Re: [clamav-users] Communigate Pro parser fails

2012-09-06 Thread Shawn Webb
Were you able to scan with versions of ClamAV prior to 0.97.5? Can you send me some samples? Thanks, Shawn On Thu, Sep 6, 2012 at 6:15 AM, Victor Sudakov v...@mpeks.tomsk.su wrote: Colleagues, AFAIK clamd can parse Communigate Pro message spool format, where the message itself is preceded

Re: [clamav-users] Windows versions of ClamAV 0.97.6 posted!

2012-09-19 Thread Shawn Webb
Paul, As of 0.97.5, we do not generate CAB or ZIP files for binary builds. The last published ZIP file was for 0.97.4 and is located on Sourcefore. Since MSI files can be extracted, we haven't provided CAB/ZIP files. Thanks, Shawn Webb On Wed, Sep 19, 2012 at 10:03 AM, Joel Esler jes

Re: [clamav-users] Help to download ClamAV 0.97.6 tar.gz source code

2012-10-01 Thread Shawn Webb
On Mon, Oct 1, 2012 at 10:33 AM, Noel Jones njo...@megan.vbhcs.org wrote: This makes getting source code unnecessarily complicated; lots of folks do not use a browser on their production server. Please remove the offending web code immediately. I'm a little confused. From what page would you

Re: [clamav-users] Virus names - a rose by any name?

2013-01-12 Thread Shawn Webb
In addition to having the same sentiments Joel has, I'd like to explain why not displaying the name of the virus does not add any extra security for a number of reasons: 1. Attackers can already deduce ClamAV's engine because it's opensource. They have the blueprints. They already know how it

Re: [clamav-users] Solaris 10 UFS Support?

2013-01-23 Thread Shawn Webb
ClamAV does not currently support scanning file-backed UFS containers. The closest thing that it does support is ISO files. If you can mount the UFS container, ClamAV can scan the mountpoint. Thanks, Shawn On Jan 23, 2013 7:59 AM, Peter Bonivart boniv...@opencsw.org wrote: On Wed, Jan 23,

Re: [clamav-users] Question about a virus

2013-01-30 Thread Shawn Webb
Additionally, if you (April) can provide an MD5 or SHA1 of the sample in question, I can look up if we have coverage for it. On Wed, Jan 30, 2013 at 10:25 AM, Al Varnell alvarn...@mac.com wrote: On Jan 30, 2013, at 6:50 AM, April Wilson awil...@netpilot.com wrote: My question is can ClamAV

Re: [clamav-users] Is there a way to download old clamAV cvd file from 2007, 2009, 2011 etc.?

2013-02-04 Thread Shawn Webb
to do with them, we could figure out a solution that could benefit multiple people. Thanks, Shawn Webb ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [clamav-users] I would like to discuss sample submission with a ClamAV team member

2013-02-12 Thread Shawn Webb
On Tue, Feb 12, 2013 at 7:51 PM, Al Varnell alvarn...@mac.com wrote: On 2/12/13 4:13 PM, Dave Michmerhuizen wrote: I have a regular feed of very new malicious email attachments that are not detected by ClavAV (which we use.) I would like to share them with the ClamAV team, preferably

Re: [clamav-users] daily-16682.cdiff not found on remote server

2013-02-14 Thread Shawn Webb
On Thu, Feb 14, 2013 at 10:59 AM, Matthias Egger maeg...@ee.ethz.ch wrote: Hello Since about two hours we get the following Errors while updating with freshclam: ClamAV update process started at Thu Feb 14 16:51:42 2013 main.cvd is up to date (version: 54, sigs: 1044387, f-level: 60,

Re: [clamav-users] Database Mirror Issues

2013-02-14 Thread Shawn Webb
On Thu, Feb 14, 2013 at 11:00 AM, Clayton Keller inetad...@ruraltel.netwrote: Within the past hour we have started seeing the following errors reported when running freshclam: ERROR: getpatch: Can't download daily-16682.cdiff from db.us.clamav.net ERROR: Can't download daily.cvd from

Re: [clamav-users] TTL on the current.cvd.clamav.net TXT resource record.

2013-02-15 Thread Shawn Webb
We temporarily bumped the TTL up to three hours yesterday to ease the burden on the mirrors while we pushed out a change that would cause a lot of bandwidth. The TTL will be set back to its previous value soon. On Fri, Feb 15, 2013 at 7:26 AM, Kees Theunissen c.j.theunis...@differ.nlwrote: The

Re: [clamav-users] Database Mirror Issues

2013-02-15 Thread Shawn Webb
Due to some hiccups with pushing out a custom daily.cvd I tried to do, you will need to delete the daily.cvd you have. You will download a fresh daily.cvd. Sorry for any inconvenience. On Fri, Feb 15, 2013 at 6:13 PM, Lee Graves leegra...@gmail.com wrote: Here it is in verbose mode. WARNING:

Re: [clamav-users] Database Mirror Issues

2013-02-15 Thread Shawn Webb
It applies to those who are stuck on updates prior to daily.cvd version 16685. On Fri, Feb 15, 2013 at 6:31 PM, Al Varnell alvarn...@mac.com wrote: On Feb 15, 2013, at 3:24 PM, Shawn Webb sw...@sourcefire.com wrote: Due to some hiccups with pushing out a custom daily.cvd I tried to do, you

Re: [clamav-users] Database Mirror Issues

2013-02-15 Thread Shawn Webb
On Fri, Feb 15, 2013 at 8:24 PM, Lee Graves leegra...@gmail.com wrote: Is there any other way around this? It wouldn't be a big deal if it was just a few boxes, but we've got quite a lot affected by this. I wish there was, but there is not. I'm sorry for the inconvenience.

Re: [clamav-users] Freshclam: Error creating socket

2013-02-25 Thread Shawn Webb
Can you paste the whole log, please? On Mon, Feb 25, 2013 at 9:02 AM, Massimo Rossi massimo.ro...@sysdat.itwrote: Hi to all, I'm having an issue updating clamav virus definitions on a CentOS 5 server. When I launch freshclam I obtain ERROR: Can't create new socket. Using clamav or root

Re: [clamav-users] Freshclam: Error creating socket

2013-02-25 Thread Shawn Webb
On Mon, Feb 25, 2013 at 9:22 AM, Massimo Rossi massimo.ro...@sysdat.itwrote: ERROR: Can't create new socket WARNING: getpatch: Can't download daily-16682.cdiff from clamav.mirror.garr.it ERROR: Can't create new socket WARNING: getpatch: Can't download daily-16682.cdiff from

Re: [clamav-users] llvm library

2013-03-15 Thread Shawn Webb
submit patches upstream. We've essentially forked LLVM's source and included the fork within ClamAV's source code. I hope that helps answer your questions. Let me know if you have any further questions or comments. Thanks, Shawn Webb ___ Help us build

Re: [clamav-users] http://blog.clamav.net/2013/02/resolving-issues-with-freshclam.html

2013-03-26 Thread Shawn Webb
an f-level of 63, is correct. You're good to go. Thanks, Shawn Webb ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [clamav-users] SubmitDetectionStats error message after update

2013-03-26 Thread Shawn Webb
On Tue, Mar 26, 2013 at 11:09 AM, Jerry je...@seibercom.net wrote: On Tue, 26 Mar 2013 08:59:19 -0400 Matt Olney articulated: Jerry, is this still an issue for you? Our systems team says there was an issue with the box but that has been resolved. Please let us know, This is the

Re: [clamav-users] SubmitDetectionStats error message after update

2013-03-27 Thread Shawn Webb
On Tue, Mar 26, 2013 at 1:10 PM, Jerry je...@seibercom.net wrote: On Tue, 26 Mar 2013 12:14:52 -0400 Shawn Webb articulated: What version of ClamAV were you running before you updated and what version are you running now? I am running FreeBSD-8.3 amd64. From the ports system, I am now

Re: [clamav-users] Help with clamscan 0.97.7 and mbox files

2013-04-11 Thread Shawn Webb
Hey Scott, This is a known bug in ClamAV 0.97. We've addressed and fixed it in 0.98. Development is ongoing on 0.98 and there isn't a firm release date, yet. Thanks, Shawn On Thu, Apr 11, 2013 at 9:13 AM, Scott Ehrlich sc...@ehrlichtronics.comwrote: Making more progress - using

Re: [clamav-users] Help with clamscan 0.97.7 and mbox files

2013-04-11 Thread Shawn Webb
, what are the needed switches/options to make it work? Thanks. Scott On Thu, Apr 11, 2013 at 9:32 AM, Shawn Webb sw...@sourcefire.com wrote: Hey Scott, This is a known bug in ClamAV 0.97. We've addressed and fixed it in 0.98. Development is ongoing on 0.98 and there isn't a firm release

Re: [clamav-users] Help with clamscan 0.97.7 and mbox files

2013-04-11 Thread Shawn Webb
these results with a 1.5 GB file (thus, less than 2 GB). What is the best way to scan it? Thanks. Scott On Thu, Apr 11, 2013 at 9:42 AM, Shawn Webb sw...@sourcefire.com wrote: Hey Scott, The bug is that ClamAV 0.97 doesn't support scanning large files under Linux. Files greater than 2GB

Re: [clamav-users] Help with clamscan 0.97.7 and mbox files

2013-04-11 Thread Shawn Webb
: cli_updatelimits: filesize exceeded (allowed: abc, needed: xyz) How to fix this? Thanks. Scott On Thu, Apr 11, 2013 at 9:59 AM, Shawn Webb sw...@sourcefire.com wrote: Interesting. Can you send me the log file from clamscan or clamd (whichever you're using to scan the file)? I'll take

Re: [clamav-users] Help with clamscan 0.97.7 and mbox files

2013-04-11 Thread Shawn Webb
Warning: fmap: map allocation failed libclamav Error: CRITICAL: fmap() failed /path/to/mbox-file: Cannot allocate memory ERROR The file is about 1.6 GB. Thanks. Scott On Thu, Apr 11, 2013 at 12:20 PM, Shawn Webb sw...@sourcefire.com wrote: Hey Scott, Can you try setting --max

Re: [clamav-users] Stats - remote server temporary failure

2013-04-30 Thread Shawn Webb
Hey John, We've identified and resolved the problem. Thank you for using ClamAV and for submitting detection statistics. Thanks, Shawn On Tue, Apr 30, 2013 at 9:42 AM, John Horne john.ho...@plymouth.ac.ukwrote: Hello, Using ClamAV 0.97.7 on CentOS 5.9 servers, we see quite a few of the

Re: [clamav-users] Old daily.cld in mirrors?

2013-05-10 Thread Shawn Webb
On Fri, May 10, 2013 at 10:53 AM, Greg Folkert g...@donor.com wrote: I'm seeing similar results. My Private mirror (using clamdownloader.pl) last down loaded daily.cvd and daily-17172.cdiff from the exact same time. Is the DNS update setup broken? Since I see the the CDIFFs and DAILY.CVD

Re: [clamav-users] freshclam checks database every time

2013-06-21 Thread Shawn Webb
On Fri, Jun 21, 2013 at 7:28 AM, Andreas Schulze andreas.schu...@datev.dewrote: I agree if freshclam load a *new* db in case of a *new* pattern version to verify the data are valid. But if no update was available, thats total unnecessary! Is there any clamav developer who could point me into

Re: [clamav-users] Freshclam updates failing

2013-06-21 Thread Shawn Webb
On Fri, Jun 21, 2013 at 8:45 AM, Denis McMahon denismfmcma...@gmail.comwrote: Log at: http://www.sined.co.uk/tmp/freshclam.log.htm All the tests suggested at: https://github.com/vrtadmin/clamav-faq/blob/master/mirrors/MirrorProblems.md appear to suggest that my dns is fine (these are

Re: [clamav-users] Freshclam updates failing

2013-06-22 Thread Shawn Webb
On Sat, Jun 22, 2013 at 8:52 AM, Denis McMahon denismfmcma...@gmail.comwrote: On 22/06/13 04:10, Dennis Peterson wrote: On 6/21/13 5:45 AM, Denis McMahon wrote: appear to suggest that my dns is fine (these are included in the log). I have another machine on the LAN which updates fine.

Re: [clamav-users] Freshclam updates failing

2013-06-22 Thread Shawn Webb
What does your /etc/resolv.conf and /etc/nsswitch.conf look like? On Sat, Jun 22, 2013 at 2:01 PM, Denis McMahon denismfmcma...@gmail.comwrote: On 22/06/13 17:36, Dennis Peterson wrote: On 6/22/13 9:08:48AM, Denis McMahon wrote: $ sudo find / -name mirrors.dat . nothing Rgds Denis

Re: [clamav-users] clamscan produces output to --log=FILE when --quiet, --no-summary and --infected are specified

2013-06-27 Thread Shawn Webb
On Thu, Jun 27, 2013 at 3:35 PM, David Raynor dray...@sourcefire.comwrote: On Thu, Jun 27, 2013 at 2:14 PM, Trevor Cooper tcoo...@ucsd.edu wrote: I'm writing an automated daily scan script and I can't seem to get NO output from clamscan if/when nothing of interest is found. For example,

Re: [clamav-users] False positive Win.Trojan.Bamital-1158 for explorer.exe ?

2013-06-29 Thread Shawn Webb
On Sat, Jun 29, 2013 at 8:45 AM, Peter Maffter petermaff...@yahoo.dewrote: From time to time I am checking my Windows partitions when using Linux on the same machine. Yesterday I got: /windows/C/Windows/SysWOW64/explorer.exe: Win.Trojan.Bamital-1158 FOUND

Re: [clamav-users] Clam 0.97.8 not scanning rar

2013-07-08 Thread Shawn Webb
Attempting to find out who the maintainer is resulted in this IRC conversation: 11:24 lattera anyone know where I can go to find out who the maintainer is for the clamav package? http://dl.fedoraproject.org/pub/epel/6/x86_64/repoview/clamav.html 11:24 lattera I think it's this guy, but the link

Re: [clamav-users] R: engine outdated error

2013-07-26 Thread Shawn Webb
Stefano, What program is generating those warning messages? Can you send me verbose debugging logfiles? (clamscan --debug --verbose /etc/passwd) Thanks, Shawn On Fri, Jul 26, 2013 at 2:45 AM, Stefano Gatto ga...@fly2net.it wrote: I'm sorry I dont understand what you mean when you ask for

Re: [clamav-users] R: R: engine outdated error

2013-07-26 Thread Shawn Webb
-users-boun...@lists.clamav.net] Per conto di Shawn Webb Inviato: venerdì 26 luglio 2013 09:26 A: ClamAV users ML Oggetto: Re: [clamav-users] R: engine outdated error Stefano, What program is generating those warning messages? Can you send me verbose debugging logfiles? (clamscan --debug

Re: [clamav-users] Can't unlink the socket file /var/clamd

2013-07-29 Thread Shawn Webb
On Fri, Jul 26, 2013 at 5:03 AM, andrei vasile enisal_...@yahoo.com wrote: Hello I installed clam from WHM. I have the following error: ERROR: LOCAL: Socket file /var/clamd could not be bound: Permission denied ERROR: Can't unlink the socket file /var/clamd Logwatch say: Not loading

Re: [clamav-users] R: R: engine outdated error

2013-07-29 Thread Shawn Webb
Stefano, on the machine with the problems, can you run freshclam with debug and verbose logging? Since debugging output goes to stderr, you'll want to pipe stderr to stdout (freshclam --debug --verbose 21). Can you re-run clamscan on the same machine with the same flags and with stderr piped to

Re: [clamav-users] NEED HELP

2013-09-19 Thread Shawn Webb
If I understand correctly, by saying local clamav server, you mean that you have set up a local database mirror. Does main-55.cdiff exist on your local mirror? Does main.cvd, version 55 exist on your local mirror? On Thu, Sep 19, 2013 at 11:28 AM, Deevakar PK pkdeeva...@gmail.com wrote: Hi

Re: [clamav-users] 0.98 Outdated

2013-09-19 Thread Shawn Webb
On Thu, Sep 19, 2013 at 4:13 PM, Mike Grau m.g...@kcc.state.ks.us wrote: On a fresh install ClamAV update process started at Thu Sep 19 15:10:21 2013 WARNING: Your ClamAV installation is OUTDATED! WARNING: Local version: 0.98 Recommended version: 0.97.8 DON'T PANIC! Read

Re: [clamav-users] Compiler error: 7z/Types.h:58: redefinition of `Byte'

2013-09-20 Thread Shawn Webb
On Fri, Sep 20, 2013 at 10:38 AM, Bob Cobb bobcob...@hotmail.com wrote: After downloading ClamAV 0.98 I tried to compile it, but I got this error, In file included from 7z/LzmaDec.h:7, from lzma_iface.h:26, from upx.c:59: 7z/Types.h:58: redefinition of

Re: [clamav-users] Compiler error: 7z/Types.h:58: redefinition of `Byte'

2013-09-23 Thread Shawn Webb
On Mon, Sep 23, 2013 at 10:33 AM, Francis Stevens francis.stev...@bristow.co.uk wrote: I have also hit this compilation issue, also on an old RedHat system. Looking in the sources for the file libclamav/7z/Types.h for 0.97.8 there are some edits that seem to be working around this issue which

Re: [clamav-users] Compiler error: 7z/Types.h:58: redefinition of `Byte'

2013-09-23 Thread Shawn Webb
On Mon, Sep 23, 2013 at 12:18 PM, Francis Stevens francis.stev...@bristow.co.uk wrote: Shawn, The patch has wrapped in the post, can you post as an attachment or email to me direct. If you could include the required patch command it would speed things up - I don't use patch often enough to

Re: [clamav-users] Compiler error: 7z/Types.h:58: redefinition of `Byte'

2013-09-23 Thread Shawn Webb
On Mon, Sep 23, 2013 at 4:59 PM, Shawn Webb sw...@sourcefire.com wrote: On Mon, Sep 23, 2013 at 12:18 PM, Francis Stevens francis.stev...@bristow.co.uk wrote: Shawn, The patch has wrapped in the post, can you post as an attachment or email to me direct. If you could include the required

Re: [clamav-users] Compiler error: 7z/Types.h:58: redefinition of `Byte'

2013-09-24 Thread Shawn Webb
On Mon, Sep 23, 2013 at 5:04 PM, Dennis Peterson denni...@inetnw.comwrote: On 9/23/13 1:59:42PM, Shawn Webb wrote: Maybe this time I'll actually attach the patch. ;) I believe the list server discourages attachments. dp Did the patch not go through

Re: [clamav-users] Compiler error: 7z/Types.h:58: redefinition of `Byte'

2013-09-24 Thread Shawn Webb
On Tue, Sep 24, 2013 at 2:21 PM, Rob Sterenborg (lists) li...@sterenborg.info wrote: On 09/24/2013 03:51 PM, Shawn Webb wrote: On Mon, Sep 23, 2013 at 5:04 PM, Dennis Peterson denni...@inetnw.com wrote: On 9/23/13 1:59:42PM, Shawn Webb wrote: Maybe this time I'll actually attach

Re: [clamav-users] Compiler error: 7z/Types.h:58: redefinition of `Byte'

2013-09-25 Thread Shawn Webb
On Wed, Sep 25, 2013 at 4:51 AM, Francis Stevens francis.stev...@bristow.co.uk wrote: Shawn Webb wrote: On Tue, Sep 24, 2013 at 2:21 PM, Rob Sterenborg (lists) li...@sterenborg.info wrote: On 09/24/2013 03:51 PM, Shawn Webb wrote: On Mon, Sep 23, 2013 at 5:04 PM, Dennis Peterson denni

Re: [clamav-users] Clarification required on DisableCertCheck configuration option.

2013-09-25 Thread Shawn Webb
On Wed, Sep 25, 2013 at 7:10 AM, ANANT S ATHAVALE a...@isac.gov.in wrote: Dear List, I am seeing a new option: DisableCertCheck in clamd.conf in 0.98. And in configuration file, it is mentioned that, by default, the signature chain is checked with database. Is this database part of

Re: [clamav-users] - Can't connect to UNIX, socket /var/run/clamav/clamd.ctl

2013-11-01 Thread Shawn Webb
On Fri, Nov 1, 2013 at 5:51 AM, Paolo De Michele pa...@paolodemichele.itwrote: On 11/01/2013 10:11 AM, Paolo De Michele wrote: On 11/01/2013 02:45 AM, Dennis Peterson wrote: On 10/31/13, 5:08 PM, Paolo De Michele wrote: hi everybody, I installed a web/mail server correctly with the

Re: [clamav-users] Warning from Clamav on ISPconfig

2013-12-18 Thread Shawn Webb
On Wed, Dec 18, 2013 at 3:56 PM, EyeLand ournet@gmail.com wrote: Hello, on VPS I install ISPconfig, and on control panel I receive warning from Clamav, can you consult? Thank you! Wed Dec 18 10:33:53 2013 - main.cvd is up to date (version: 55, sigs: 2424225, f-level: 60, builder: neo)

Re: [clamav-users] request for feature

2014-01-31 Thread Shawn Webb
Hey Gene, Thank you for giving us ideas for new features. Our bugzilla system at https://bugzilla.clamav.net/ is the right place to file feature requests. Thanks, Shawn On Fri, Jan 31, 2014 at 2:23 PM, Gene Heskett ghesk...@wdtv.com wrote: Greetings; I have trolled thru the man pages at

Re: [clamav-users] LibhClamAV Warning

2014-02-12 Thread Shawn Webb
On Wed, Feb 12, 2014 at 1:38 PM, Anthony Magrone anthonymagr...@hamlinandburton.com wrote: How can I address the following warning? /etc/cron.daily/autoclam: LibClamAV Warning: SWF: Invalid tag length. LibClamAV info: scancws: Error decompressing SWF file Regards, Anthony Hey Anthony,

Re: [clamav-users] Error message outdated version although yum list installed reports correct version of clamav

2014-02-19 Thread Shawn Webb
On Feb 19, 2014 9:28 PM, Jobst Schmalenbach jo...@barrett.com.au wrote: Hi. Strange problem indeed: [root /tmp] #yum list installed clamav* Loaded plugins: fastestmirror Installed Packages clamav.x86_64 0.98-2.el5.rf installed clamav-db.x86_64

Re: [clamav-users] Introducing OpenSSL as a dependency to ClamAV

2014-02-26 Thread Shawn Webb
On Wed, Feb 26, 2014 at 1:01 PM, Dennis Peterson denni...@inetnw.comwrote: On 2/26/14, 8:08 AM, Joel Esler (jesler) wrote: On Friday last week I put a blog post up about introducing OpenSSL into the ClamAV ecosystem. I wanted to make sure everyone saw it, so please have a look at the blog

Re: [clamav-users] Introducing OpenSSL as a dependency to ClamAV

2014-02-27 Thread Shawn Webb
On Thu, Feb 27, 2014 at 5:56 PM, Lawrence K. Chen, P.Eng. lkc...@ksu.eduwrote: On 02/27/14 02:34, Steve Basford wrote: OpenSSL will be required to both compile and run ClamAV. Out of interest what Cipher: http://zombe.es/post/4078724716/openssl-cipher-selection

Re: [clamav-users] Introducing OpenSSL as a dependency to ClamAV

2014-02-28 Thread Shawn Webb
On Thu, Feb 27, 2014 at 5:56 PM, Lawrence K. Chen, P.Eng. lkc...@ksu.eduwrote: On 02/27/14 02:34, Steve Basford wrote: OpenSSL will be required to both compile and run ClamAV. Out of interest what Cipher: http://zombe.es/post/4078724716/openssl-cipher-selection

Re: [clamav-users] Introducing OpenSSL as a dependency to ClamAV

2014-02-28 Thread Shawn Webb
On Fri, Feb 28, 2014 at 8:59 AM, Richard Conto r...@umich.edu wrote: Can the OpenSSL dependency be abstracted so that GNU TLS could be a replacement as well? (Frankly, I'm speaking out of a bit of ignorance here as I don't know how incompatible GNU TLS is with OpenSSL at the API layer. With

Re: [clamav-users] Introducing OpenSSL as a dependency to ClamAV

2014-02-28 Thread Shawn Webb
On Fri, Feb 28, 2014 at 10:27 AM, Mark Allan markjal...@blueyonder.co.ukwrote: As this is first time ClamAV has had an external dependency, would it be worth making it an opt-out configure option for people who can't get it to compile or who have to rely on an older/incompatible version of

Re: [clamav-users] Introducing OpenSSL as a dependency to ClamAV

2014-03-13 Thread Shawn Webb
On Wed, Mar 12, 2014 at 4:48 PM, Paul Kosinski cla...@iment.com wrote: I'm not worried about dependency on external libraries per se. I just want to know *why*? With libz and libz2, it's pretty obvious, with SSL, it's not clear. Decrypting encrypted data while scanning would need the key. Is

Re: [clamav-users] Problem with Freshclam and local mirror

2014-04-01 Thread Shawn Webb
On Tue, Apr 1, 2014 at 5:30 AM, Simon Hobson li...@thehobsons.co.uk wrote: Because I've several machines using it, I've setup one to act as a local server, with the others pulling their updates from it. It's been generally reliable for years, but since updating to 0.98.1 I'm having repeated

Re: [clamav-users] Problem with Freshclam and local mirror

2014-04-01 Thread Shawn Webb
On Tue, Apr 1, 2014 at 12:47 PM, Shawn Webb sw...@sourcefire.com wrote: On Tue, Apr 1, 2014 at 5:30 AM, Simon Hobson li...@thehobsons.co.ukwrote: Because I've several machines using it, I've setup one to act as a local server, with the others pulling their updates from it. It's been generally

Re: [clamav-users] Silly question - clamav - linux viruses?

2014-04-17 Thread Shawn Webb
In addition to many other file formats, ClamAV recognizes and scans ELF files, the executable file format shared between Linux, BSD, and the other Unixes. The alert name can vary, as Alain pointed out. On Thu, Apr 17, 2014 at 11:26 AM, Dennis Peterson denni...@inetnw.comwrote: On 4/17/14, 8:13

Re: [clamav-users] clamdscan big files problem

2014-04-25 Thread Shawn Webb
On Fri, Apr 25, 2014 at 10:35 AM, SR srju...@gmail.com wrote: Hello everyone, I have happily been using Clamav on our file server for more than a year now. The scan of the different volumes is done by clamdscan which is ran from cron jobs. The problem that I am facing since a few weeks,

Re: [clamav-users] clamdscan big files problem

2014-04-25 Thread Shawn Webb
On Fri, Apr 25, 2014 at 11:35 AM, SR srju...@gmail.com wrote: 2014-04-25 10:58 GMT-04:00 Shawn Webb sw...@sourcefire.com: Hey Stephen, How big is that file? How much RAM (physical and swap separate, please) is installed on the scanning machine? Currently, ClamAV has a hard file limit

Re: [clamav-users] Manual cdiff update

2014-04-28 Thread Shawn Webb
On Fri, Apr 25, 2014 at 8:20 PM, Arthur Snyder snyd...@yahoo.com wrote: I am trying to manually update a daily.cvd file with a daily-xx.cdiff file. I know I can just download the latest daily.cvd. I know I can just run freshclam and update. That is not the point. I run sigtool

Re: [clamav-users] Freshclam and safebrowsing

2014-05-05 Thread Shawn Webb
On Sun, May 4, 2014 at 8:53 AM, Alex mysqlstud...@gmail.com wrote: Hi, I'm running clamav-0.98.1 on fedora20 and was just wondering about safebrowsing.cvd. I notice when freshclam runs, it always downloads an entirely new version when there are any changes, instead of just the differences,

Re: [clamav-users] Crash on reload. Version 0.98.3. Mac OS X 10.7.5

2014-05-07 Thread Shawn Webb
Hey James, Can you paste your clamd.conf file please? Thanks, Shawn On May 7, 2014 9:39 PM, James Brown jlbr...@bordo.com.au wrote: Have just upgraded to version 0.98.3 from 0.98.1. Clamd starts fine, but anytime I reload the database (e.g. running freshclam) clamd will crash. OS X’s

Re: [clamav-users] Compiling error: /usr/lib/libxml2.so: error adding symbols: File in wrong format

2014-05-07 Thread Shawn Webb
What's the output of this command: file /usr/lib/libxml2.so Can you paste (preferably to a pastebin service) your config.log? What options did you pass to ./configure? On Thu, May 8, 2014 at 1:48 AM, Alexander Tampermeier alexan...@tampermeier.at wrote: I have been using ClamAV on my Linux

Re: [clamav-users] Compiling error: /usr/lib/libxml2.so: error adding symbols: File in wrong format

2014-05-08 Thread Shawn Webb
--sysconfdir=/etc/clamav --with-zlib=/usr --with-dbdir=/usr/share/clamav Where 'echo ${BUILD64}' outputs: -m64 I pasted the content of my config.log at http://de.pastebin.de/124754 Regards Alexander Am 08.05.2014 07:52, schrieb Shawn Webb: What's the output of this command: file /usr/lib

Re: [clamav-users] Compiling error: /usr/lib/libxml2.so: error adding symbols: File in wrong format

2014-05-08 Thread Shawn Webb
(CC=gcc ${BUILD64} ./configure ...) at http://de.pastebin.de/124756 Output of command #3 (make) is pasted at http://de.pastebin.de/124757 Regards Alexander Am 08.05.2014 08:40, schrieb Shawn Webb: Can you run these commands, and paste the output of commands 2 and 3 to your pastebin

Re: [clamav-users] Crash on reload. Version 0.98.3. Mac OS X 10.7.5

2014-05-08 Thread Shawn Webb
Hey All, This bug only affects OSX machines and is due to an improper return. This commit fixes it: https://github.com/vrtadmin/clamav-devel/commit/9e47301bc96964b33fe578170296c780924b3b7b Additionally, this bug has been filed as bug 10986: https://bugzilla.clamav.net/show_bug.cgi?id=10986

Re: [clamav-users] Compiling error: /usr/lib/libxml2.so: error adding symbols: File in wrong format

2014-05-08 Thread Shawn Webb
/124761 Regards Alexander Am 08.05.2014 09:29, schrieb Shawn Webb: Did you add the --disable-silent-rules to your ./configure run? It looks like step 3 is still producing friendly output. On Thu, May 8, 2014 at 3:21 AM, Alexander Tampermeier alexan...@tampermeier.at wrote: Hello Shawn

Re: [clamav-users] Crash on reload. Version 0.98.3. Mac OS X 10.7.5

2014-05-08 Thread Shawn Webb
Thanks! I'll have a fix for you first thing in the morning. It looks like there might be a buggy edge case. Thanks, Shawn On May 7, 2014 9:46 PM, James Brown jlbr...@bordo.com.au wrote: On 8 May 2014, at 11:42 am, Shawn Webb sw...@sourcefire.com wrote: Hey James, Can you paste your

Re: [clamav-users] Version 0.98.3 fails on Solaris

2014-05-08 Thread Shawn Webb
On Thu, May 8, 2014 at 11:13 AM, Martin Preen pr...@informatik.uni-freiburg.de wrote: Hello, after building 0.98.3 on Solaris 10 (Sparc) I got some error messages from freshclam. The first run: ERROR: Corrupted database file /var/clamav/main.cvd: Can't allocate memory Corrupted database

Re: [clamav-users] Version 0.98.3 compile failure on Solaris

2014-05-08 Thread Shawn Webb
On Thu, May 8, 2014 at 11:04 AM, Lars Hecking lheck...@users.sourceforge.net wrote: The configure code checking for the newly required openssl library is broken. [...] configure:16590: checking for OpenSSL installation configure:16632: checking for SSL_library_init in -lssl

Re: [clamav-users] Crash on db reload: 0.98.3 (OS: win32, ARCH: i386

2014-05-08 Thread Shawn Webb
On Thu, May 8, 2014 at 11:41 AM, Steve Basford steveb_cla...@sanesecurity.com wrote: Just a quick report... 0.98.3 crashes... 0.98.1 no issues... Thu May 08 15:29:06 2014 - +++ Started at Thu May 08 15:29:06 2014 Thu May 08 15:29:06 2014 - clamd daemon 0.98.3 (OS: win32, ARCH: i386, CPU:

Re: [clamav-users] Version 0.98.3 hard loops on clamdscan -V

2014-05-09 Thread Shawn Webb
On Thu, May 8, 2014 at 10:35 PM, Eric Shubert e...@shubes.net wrote: Immediately after upgrading from 0.98 to 0.98.3, when clamdscan --stdout -V is run (via simscanmk -g), the clamdscan appears to go into a hard loop (eats a lot of cpu endlessly). Here are non-default config settings:

Re: [clamav-users] Version 0.98.3 hard loops on clamdscan -V

2014-05-09 Thread Shawn Webb
: Re: [clamav-users] Version 0.98.3 hard loops on clamdscan -V On 05/09/2014 04:41 AM, Shawn Webb wrote: On Thu, May 8, 2014 at 10:35 PM, Eric Shubert e...@shubes.net wrote: Immediately after upgrading from 0.98 to 0.98.3, when clamdscan --stdout -V is run (via simscanmk -g

Re: [clamav-users] Version 0.98.3 compile failure on Solaris

2014-05-09 Thread Shawn Webb
On Thu, May 8, 2014 at 11:04 AM, Lars Hecking lheck...@users.sourceforge.net wrote: The configure code checking for the newly required openssl library is broken. [...] configure:16590: checking for OpenSSL installation configure:16632: checking for SSL_library_init in -lssl

Re: [clamav-users] Version 0.98.3 fails on Solaris

2014-05-10 Thread Shawn Webb
Hey All, The attached two patches will make building (with gcc) and running on Solaris work. I've also pasted them to the below linked sites in case the attachments don't go through. The patches ought to be applied in order. Patch 1: http://ix.io/ceV (001-clamav-solaris.patch) Patch 2:

Re: [clamav-users] Compiling a minimal version without some of the executables

2014-05-12 Thread Shawn Webb
On Mon, May 12, 2014 at 6:21 PM, Dennis Waters dennis123...@googlemail.comwrote: I'm trying to find a way to compile clamav, but only compiling clamscan and freshclam (and libclamav of course). I've tried searching, tried the documentation, tried ./configure --help. Unfortunately, while I

Re: [clamav-users] Clamav 0.98.3 on RHEL4 - OpenSSL problem

2014-05-16 Thread Shawn Webb
On Fri, May 16, 2014 at 8:56 AM, Dariusz Wojciechowski ad...@faba.plwrote: Hello. I try to compile Clamav 0.98.3 on my quite old server with Red Hat EL 4. I guess I have the same issue as Gary on his Mac OSX 10.5.8: http://comments.gmane.org/gmane.comp.security.virus.clamav.user/39771 I

Re: [clamav-users] [Clamav-devel] ClamAV(R): ClamAV 0.98.4rc1 is now available!

2014-05-20 Thread Shawn Webb
Hey Mark, Is there a way you could get me the sample? Thanks, Shawn On Tue, May 20, 2014 at 6:49 AM, Mark Allan markjal...@blueyonder.co.ukwrote: I may have been a bit hasty with this. It appears there's another issue with clamd. I'm receiving reports of clamd crashing when attempting

Re: [clamav-users] Compiling error: /usr/lib/libxml2.so: error adding symbols: File in wrong format

2014-05-20 Thread Shawn Webb
On Mon, May 19, 2014 at 2:52 PM, MarkusGMX markus@gmx.at wrote: Am 16/05/14 17:57, schrieb Alexander Tampermeier: Sadly, the libxml2-error still persists in v0.98.4-rc1. Hope, it can be fixed soon. [...] :-( I am also waiting for a bugfix for the build process.

Re: [clamav-users] Clamav 0.98.3 on RHEL4 - OpenSSL problem

2014-05-23 Thread Shawn Webb
On Fri, May 23, 2014 at 1:45 PM, Todd Aiken todd.ai...@ubishops.ca wrote: Hi everybody. I was having the same problem, and was able to compile and install a new version of OpenSSL (0.9.8y) to /usr/local/ssl just like the original poster of this thread, but I am still having trouble compiling

Re: [clamav-users] Clamav 0.98.3 on RHEL4 - OpenSSL problem

2014-05-23 Thread Shawn Webb
On Fri, May 23, 2014 at 3:26 PM, Todd Aiken todd.ai...@ubishops.ca wrote: -Original Message- From: Shawn Webb sw...@sourcefire.com Reply-To: ClamAV users ML clamav-users@lists.clamav.net Date: Friday, May 23, 2014 at 1:53 PM To: ClamAV users ML clamav-users@lists.clamav.net Subject

Re: [clamav-users] Clamav 0.98.3 on RHEL4 - OpenSSL problem

2014-05-23 Thread Shawn Webb
On Fri, May 23, 2014 at 3:47 PM, Todd Aiken todd.ai...@ubishops.ca wrote: -Original Message- From: Shawn Webb sw...@sourcefire.com Reply-To: ClamAV users ML clamav-users@lists.clamav.net Date: Friday, May 23, 2014 at 3:32 PM To: ClamAV users ML clamav-users@lists.clamav.net Subject

Re: [clamav-users] Clamav 0.98.3 on RHEL4 - OpenSSL problem

2014-05-26 Thread Shawn Webb
On Mon, May 26, 2014 at 8:58 AM, Todd Aiken todd.ai...@ubishops.ca wrote: -Original Message- From: Shawn Webb sw...@sourcefire.com Reply-To: ClamAV users ML clamav-users@lists.clamav.net Date: Friday, May 23, 2014 at 4:22 PM To: ClamAV users ML clamav-users@lists.clamav.net Subject

Re: [clamav-users] Clamav 0.98.3 on RHEL4 - OpenSSL problem

2014-05-27 Thread Shawn Webb
On Tue, May 27, 2014 at 9:20 AM, Todd Aiken todd.ai...@ubishops.ca wrote: -Original Message- From: Shawn Webb sw...@sourcefire.com Reply-To: ClamAV users ML clamav-users@lists.clamav.net Date: Monday, May 26, 2014 at 4:06 PM To: ClamAV users ML clamav-users@lists.clamav.net Subject

Re: [clamav-users] Clamav 0.98.3 on RHEL4 - OpenSSL problem

2014-05-27 Thread Shawn Webb
On Tue, May 27, 2014 at 11:04 AM, Todd Aiken todd.ai...@ubishops.ca wrote: -Original Message- From: Shawn Webb sw...@sourcefire.com Reply-To: ClamAV users ML clamav-users@lists.clamav.net Date: Tuesday, May 27, 2014 at 10:59 AM To: ClamAV users ML clamav-users@lists.clamav.net

Re: [clamav-users] Tips for low memory systems

2014-05-27 Thread Shawn Webb
You can also take a look at this thread from 2013: http://www.gossamer-threads.com/lists/clamav/users/59413 On Tue, May 27, 2014 at 10:26 PM, Michael Heuberger michael.heuber...@binarykitchen.com wrote: Yeah I know but I am very busy these days. Either an easy solution or I'll buy more RAM

Re: [clamav-users] Communication error

2014-05-30 Thread Shawn Webb
On Fri, May 30, 2014 at 6:21 AM, Henri Salo he...@nerv.fi wrote: Hello list, I've been having lots of problems with scanning major dataset. Command I execute is: clamdscan -i -m --fdpass /mnt/dataset/ --log=clamav.log After some time of processing ClamAV starts to find malware and in this

Re: [clamav-users] Communication error

2014-05-30 Thread Shawn Webb
On Fri, May 30, 2014 at 1:14 PM, Henri Salo he...@nerv.fi wrote: On Fri, May 30, 2014 at 08:16:46AM -0400, Shawn Webb wrote: Hey Henri, Which version of ClamAV are you using? On what OS and architecture? Thanks, Shawn Hello Shawn and thank you for replying, I have this issue

Re: [clamav-users] libclamunrar_iface.so

2014-05-30 Thread Shawn Webb
On May 30, 2014 5:11 PM, Andreas Schulze andreas.schu...@datev.de wrote: Hello, after packaging 0.98.4-rc1 I noticed a message after starting clamav: LibClamAV Warning: Cannot dlopen: file not found – unrar support unavailable solution: ln -s /usr/lib/libclamunrar_iface.so.6

Re: [clamav-users] OpenSSL Security Advisory [05 Jun 2014]

2014-06-07 Thread Shawn Webb
On Sat, Jun 7, 2014 at 3:05 AM, Al Varnell alvarn...@mac.com wrote: Based on the subject document https://www.openssl.org/news/secadv_20140605.txt what, if any vulnerabilities are applicable to the ClamAV® scan engine? Hey Al, Since we use OpenSSL purely for generating hashes, the recent

Re: [clamav-users] DatabaseCustomURL question

2014-06-19 Thread Shawn Webb
On Thu, Jun 19, 2014 at 9:49 AM, Steve Basford steveb_cla...@sanesecurity.com wrote: Hi, Does anyone have DatabaseCustomURL in their freshclam.conf: I've just tried this format... DatabaseCustomURL http://blahblahblah.com:/test.cud And I get an Unknown error ? :) ie... ClamAV

Re: [clamav-users] Does Clamsubmit work?

2014-06-24 Thread Shawn Webb
On Tue, Jun 24, 2014 at 4:36 PM, Daniel Quintiliani d...@runbox.com wrote: Hi, There was a recent thread about ClamAV's low detection rates when compared to other AVs on VirusTotal. When Clamsubmit came out I started using it to submit false negatives, following the two per day rules of

Re: [clamav-users] Malformed database?

2014-06-25 Thread Shawn Webb
On Wed, Jun 25, 2014 at 8:44 AM, Paul Smith p...@pscs.co.uk wrote: On 25/06/2014 13:25, Joel Esler (jesler) wrote: On Jun 25, 2014, at 7:15 AM, Paul Smith p...@pscs.co.ukmailto:paul@ pscs.co.uk wrote: Oh? The FAQ says that the latest two major versions (0.97 and 0.98 ?) are tested against

Re: [clamav-users] Malformed database?

2014-06-25 Thread Shawn Webb
On Wed, Jun 25, 2014 at 8:48 AM, Shawn Webb sw...@sourcefire.com wrote: On Wed, Jun 25, 2014 at 8:44 AM, Paul Smith p...@pscs.co.uk wrote: On 25/06/2014 13:25, Joel Esler (jesler) wrote: On Jun 25, 2014, at 7:15 AM, Paul Smith p...@pscs.co.ukmailto:paul@ pscs.co.uk wrote: Oh? The FAQ

Re: [clamav-users] Problem with ClamAV 0.98.4 - HAVP won't load CVD files

2014-06-26 Thread Shawn Webb
On Thu, Jun 26, 2014 at 12:37 AM, Paul Kosinski cla...@iment.com wrote: I'm using HAVP (0.92) on Linux (openSuSE 13.1) as a virus scanning filter for HTTP traffic. It worked perfectly with ClamAV 0.98.3 (and many previous versions), but now it won't start at all with 0.98.4. HAVP uses

  1   2   >