Re: [clamav-users] Heuristics, only on or off?

2021-03-24 Thread Kris Deugau
Joe Acquisto-j4 wrote: In log find (snipped) ". . .infected by Heuristics.OLE2.ContainsMacros.VBA" This is enabled by the AlertOLE2Macros directive in clamd.conf ". . .infected by Heuristics.Phishing.Email.SpoofedDomain" This is enabled by the PhishingScanURLs directive in clamd.conf. I

Re: [clamav-users] Heuristics, only on or off?

2021-03-24 Thread G.W. Haywood via clamav-users
Hi there, On Tue, 23 Mar 2021, Joe Acquisto-j4 wrote: On Tuesday, March 23, 2021 at 5:02 PM, G.W. Haywood wrote: On Tue, 23 Mar 2021, Joe Acquisto-j4 wrote: ". . .infected by Heuristics.OLE2.ContainsMacros.VBA" and ". . .infected by Heuristics.Phishing.Email.SpoofedDomain" I love the

Re: [clamav-users] Heuristics, only on or off?

2021-03-24 Thread Andrew C Aitchison via clamav-users
On Tue, 23 Mar 2021, Joe Acquisto-j4 wrote: In log find (snipped) ". . .infected by Heuristics.OLE2.ContainsMacros.VBA" and ". . .infected by Heuristics.Phishing.Email.SpoofedDomain" I love the first one but loathe the second one. Is there some secret sauce to allow discriminating between

Re: [clamav-users] Heuristics, only on or off?

2021-03-23 Thread Al Varnell via clamav-users
Sent from my iPad > On Mar 23, 2021, at 18:29, Joe Acquisto-j4 wrote: > > The "spoofed domain" is the one I would rather allow to pass through without > comment or quarantine as some are "legitmate". But the docs did warn > about "false posititves". Although pedantic types (who me?) might

Re: [clamav-users] Heuristics, only on or off?

2021-03-23 Thread Joe Acquisto-j4
> On Tuesday, March 23, 2021 at 5:02 PM, G.W. Haywood wrote: >> On Tue, 23 Mar 2021, Joe Acquisto-j4 wrote: >> >> > In log find (snipped) >> >> Full marks for reading your logs. :) >> >> > ". . .infected by Heuristics.OLE2.ContainsMacros.VBA" >> > >> > and >> > >> > ". . .infected by

Re: [clamav-users] Heuristics, only on or off?

2021-03-23 Thread Mark Pizzolato - Clamav-Win32 via clamav-users
On Tuesday, March 23, 2021 at 5:02 PM, G.W. Haywood wrote: > On Tue, 23 Mar 2021, Joe Acquisto-j4 wrote: > > > In log find (snipped) > > Full marks for reading your logs. :) > > > ". . .infected by Heuristics.OLE2.ContainsMacros.VBA" > > > > and > > > > ". . .infected by

Re: [clamav-users] Heuristics, only on or off?

2021-03-23 Thread G.W. Haywood via clamav-users
Hi there, On Tue, 23 Mar 2021, Joe Acquisto-j4 wrote: In log find (snipped) Full marks for reading your logs. :) ". . .infected by Heuristics.OLE2.ContainsMacros.VBA" and ". . .infected by Heuristics.Phishing.Email.SpoofedDomain" I love the first one but loathe the second one. That's

[clamav-users] Heuristics, only on or off?

2021-03-23 Thread Joe Acquisto-j4
In log find (snipped) ". . .infected by Heuristics.OLE2.ContainsMacros.VBA" and ". . .infected by Heuristics.Phishing.Email.SpoofedDomain" I love the first one but loathe the second one. Is there some secret sauce to allow discriminating between them? joe a