Re: [clamav-users] ClamAV on RHEL 6.8 (IBM Power 8 -PPC64)

2017-05-19 Thread Kishore Pawar
Hi Carlos Velasco & Reindl Harald Thanks for all your help. I guess my ClamAV is looking good now? Here's the latest output after doing some changes based on your inputs. # ls -lrt /var/run/clamav/ total 8 srw-rw. 1 clamav root 0 May 18 20:19 clamav-milter.socket -rw-rw-r--. 1 clamav

Re: [clamav-users] Mail from Paypal wrongly identified as phishing by ClamAv

2017-05-19 Thread Joel Esler (jesler)
I assume G.W. means “using a URL that looks like something this”: src="https://102.112.2O7.net/b/ss/paypalglobal/1/G.4--NS/123456?pageName=system_email_PP1814” -- Joel Esler | Talos: Manager | jes...@cisco.com On May 18, 2017, at 1:15 PM, Reindl Harald

Re: [clamav-users] about signature matching process

2017-05-19 Thread Joel Esler (jesler)
ClamAV will match on multiple signature types. By default it will only alert on the first match, but you can configure this differently. -- Joel Esler | Talos: Manager | jes...@cisco.com On May 19, 2017, at 12:52 PM, Abdullah AL-Mutairy

[clamav-users] about signature matching process

2017-05-19 Thread Abdullah AL-Mutairy
hello everyone i can see that there are different types of signatures in clamAV. there is md5 hashes, rules, byte signatures.. etc when I do a scan on a file, does clamav extract only one of signature of the file or does it extract multiple of signatures of the same file and then compare it with

[clamav-users] FW: clamav-users Digest, Vol 150, Issue 18

2017-05-19 Thread outre...@epsilon.com
Hi Al, Thanks for your input, I will send you a sample. Paypal sends campaigns for all their EMEA countries via our platform, so there are several sending domains used. Do I need to send a sample for each domain? Many thanks, Anne-Sophie -- Message: 11 Date: Thu,

[clamav-users] Bis: ClamAV ScanOnAccess not scanning RHEL7

2017-05-19 Thread Remi Bruggeman
Hello all, By the end of March I mailed about the ScanOnAccess not working on RHEL7. (Ref: https://lists.gt.net/clamav/users/69284#69284 ) Sadly we did not come to a solution at that time. I would like to bump the subject and hope we can come to a solution. I'd like to actively participate in