11.12.2017 um 12:50 schrieb Al Varnell: Did you ever read the documentation on Private Local Mirrors ? It would appear you are trying to use solution number "2" and that you haven't added the following line to freshclam.conf on the

Re: [clamav-users] Local Mirror error "Can't download daily.cvd"

2017-12-11 Thread Reindl Harald
Am 11.12.2017 um 12:07 schrieb Emanuel: i solved my problem, i adding in to the freshclam config from client server, this rules: HTTPProxyServer 168.181.185.235 HTTPProxyPort 80 but into the client server i see this error: ClamAV update process started at Mon Dec 11 08:05:22 2017

Re: [clamav-users] Trouble getting cvd files from private local mirror

2017-12-08 Thread Reindl Harald
Am 08.12.2017 um 19:34 schrieb John Kennedy: connect_error: getsockopt(SO_ERROR): fd=4 error=110: Connection timed out Can't connect to port 80 of host clamav.trustx.com (IP: 10.10.10.10) WARNING: Can't download main.cvd from clamav.trustx.com and what is difficult to understand that on

Re: [clamav-users] Local Mirror error "Can't download daily.cvd"

2017-12-07 Thread Reindl Harald
Am 07.12.2017 um 12:27 schrieb Emanuel: Here the config: DatabaseDirectory /var/lib/clamav DatabaseMirror clamav.clamavsrv.tk DatabaseDirectory /var/www/html/clamav.clamavsrv/public_html Firewall port 80 y 53 TCP is OPEN for me it is still not clear if that machine should update the local

  1   2   3   4   >