Re: [clamav-users] Scan reports

2022-05-31 Thread Richard Graham via clamav-users
On Tue, May 31, 2022 at 4:14 PM Andrew C Aitchison wrote: > > On Tue, 31 May 2022, John Paul Guay wrote: ... > > rsync -zar --remove-source-files padmin@$server:$SOURCEFILE $TARGETDIR Does the user `padmin` still exist on all the servers and have the proper permissions/access? RG

Re: [clamav-users] CLAMAV: Docker Tag 0.104.2 has 9 Medium Vulnerabilities for Busy Box

2022-02-13 Thread Richard Graham via clamav-users
On Sun, Feb 13, 2022 at 2:11 PM Marc wrote: > ... > > Maybe it is time to allow environment variables in the config files? > > sed -e "s|^\(Example\)|\# \1|" \ > -e "s|.*\(PidFile\) .*|\1 /run/lock/clamd.pid|" \ Maybe it is time for a `sed` script file? :-) sed -f

Re: [clamav-users] Yara regular expression finds only first match in ClamAV ?

2021-08-22 Thread Richard Graham via clamav-users
Hi, Very interesting! Thanks! R On Sun, Aug 22, 2021 at 9:10 PM G.W. Haywood via clamav-users < clamav-users@lists.clamav.net> wrote: > Hi there, > > On Sun, 22 Aug 2021, Richard Graham via clamav-users wrote: > > On Sun, Aug 22, 2021 at 10:41 AM Zvi Kave wrote: > >

Re: [clamav-users] Yara regular expression finds only first match in ClamAV ?

2021-08-22 Thread Richard Graham via clamav-users
Hi, I'm wondering if the --allmatch option/switch is useful here. Regards, R On Sun, Aug 22, 2021 at 10:41 AM Zvi Kave via clamav-users < clamav-users@lists.clamav.net> wrote: > Hi Ged, > > > Sorry. I hope you have some hair yet. > > I understand that I have to be patient. > > > Thank you, > >

Re: [clamav-users] false positive on MBL_85256034.UNOFFICIAL with Google Drive links

2021-04-28 Thread Richard Graham via clamav-users
On Wed, Apr 28, 2021 at 4:25 PM Robert Kudyba wrote: > ... > sigtool --find-sigs MBL_85256034*|sigtool --decode-sigs > ... and remember that --find-sigs takes a REGEX not a glob so perhaps you meant "MBL_85256034.*", although sigtools checks the entire entry so searching for 'MBL_85256034' is

Re: [clamav-users] ClamAV MD5 sum based whitelists (*.fp) don’t work in Ubuntu MATE 20.04.2

2021-04-20 Thread Richard Graham via clamav-users
On Tue, Apr 20, 2021 at 11:54 AM Pavel Řezníček wrote: > Humm, I’ve restarted my laptop and now the .fp file gets read and the > detection gets ignored. > > How come I need to restart the machine? Is there any service I could > restart instead? > A restart shouldn't be necessary. Is that

Re: [clamav-users] ClamAV MD5 sum based whitelists (*.fp) don’t work in Ubuntu MATE 20.04.2

2021-04-17 Thread Richard Graham via clamav-users
Oops, my first email text formatting may have destroyed the contents. Here's another try. On Sat, Apr 17, 2021 at 8:55 PM Richard Graham wrote: > > > > Very curious! It seems to work as expected on my Fedora 32 system. If > you run clamscan with the --debug option, you can see it load the

Re: [clamav-users] ClamAV MD5 sum based whitelists (*.fp) don’t work in Ubuntu MATE 20.04.2

2021-04-17 Thread Richard Graham via clamav-users
Very curious! It seems to work as expected on my Fedora 32 system. If you run clamscan with the --debug option, you can see it load the ".fp" files (all lots and lots of other stuff too!). *$ clamscan --versionClamAV 0.103.2/26143/Sat Apr 17 13:06:39 2021* *$ cat

Re: [clamav-users] Last ClamAV compatible with x32

2021-04-12 Thread Richard Graham via clamav-users
On Mon, Apr 12, 2021 at 5:28 PM Gary R. Schmidt wrote: > On 13/04/2021 01:22, Sorin Petrut Niculae via clamav-users wrote: > newer version of zlib for this version of RHEL 6.7 x32. Newer than the > > one for the RHEL repositories. > > > > > > Any advice? > > > Build it from source. > > As I have

Re: [clamav-users] clamscan suddenly taking 25 minutes for a single mail

2021-04-06 Thread Richard Graham via clamav-users
> > But I'd like to understand why, on Sunday morning, the scan time which had > been under a minute per mail, for over 4 months, suddenly jumped to 25 > minutes per mail and has remained at that. It's a good question. Is there any way to reproduce what was happening on Sunday morning? ... and

Re: [clamav-users] clamscan suddenly taking 25 minutes for a single mail

2021-04-06 Thread Richard Graham via clamav-users
Clamscan can spend a long time loading signatures, etc. If you run your command with strace (or monitor the process with lsof, etc.) you'll probably see clamscan is busy accessing signature files. On Tue, Apr 6, 2021 at 5:44 PM Eddie via clamav-users < clamav-users@lists.clamav.net> wrote:

Re: [clamav-users] Terminate clamscan after specific time

2021-01-05 Thread Richard Graham via clamav-users
On Tue, Jan 5, 2021 at 5:01 PM G.W. Haywood via clamav-users < clamav-users@lists.clamav.net> wrote: > ... > An Englishman asked an Irishman for directions to somewhere. > > The Irishman replied, "If I was going there, I wouldn't start from here". > > :) > > Reminds me of another Irishman...

Re: [clamav-users] Help please

2021-01-05 Thread Richard Graham via clamav-users
You also may want to install it from the Ubuntu repo. https://help.ubuntu.com/community/ClamAV https://packages.ubuntu.com/focal/clamav On Tue, Jan 5, 2021 at 9:36 PM David Copeland wrote: > You might have a look at: > > >

Re: [clamav-users] Fwd: Re: Fwd: Re: Fwd: Win.Trojan.Virut-375 FOUND in libcef.dll

2020-11-17 Thread Richard Graham via clamav-users
Maybe the SHA-256 and file size matched so it assumes (with extremely high probability) that it already has the file? On Wed, Nov 18, 2020 at 1:08 AM Alejandro Hernández via clamav-users < clamav-users@lists.clamav.net> wrote: > 樂 Im not sure. Last time, I did it through this option on the web:

Re: [clamav-users] Fwd: Re: Fwd: Win.Trojan.Virut-375 FOUND in libcef.dll

2020-11-17 Thread Richard Graham via clamav-users
On Tue, Nov 17, 2020 at 10:07 PM Alejandro Hernández via clamav-users < clamav-users@lists.clamav.net> wrote: > Here i 've just uploaded the file again to virustotal: > https://www.virustotal.com/gui/file/f2ed1af539f3c783ffe0661d773a8e307ca1601536459b9db24469ebd60a80fe/detection > N.B.: I'm not

Re: [clamav-users] Fwd: Win.Trojan.Virut-375 FOUND in libcef.dll

2020-11-16 Thread Richard Graham via clamav-users
On Mon, Nov 16, 2020 at 1:16 PM Alejandro Hernández via clamav-users < clamav-users@lists.clamav.net> wrote: > > everybody says it is a false positive. Could you check it and tell me? (I > 've send it you before but no feedback) > > > Program: Epic Games Store > > C:\Program Files (x86)\Epic >

Re: [clamav-users] ClamAV problem with installation

2020-10-30 Thread Richard Graham via clamav-users
I'm also wondering if you're new to Linux and ClamAV, perhaps your distro has a package that can be more simply installed? Does your distro's package manager show that ClamAV is available for install? A lot can be learned from installing SW from source (sometimes some great feature/performance

Re: [clamav-users] Clamd.exe

2020-10-23 Thread Richard Graham via clamav-users
Have all the installation steps been followed? https://www.clamav.net/documents/installing-clamav-on-windows On Fri, Oct 23, 2020 at 6:38 PM Marcy Rogers via clamav-users < clamav-users@lists.clamav.net> wrote: > Good Morning, > > I have Clamav on Windows Servers. I am running clamd.exe in

Re: [clamav-users] How to determine virus database version from behind proxy?

2020-07-09 Thread Richard Graham via clamav-users
hat do you think about DNS over TOR? On Jul 9, 2020, at 14:11, Richard Graham via clamav-users < > clamav-users@lists.clamav.net> wrote: Or for more advertised privacy: > > curl -H 'accept: application/dns-json' ' > https://mozilla.cloudflare-dns.com/dns-query?name=cur

Re: [clamav-users] How to determine virus database version from behind proxy?

2020-07-09 Thread Richard Graham via clamav-users
Or for more advertised privacy: curl -H 'accept: application/dns-json' ' https://mozilla.cloudflare-dns.com/dns-query?name=current.cvd.clamav.net= ' On Thu, Jul 9, 2020 at 7:58 PM Richard Graham wrote: > There are several DOH severs. > > You could also try: > > curl -H 'accept:

Re: [clamav-users] How to determine virus database version from behind proxy?

2020-07-09 Thread Richard Graham via clamav-users
There are several DOH severs. You could also try: curl -H 'accept: application/dns-json' ' https://dns.google.com/resolve?name=current.cvd.clamav.net=A' ... or even just: curl 'https://dns.google.com/resolve?name=current.cvd.clamav.net=A' On Thu, Jul 9, 2020 at 3:51 PM Eric Tykwinski