Re: [clamav-users] Help with clamav

2024-04-10 Thread Andrew C Aitchison via clamav-users
erent clam scans on all my vms. That is likely the price you pay for a scan that doesn't require that you send the whole disk over the network. -Original Message- From: clamav-users On Behalf Of Andrew C Aitchison via clamav-users Sent: 05 April 2024 19:49 To: Nathan Millard via clamav

Re: [clamav-users] False positive?

2024-04-08 Thread Andrew C Aitchison via clamav-users
There are also reports on Reddit today of ClamAV finding this: https://www.reddit.com/r/flatpak/comments/1byn8og/clamav_detecting_winvirusexpiro100265760_malware/?rdt=45424 One reply says: I ran one of the files tagged as a virus by Clamav through VirusTotal.com; out of 64 anti-virus

Re: [clamav-users] freshclam with lambda and S3

2024-04-08 Thread Andrew C Aitchison via clamav-users
On Wed, 3 Apr 2024, Matthew Hibberd via clamav-users wrote: * I am hosting the ClamAV DB files on S3. * I have a lambda routinely running as a cron job that downloads the latest DB files from S3 to a local dir and runs freshclam against said dir as its database directory. *

Re: [clamav-users] Help with clamav

2024-04-05 Thread Andrew C Aitchison via clamav-users
ed by them. -Original Message- From: clamav-users On Behalf Of Andrew C Aitchison via clamav-users Sent: 05 April 2024 17:21 To: Nathan Millard via clamav-users Cc: Andrew C Aitchison Subject: Re: [clamav-users] Help with clamav On Fri, 5 Apr 2024, Nathan Millard via clamav-users

Re: [clamav-users] Help with clamav

2024-04-05 Thread Andrew C Aitchison via clamav-users
On Fri, 5 Apr 2024, Nathan Millard via clamav-users wrote: I would like some help setting up clamav to scan remote hosts from a clamd server is this possible? Nearly. In the likely setup, each client reads the files and sends them to the server for checking. For Linux etc. you can get a

Re: [clamav-users] Squid and ClamAV issues

2024-03-30 Thread Andrew C Aitchison via clamav-users
On Fri, 29 Mar 2024, Jonathan Lee via clamav-users wrote: Does anyone know how to fix this issue for version 335? "The database server doesn't have the latest patch for the bytecode database (version 335). The server will likely have updated if you check again in a few hours. ERROR:

Re: [clamav-users] How does one Obtain ClamAV Linux Anvi-Virus Database File Updates for Systems not Connected to the internet

2024-03-25 Thread Andrew C Aitchison via clamav-users
On Mon, 25 Mar 2024, McCarthy, John D. [US-US] via clamav-users wrote: How does one Obtain ClamAV Linux Anvi-Virus Database File Updates for Systems not Connected to the internet? All our systems are air-gapped (not internet connected) so as ClamAV provides Linux Anvi-Virus Database File

Re: [clamav-users] Debian libmspack breakage to fix y2038

2024-02-29 Thread Andrew C Aitchison via clamav-users
Thanks Scott. Glad to hear that this is under control. On Thu, 29 Feb 2024, Scott Kitterman via clamav-users wrote: On February 29, 2024 12:56:47 PM UTC, Andrew C Aitchison via clamav-users wrote: I haven't fully understood this yet, but Debian is planning a flag-day on 29 March to fix

[clamav-users] Debian libmspack breakage to fix y2038

2024-02-29 Thread Andrew C Aitchison via clamav-users
I haven't fully understood this yet, but Debian is planning a flag-day on 29 March to fix the y2038 bug on 32bit systems (possibly excluding intel). https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1063130 Since clamav uses libmspack it is listed at https://tracker.debian.org/pkg/libmspack

Re: [clamav-users] Need help with clamd on Ubuntu

2024-01-09 Thread Andrew C Aitchison via clamav-users
On Mon, 8 Jan 2024, Marisa Giancarla via clamav-users wrote: Hello. I am trying to get a fresh install of clamav working on Ubuntu 20.04 and I am having issues when starting clamd. When I try and start it, it comes up for maybe 5 secs then shuts itself> down. Anyone have any suggestions?

Re: [clamav-users] An example of why ClamAV should be able to scan disk images (which are typically over 2 GB)

2024-01-06 Thread Andrew C Aitchison via clamav-users
On Tue, 2 Jan 2024, Paul Kosinski via clamav-users wrote: CVE-2021-44879 Wenqing Liu reported a NULL pointer dereference in the f2fs implementation. An attacker able to mount a specially crafted image ^^^ can take

Re: [clamav-users] first questioon????

2023-10-25 Thread Andrew C Aitchison via clamav-users
On Sun, 22 Oct 2023, Rahim Fakir via clamav-users wrote: I would like to know if it is possible to have clamav on the desktop and remotely scan the phone. for example: clamscan -r -i remove=yes ipaddress root.of.cellphone For Android it is likely you can use

Re: [clamav-users] [ext] Compressing log files with clamav

2023-10-24 Thread Andrew C Aitchison via clamav-users
On Tue, 24 Oct 2023, Vu, Hong-Duc V. via clamav-users wrote: Use logrotate: == Thank you Ralf. I take that to mean there is no compression directive in the configuration file by default. Are there plans to add this feature to a future release, Micah? I guess this might be

Re: [clamav-users] Error installing from source

2023-10-13 Thread Andrew C Aitchison via clamav-users
On Fri, 13 Oct 2023, Paul Netpresto wrote: HI You need to find a later version of GCC for your servers. I had a similar problem with some legacy Ubuntu machines. Fortunately an upgrade to GCC 7.5 was available in the Ubuntu release archive. For CentOS 6 the devtoolset-7 suite will give you

Re: [clamav-users] About PDF files detected as encrypted files

2023-10-11 Thread Andrew C Aitchison via clamav-users
On Tue, 10 Oct 2023, Tsutomu Oyamada wrote: Hi, all We received following report from one of our users. The user is uisng Clamd0.103 on AIX7,2. When clamd with the option "ArchiveBlockEncrypted" ON scans a specifc PDF which is locked for editing, it is detected as "Heuristics.Encrypted.PDF

Re: [clamav-users] freshclam not working

2023-09-13 Thread Andrew C Aitchison via clamav-users
On Tue, 12 Sep 2023, Joel Esler via clamav-users wrote: Curl won’t work at all.   But it definitely points to a dns problem.  — Sent from my iPhone On Sep 11, 2023, at 13:07, Serge Slivitzky via clamav-users wrote:   Hi all, I'm using clamav on 2 systems built the same

Re: [clamav-users] Any hard size limit for scanned files?

2023-08-29 Thread Andrew C Aitchison via clamav-users
On Tue, 29 Aug 2023, Ray wrote: my company is considering moving away from ClamAV. They claim there's a file size limitation for scanned files in ClamAV that a commercial product could overcome. Is that true? I found this comment on an Ubuntu forum, which is not too old. It claims there is

Re: [clamav-users] Help clamdscan faster

2023-08-24 Thread Andrew C Aitchison via clamav-users
On Thu, 24 Aug 2023, Nhat Tran Xuan via clamav-users wrote: Hello, We are running a file management project with file storage using amazon S3. Our core architecture is every time there is an event to upload or edit a file on s3, it will trigger an event to run an ECS task, that ECS will be a

Re: [clamav-users] Catching javascript in html attachment

2023-08-04 Thread Andrew C Aitchison via clamav-users
On Fri, 4 Aug 2023, Scott via clamav-users wrote: I was looking for a way to write my own detection mechanisms. I know I can detect binary files by creating signatures with sigtool but this javascript can change like one character and the signature would be off. I'm thinking something more

Re: [clamav-users] ClamAV Current CDN Rate Limit

2023-07-18 Thread Andrew C Aitchison via clamav-users
On Tue, 18 Jul 2023, Jaspreet Nahal via clamav-users wrote: Hi, I'm building an application using ClamAV as our AV of choice and trying to evaluate the different approaches to avoiding hitting the CDN more than what is absolutely necessary. As a part of this quest, would you be able to share

Re: [clamav-users] Question About MaxFileSize

2023-06-08 Thread Andrew C Aitchison via clamav-users
On Thu, 8 Jun 2023, Micah Snyder (micasnyd) wrote: I agree with you. I suspect the majority of cases today is when people have a large archive of files to scan. I think best case scenario for people with a need to scan files larger than the present internal 2GB limit is that archives larger

Re: [clamav-users] Question About MaxFileSize

2023-05-24 Thread Andrew C Aitchison via clamav-users
On Wed, 24 May 2023, Tachibanaki Nozomi (橘木 希美) wrote: Dear Sir or Madam, Thank you for your help always. I am contacting you to ask about MaxFileSize in clamd.conf. The following description is found in the configuration of /usr/local/etc/clamd.conf. MaxFileSize # Technical design

Re: [clamav-users] How to get rid of or Fix clamonacc error

2023-03-22 Thread Andrew C Aitchison via clamav-users
[ My previous reply did not reach the list, for reasons I do understand. ] On Tue, 21 Mar 2023, Tim McConnell wrote: Hi Andrew, So maybe I'm mis understanding something. I'm expecting the scan to run once daily at 01:00. Is that not what clamonacc does? I keep getting told to remove it but

Re: [clamav-users] clamdscan: show clean files?

2023-03-13 Thread Andrew C Aitchison via clamav-users
On Mon, 13 Mar 2023, Schulze, Andreas via clamav-users wrote: Hello, we like to scan directories an gather verbose reports. These must include information about the scan result for each file. Using clamdscan, this does not happen: clamdscan inform only on infected files. # clamdscan

Re: [clamav-users] linux distribution including clamav-1.0.1

2023-03-07 Thread Andrew C Aitchison via clamav-users
On Tue, 7 Mar 2023, kumar bava via clamav-users wrote: Hi, please help me with the below question, thank you We have been using clamav-0.103.6 and would like to upgrade to the new LTS release(1.0.x). However, I can not find clamav-1.0.1 in EPEL distribution. Our systems are based on rhel7. So

Re: [clamav-users] What was detected?

2023-02-27 Thread Andrew C Aitchison via clamav-users
On Mon, 27 Feb 2023, joe a wrote: 66 On 2/27/2023 4:24 PM, Paul Netpresto wrote: I attempted that just now. Ran clamscan --debug -f some-email.eml After it cranks up and apparently beings actually scanning the email, starts cranking out errors/warnings like: Return-path: : No such file or

Re: [clamav-users] Funny --include-dir behaviour

2023-02-13 Thread Andrew C Aitchison via clamav-users
Sorry thi is coming sd an attachment. I sent this with the wrong from address so it didn't reach the list the first time. -- Andrew C. Aitchison Kendal, UK and...@aitchison.me.uk--- Begin Message --- On Mon, 13 Feb 2023, newcomer01 via clamav-users

Re: [clamav-users] about ”Can't allocate memory ERROR”

2023-02-09 Thread Andrew C Aitchison via clamav-users
On Thu, 9 Feb 2023, Tsutomu Oyamada wrote: Hi, Andy. Thanks for your reply. I am aware that version 0.103.4 is still supported by LTS. 0.103.4 came out in Nov 2021. The current supported versions include 0.103.7 from July 2022. Also, my system is AIX. Does that have an effect? I would

Re: [clamav-users] Problem with freshclam

2022-12-29 Thread Andrew C Aitchison via clamav-users
[ Apologies, my previous reply failed to reach the list. ] On Thu, 29 Dec 2022, newcomer01 wrote: Yes, the "Error-Log" comes only when freshclam will be started from reboot via cron job Did I understand you well? @reboot host -t txt current.cvd.clamav.net /etc/clamav/clamav_opts

Re: [clamav-users] LibClamAV Warning: PNG: Unexpected early end-of-file.

2022-12-12 Thread Andrew C Aitchison via clamav-users
On Mon, 12 Dec 2022, newcomer01 wrote: Well on my PC I changed a lot because the naming was too messy for me. I have "program" clam*d*scan for which I have a clam*d*.conf and a "program" clamscan for which I have a clamscan.conf. And then the normal "program" freshclam with the

Re: [clamav-users] LibClamAV Warning: PNG: Unexpected early end-of-file.

2022-12-12 Thread Andrew C Aitchison via clamav-users
On Mon, 12 Dec 2022, newcomer01 via clamav-users wrote: can nobody explain, what this message exactly mean? I Get the on lot of my E-mails LibClamAV Warning: PNG: Unexpected early end-of-file. That just means that the PNG file is either not a PNG for or is corrupted - perhaps truncated.

Re: [clamav-users] Ubuntu file needed

2022-12-09 Thread Andrew C Aitchison via clamav-users
On Fri, 9 Dec 2022, newcomer01 via clamav-users wrote: can someone showm me screesnhots on the setted permissons from: / etc/ init.d / clamav-daemon and / etc / init.d / freshclam please? And additionally must this files run as program too? This should have all that information: # ls -l

Re: [clamav-users] parallel processes fail at startup when clamd is running

2022-11-28 Thread Andrew C Aitchison via clamav-users
On Mon, 28 Nov 2022, JOHN URBAN via clamav-users wrote: We are experiencing a large number of MPI jobs failing indicating the fabric is unavailable when the scans are running. Early in the investigation so not sure if locking, timing, response time or other factors are involved, but I wanted

Re: [clamav-users] ClamAV scan time improvement

2022-11-09 Thread Andrew C Aitchison via clamav-users
On Tue, 8 Nov 2022, Vijay Kumar Kamannavar via clamav-users wrote: Hello Team, We are leveraging ClamAV agent for our vm's malware detection. we tried to scan a vm with 30GB used space and it took approx 1.30Hrs(we tried to capture certain file extensions to reduce number of files and

Re: [clamav-users] [ext] ClamAV 1.0.0 release candidate now available

2022-11-02 Thread Andrew C Aitchison via clamav-users
On Wed, 2 Nov 2022, Micah Snyder (micasnyd) wrote: Hi Andrew, Should cli_cvdverify() even be used to verify .cld files ? Indeed, it should not. Here is my PR to fix the issue. Are you able to try it out to help verify it resolves the issue on your end?

Re: [clamav-users] [ext] ClamAV 1.0.0 release candidate now available

2022-10-30 Thread Andrew C Aitchison via clamav-users
On Fri, 28 Oct 2022, Yasuhiro Kimura wrote: From: Ralf Hildebrandt via clamav-users Subject: Re: [clamav-users] [ext] ClamAV 1.0.0 release candidate now available Date: Fri, 28 Oct 2022 09:10:46 +0200 * Micah Snyder (micasnyd) via clamav-users : We are excited to announce the ClamAV 1.0.0

Re: [clamav-users] ClamAV 1.0.0 release candidate now available

2022-10-28 Thread Andrew C Aitchison via clamav-users
On Tue, 25 Oct 2022, Micah Snyder (micasnyd) via clamav-users wrote: Read this announcement online at https://blog.clamav.net/2022/10/clamav-100-release-candidate-now.html We are excited to announce the ClamAV 1.0.0 release candidate! You may find the source code and installers for this

Re: [clamav-users] ClamAV on RHEL9 with FIPS enabled

2022-10-27 Thread Andrew C Aitchison via clamav-users
On Wed, 26 Oct 2022, Orion Poplawski via clamav-users wrote: On 10/24/22 11:03, Hoevenaar, Jeffrey (GE Aerospace, US) via clamav-users wrote: Hello, It would appear ClamAV will not run on RHEL9 with FIPS enabled. Has anyone else seen this issue? Known issue:

[clamav-users] Incremental updates and server memory

2022-09-08 Thread Andrew C Aitchison via clamav-users
I guess that this would be a long term project ... The malware databases are updated with cdiffs, which means that the whole database does not have to be re-downloaded with each update. However, the running daemon has to re-read the whole database from disk (temporarily doubling the memory

Re: [clamav-users] No daily sig since July 28th

2022-08-01 Thread Andrew C Aitchison via clamav-users
On Mon, 1 Aug 2022, Shawn Iverson via clamav-users wrote: Hello, I've noticed that a daily hasn't been posted since the 28th of July. Are daily sigs being posted? # clamscan --version ClamAV 0.103.7/26615/Thu Jul 28 08:58:07 2022 # host -t txt current.cvd.clamav.net. current.cvd.clamav.net

Re: [clamav-users] ClamAV's 'configure' doesn't seem to complain about invalid options

2022-07-22 Thread Andrew C Aitchison via clamav-users
On Thu, 21 Jul 2022, Paul Kosinski via clamav-users wrote: Building 0.103.6, I ran 'configure' with the option "--disable-clamonaccess" (instead of "--disable-clamonacc") and got no error or warning that the option was not recognized. I did this because I realized that I had still been using

Re: [clamav-users] Where can I download daily.cvd, bytecode.cvd and main.cvd from?

2022-01-17 Thread Andrew C Aitchison via clamav-users
On Mon, 17 Jan 2022, Nick Howitt via clamav-users wrote: On 17/01/2022 14:33, Andrew C Aitchison wrote: Not quite. I have taken over the packaging of this and the justification of packaging the sigs is partly that the tool will work and scan out of the box, partly for the offline

Re: [clamav-users] Where can I download daily.cvd, bytecode.cvd and main.cvd from?

2022-01-17 Thread Andrew C Aitchison via clamav-users
On Mon, 17 Jan 2022, Nick Howitt via clamav-users wrote: Isn't that a bit messy? It would be so much easier to be able to use curl, wget or any browser to get the sigs so we can package them directly Unfortunately the server load was ridiculus and that had to be stopped. Petabyte per day

Re: [clamav-users] Problem installing ClamAV 104.1 on CentOS 7

2021-12-07 Thread Andrew C Aitchison via clamav-users
On Mon, 6 Dec 2021, Bowie Bailey via clamav-users wrote: I followed the instructions to install the prerequisites and then went through the steps for the default build.  Everything went fine until I got to the last step. $ sudo cmake --build . --target install sudo: cmake: command not found

Re: [clamav-users] using older clients to download from internal clam proxy

2021-12-02 Thread Andrew C Aitchison via clamav-users
On Thu, 2 Dec 2021, novpenguincne via clamav-users wrote: Thank you for the quick response. So that would lead into the logical next question. What would be the earliest client version that would work? I tried installing the 103.x client on that box but 103.x requires SystemD and this older

Re: [clamav-users] Nonsensical noreplies from ClamAV team

2021-11-18 Thread Andrew C Aitchison via clamav-users
On Thu, 18 Nov 2021, Alessandro Vesely via clamav-users wrote: Hi all, even though I filter incoming messages with ClamAV, last Monday I received a mail with two suspicious attachments. They were PE32+ executable (DLL) (GUI) x86-64, for MS Windows. I uploaded the samples to

Re: [clamav-users] how to build release 0.104.1 in non-standard systems

2021-11-05 Thread Andrew C Aitchison via clamav-users
On Fri, 5 Nov 2021, anctop--- via clamav-users wrote: We are using ClamAV on our server for protection against virus. However, the build method (using "cmake") for the new 0.104.1 release has prevented us from upgrading promptly as before. While you are getting cmake to do what you need,

Re: [clamav-users] Docker Connection Refused on Host

2021-10-10 Thread Andrew C Aitchison via clamav-users
On Sun, 10 Oct 2021, Taylor Schley via clamav-users wrote: ClamD setup in the docker container is: `/run/clamav/clamd.socket` Which is bound to `/tmp/clamd.socket` on the host MacOS. The following works from inside of the container: `clamdtop ‘/run/clamav/clamd.socket’` The

Re: [clamav-users] Scanning a zip file fails, extract it, scan with the same options and it passes

2021-10-04 Thread Andrew C Aitchison via clamav-users
What are the compressed and uncompressed sizes of the problem file ? On Fri, 1 Oct 2021, Max Allan via clamav-users wrote: Hi, I have a requirement (from the business) to AV scan all docker containers we create. I started experimenting with tomcat:latest, which is handy because you can

Re: [clamav-users] error code 429

2021-09-05 Thread Andrew C Aitchison via clamav-users
[ Top-posting to be consistent with previous message.] I had the same problem as Jim and Paul (which resolved itself at about 03:00 UTC, after ~19 hours). I am running the 0.103.2 from Ubuntu 21.04. On Sun, 5 Sep 2021, Joel Esler (jesler) via clamav-users wrote: We are experimenting with a

Re: [clamav-users] can't cmake 1.0.4rc

2021-07-30 Thread Andrew C Aitchison via clamav-users
On Thu, 29 Jul 2021, Gene Heskett via clamav-users wrote: Well, I've screwed around with this for 3 days now, that's long enough. First gotcha for debian people is cmake is not installed, and when installed, it is NOT installed in a directory accessible to the user with a default $PATH, so the

Re: [clamav-users] can't cmake 1.0.4rc

2021-07-30 Thread Andrew C Aitchison via clamav-users
On Fri, 30 Jul 2021, Gene Heskett via clamav-users wrote: I see by synaptic, that both python-test and python3-test are available. Which is preferred? I'd assume python3-test in order to future proof, but assumptions are where we've gone aglay too many times already. My experience on

Re: [clamav-users] Long Term Support (LTS) program proposal

2021-07-29 Thread Andrew C Aitchison via clamav-users
Executive Summary: An LTS release every two years, supported for three, starting with 0.103 sound good to me. Thank you. On Wed, 28 Jul 2021, Micah Snyder (micasnyd) via clamav-users wrote: For the past couple of months I've been promoting the idea of having Long Term Support (LTS) feature

Re: [clamav-users] Freshclam - can't apply latest patch 26246

2021-07-29 Thread Andrew C Aitchison via clamav-users
On Thu, 29 Jul 2021, Asenova, Elia via clamav-users wrote: Thanks for the replies. Yes, deleting daily.cld fixed the problem. My concern is that I'm building a docker image with clamav inside it and I have to delete daily.cld on every new build if I want freshclam to work correctly the first

Re: [clamav-users] Freshclam - can't apply latest patch 26246

2021-07-28 Thread Andrew C Aitchison via clamav-users
On Wed, 28 Jul 2021, Asenova, Elia via clamav-users wrote: Hello guys, This is related to a freshclam update problem that I have. Basically when running freshclam I get the following errors: ClamAV update process started at Wed Jul 28 14:30:20 2021 daily database available for update (local

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Release Candidate is here!

2021-07-28 Thread Andrew C Aitchison via clamav-users
On Wed, 28 Jul 2021, Rick Cooper wrote: total disregard for the user base, not so much as a poll or query on the lists, When ClamAV 0.103 was released in September 2020 CMake was an *experimental* option. There will be a 0.103 release in September 2021, but is likely to be the last one.

Re: [clamav-users] can't cmake 1.0.4rc

2021-07-28 Thread Andrew C Aitchison via clamav-users
On Wed, 28 Jul 2021, Gene Heskett via clamav-users wrote: cmake --version RETURN says: cmake version 3.7.2 Ah. INSTALL.md says: ### Build requirements - CMake 3.16 for Windows, and 3.14+ for other operating systems. CMake suite maintained and supported by Kitware

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Release Candidate is here!

2021-07-26 Thread Andrew C Aitchison via clamav-users
On Mon, 26 Jul 2021, Frans de Boer wrote: Here's your problem: 8<-- [DEBUG]: Exit code: 1 [DEBUG]: stdout: Running suite(s): clamd 90%: Checks: 77, Failures: 7, Errors: 0

[clamav-users] Signature delimiter - was Re: ClamAV® blog: ClamAV 0.104.0 Release Candidate is here!

2021-07-22 Thread Andrew C Aitchison via clamav-users
On Thu, 22 Jul 2021, G.W. Haywood via clamav-users wrote: "~/clamav-0.104.0-rc/build: $ cmake .. -D CMAKE_BUILD_TYPE="Release"" "CMake Error at CMakeLists.txt:6 (cmake_minimum_required):" "CMake 3.14 or higher is required. You are running version 3.13.4" "" "" "-- Configuring incomplete,

Re: [clamav-users] Qnap TS-259Pro+

2021-07-13 Thread Andrew C Aitchison via clamav-users
The TS-259Pro+ appears go have 1GB RAM, which is not really enough to run clamav, so compiling from source is unlikely to be helpful. On Tue, 13 Jul 2021, Eero Volotinen wrote: You probably need to buy newer version of qnap nas or compile clamav from sources. Eero On Tue 13. Jul 2021 at

[clamav-users] Fw: openSUSE-SU-2021:2242-1: important: Security update for clamav-database

2021-07-07 Thread Andrew C Aitchison via clamav-users
On Wed, 7 Jul 2021, Joe Acquisto-j4 wrote: > On Tue, 6 Jul 2021, Joe Acquisto-j4 wrote: > > On Tue, 6 Jul 2021, G.W. Haywood wrote: > > > On Tue, 6 Jul 2021, Paul Kosinski via clamav-users wrote: > > > > > > > Just FYI: this is the first time I remember seeing openSUSE > > > > notifying

Re: [clamav-users] clamdscan "Can't get file status ERROR"

2021-06-21 Thread Andrew C Aitchison via clamav-users
On Mon, 21 Jun 2021, Roger Rutishauser wrote: I'm using ClamAV 0.101.1/26207 with default clamd.config settings (except for enhanced logging) Please update to the latest version 0.103.2 See many recent messages in this list - you could be blocked for using an older version. I have a PDF

Re: [clamav-users] Regarding increasing ClamAV file size while using docker

2021-06-08 Thread Andrew C Aitchison via clamav-users
On Tue, 8 Jun 2021, Karthik Iyer via clamav-users wrote: Hi, I would like to scan files as big as 100 gb. At present you cannot: https://lists.clamav.net/pipermail/clamav-users/2021-April/011018.html The code is not 64bit clean (maybe not even 32bit clean - the developers only guarantee

Re: [clamav-users] Manually copy and use local filesystem as DownloadMirror/PrivateMirror

2021-05-17 Thread Andrew C Aitchison via clamav-users
Anish, What sort of scanning are you doing on these client machines ? Which databases are you using with ClamAV ? What data is stored on these clients ? What operating system(s) are they running ? I ask since the way some of us run ClamAV there is little benefit on running it on each client

Re: [clamav-users] clamav incremental scan?

2021-05-09 Thread Andrew C Aitchison via clamav-users
On Tue, 4 May 2021, Michael Wang wrote: I do not disagree with you on the separate functionality of the scheduling engine and scanning engine. The question is: does such an engine exist? ClamWin has a scheduler https://clamwin.com/content/view/71/1/ but, although based on ClamAV,

Re: [clamav-users] ClamAV® blog: ClamAV 0.103.2 security patch release

2021-04-14 Thread Andrew C Aitchison via clamav-users
Joel, You can add a direct link to the PGP key now as this is completely independant of the released packages. Better yet would be to 1) Sign the new key with the old one (which doesn't actually expire until Monday) 2) Get other (public domain) software people to sign your key. This assumes

Re: [clamav-users] Unable to Update

2021-04-13 Thread Andrew C Aitchison via clamav-users
On Tue, 13 Apr 2021, j via clamav-users wrote: I've been getting the following message'WARNING: getpatch: Can't download daily-26093.cdiff from database.clamav.net WARNING: getpatch: Can't download daily-26093.cdiff from database.clamav.net WARNING: getpatch: Can't download

Re: [clamav-users] Error 429 when updating database

2021-04-08 Thread Andrew C Aitchison via clamav-users
On Thu, 8 Apr 2021, Joel Esler (jesler) via clamav-users wrote: Still, 102.4 should work properly, shouldn't it? It does. But 103.2 handles the downloads and interactions SO MUCH BETTER (I’ve been watching the updates for 103.2’s FreshClam all morning, and it’s working so much better.

Re: [clamav-users] vistumbler as false positive

2021-04-08 Thread Andrew C Aitchison via clamav-users
On Thu, 8 Apr 2021, Eero Volotinen wrote: https://raw.github.com/acalcutt/Releases/master/Vistumbler/VistumblerMDB/v10/Vistumbler_v10-7.exe Looks like this is (vistumbler) detected as false positive. and On Thu, 8 Apr 2021, Arnaud Jacques wrote: At first look, ClamAV is not the only one

Re: [clamav-users] clamscan suddenly taking 25 minutes for a single mail

2021-04-06 Thread Andrew C Aitchison via clamav-users
On Tue, 6 Apr 2021, Eddie via clamav-users wrote: A POP3 proxy program I have running on a Debian 10.8 system, uses clamscan to check incoming e-mails.  At some point in the very early morning (US West Coast time) it suddenly started taking a very long time to scan each mail,  So much that

Re: [clamav-users] ClamAV 0.103.1 on RHEL 6.7 x32

2021-04-06 Thread Andrew C Aitchison via clamav-users
On Tue, 6 Apr 2021, Sorin Petrut Niculae via clamav-users wrote: Can anyone confirm if is possible to use ClamAV on RHEL 6.7 x32 I was able to install and copy the ddbb files (manually) to /usr/local/share/clamav but when I run clamscan I got the next error message: * [redhat@redhat

Re: [clamav-users] Need help | Install clamav from source package

2021-03-28 Thread Andrew C Aitchison via clamav-users
Could you take the latest OpenSuSE source package and build that ? That might be an easier way to get SuSE-friendly config files than starting from the source on the ClamAV site. If the latest ClamAV source package on the latest OpenSuSE doesn't work, try the latest ClamAV source from an

Re: [clamav-users] Heuristics, only on or off?

2021-03-24 Thread Andrew C Aitchison via clamav-users
On Tue, 23 Mar 2021, Joe Acquisto-j4 wrote: In log find (snipped) ". . .infected by Heuristics.OLE2.ContainsMacros.VBA" and ". . .infected by Heuristics.Phishing.Email.SpoofedDomain" I love the first one but loathe the second one. Is there some secret sauce to allow discriminating between

Re: [clamav-users] Number of signatures downloaded has reduced significantly

2021-03-23 Thread Andrew C Aitchison via clamav-users
On Tue, 23 Mar 2021, Pierre Olivier KAPLAN wrote: A few days ago, it seems that you have changed your hosts and your signatures file base format. Since, we noticed that the amount of included signatures has been divided by 3 (from 1.904 M to 641 k). A lot of hashes have disappeared. Did the

Re: [clamav-users] ClamAV® blog: ClamAV, CVDs, CDIFFs and the magic behind the curtain

2021-03-20 Thread Andrew C Aitchison via clamav-users
On Fri, 19 Mar 2021, Joel Esler (jesler) via clamav-users wrote: https://blog.clamav.net/2021/03/clamav-cvds-cdiffs-and-magic-behind.html ClamAV, CVDs, CDIFFs and the magic behind the curtain 3. ... This is an expensive operation in terms of bandwidth because daily.cvd and main.cvd are,

Re: [clamav-users] Restriction of downloads

2021-03-13 Thread Andrew C Aitchison via clamav-users
On Sat, 13 Mar 2021, Matus UHLAR - fantomas wrote: I just found that my "antivirus essentiel" installed package provided by Synology is unable to update virus definition file since 03/06/2021 ! On 13/03/2021 00:47, G.W. Haywood via clamav-users wrote: Then should you not be talking to

Re: [clamav-users] Unable to download clamav cvd file using google cloud python function

2021-03-11 Thread Andrew C Aitchison via clamav-users
On Thu, 11 Mar 2021, Paul Smith via clamav-users wrote: On 10/03/2021 22:29, Joel Esler (jesler) via clamav-users wrote: 100 CDIFFs or so behind, and they download it nearly 2k times in a row?  Why?  This is not a partial download either.  It’s the full file.  Stuck cron? Who in the past

Re: [clamav-users] Clamav-milter finds postive, goes to hold queue

2021-02-23 Thread Andrew C Aitchison via clamav-users
On Tue, 23 Feb 2021, Joe Acquisto-j4 wrote: Wondering now what people generally do with infected mail? That is, is there a general consensus? Would it be "safe" (for the systems) to simply send the mail through, to the end use and merely tag the subject line with "Virus Detected" as SPAM

Re: [clamav-users] ClamAV not even mentioned in article "The 6 Best Antiviruses for Linux 2021"

2021-02-19 Thread Andrew C Aitchison via clamav-users
On Fri, 19 Feb 2021, Paul Kosinski via clamav-users wrote: https://www.safetydetectives.com/best-antivirus/linux/ Usability. Linux programs tend not to be easy to use in fact, they often run on command line only. But because it's so crucial that cybersecurity software is configured

Re: [clamav-users] How to exclude specific files from clamdscan

2021-01-27 Thread Andrew C Aitchison via clamav-users
On Wed, 27 Jan 2021, G.W. Haywood via clamav-users wrote: Hi there, On Wed, 27 Jan 2021, Michael Kyriacou via clamav-users wrote: > ... I am using clamav version 0.102.4, on Ubuntu 20.04. You really should be upgrading to the latest version. Sadly, 0.102.4 *is* the latest packaged

Re: [clamav-users] Trying to use daemon service to scan on demand with php

2021-01-23 Thread Andrew C Aitchison via clamav-users
On Sat, 23 Jan 2021, Paul Claridge wrote: My current project is a web service on Ubuntu LAMP (20.02LTS). I have installed the clamav-daemon package successfully. My php scripts run as www-data:www-data and I have changed the user and group in /etc/clamav/clamd.conf to www-data:www-data so

Re: [clamav-users] usb boot drive

2021-01-08 Thread Andrew C Aitchison via clamav-users
On Fri, 8 Jan 2021, Kyjana via clamav-users wrote: Hello, I recently made a bootable USB drive that runs Linux and I was wondering if I could install ClamAV on it without issues or if it would mess with any of the boot files. Sorry if this is a stupid question I just want to make sure I don't

Re: [clamav-users] Terminate clamscan after specific time

2021-01-07 Thread Andrew C Aitchison via clamav-users
On Thu, 7 Jan 2021, G.W. Haywood via clamav-users wrote: Hi there, On Wed, 6 Jan 2021, Zvi Kave via clamav-users wrote: Can you send link to your posts about root directory scan? https://marc.info/?l=clamav-users=1=2 The footer of every message from the list has a link

Re: [clamav-users] Terminate clamscan after specific time

2021-01-06 Thread Andrew C Aitchison via clamav-users
Would it be better to *pause* the scan if/when the computer gets busy ? If you "nice" the scan it will only run when the cpu is less busy; if you have "ionice" you can make it run when the disk is less busy. On Wed, 6 Jan 2021, Zvi Kave via clamav-users wrote: Hi , My goal is to terminate

Re: [clamav-users] local server takes time to update clamav db

2020-12-10 Thread Andrew C Aitchison via clamav-users
On Thu, 10 Dec 2020, Joel Esler (jesler) via clamav-users wrote: So, there are occasions where one PoP from Cloudflare is behind and hasn't yet fetched the file from the other PoP or from our mirror directly. This might be the case that you're the first one that's asked for it from your PoP

Re: [clamav-users] local server takes time to update clamav db

2020-12-10 Thread Andrew C Aitchison via clamav-users
Date: Thu, 10 Dec 2020 14:07:08 + (GMT) From: Andrew C Aitchison To: clamav-users@lists.clamav.net Cc: "Joel Esler (jesler)" Subject: Re: [clamav-users] local server takes time to update clamav db On Thu, 10 Dec 2020, Joel Esler (jesler) via clamav-users wrote: On Dec 10, 2020, at 6:06

Re: [clamav-users] Fwd: Re: Clamav File - Virus detected by Microsoft Defender

2020-11-28 Thread Andrew C Aitchison via clamav-users
On Sat, 28 Nov 2020, G.W. Haywood via clamav-users wrote: Hi there, On Sat, 28 Nov 2020, Alejandro Hernández via clamav-users wrote: On Fri, 27 Nov 2020, G.W. Haywood worte: > 3. To which (.tmp) file do you refer? There was an image attached with the name. :D No, I don't think so. :( But

Re: [clamav-users] Clamd freshclam Service

2020-11-26 Thread Andrew C Aitchison via clamav-users
On Thu, 26 Nov 2020, Will Watters via clamav-users wrote: Hello, Is there anywhere to get clamd freshclam file to run as a daemon for Centos 6 please, so the service can be stopped and started, etc. I have this for Centos 7 but is systemd residing in

Re: [clamav-users] Regarding ClamAV code coverage metrics with help of existing unit-test cases

2020-11-26 Thread Andrew C Aitchison via clamav-users
On Thu, 26 Nov 2020, Satish Kumar via clamav-users wrote: Dear All, I would like to build the ClamAV software from source code on an ubuntu machine and  measure the  code coverage of the ClamAV project with the help  of existing unit test cases in the ClamAV project  for that,

Re: [clamav-users] clamav scan of changed files

2020-10-22 Thread Andrew C Aitchison via clamav-users
On Wed, 21 Oct 2020, G.W. Haywood via clamav-users wrote: On Wed, 21 Oct 2020, Andrew C Aitchison via clamav-users wrote: > and that using clamav's on-access scanning has the advantage of catching the > nasties before the file is used, unlike the inotify-bsed solutions, which &

Re: [clamav-users] clamav scan of changed files

2020-10-21 Thread Andrew C Aitchison via clamav-users
On Wed, 21 Oct 2020, giovanni+cla...@paclan.it wrote: On 10/21/20 4:08 AM, Olivier via clamav-users wrote: > Hi > > > I would like to know what would be the best way to do a virus scan of > > changed or new files only. I > > want to run a daily scan of changed and new files during

Re: [clamav-users] ransomware

2020-10-03 Thread Andrew C Aitchison via clamav-users
To the best of my knowledge, ClamAV does not *remove* any malware. It is usually used to detect malware *prior* to infection; and I do not think that much effort has been made to teach it to detect infected systems (please tell me if I am wrong). On Sat, 3 Oct 2020, Mat via clamav-users

Re: [clamav-users] clamscan --disable-cache

2020-09-30 Thread Andrew C Aitchison via clamav-users
On Wed, 30 Sep 2020, Dave Sill via clamav-users wrote: "G.W. Haywood via clamav-users" wrote: In the second scan, how did clamscan manage to do what it claims to have done in the time that it did it? OK, you could have just said that the cache is internal to each invocation of clamscan,

Re: [clamav-users] Scanning an MP3 , MP4 and JPEG files

2020-09-07 Thread Andrew C Aitchison via clamav-users
On Mon, 7 Sep 2020, Ankur Sharma via clamav-users wrote: Hi Team, I am trying to scan MP3,MP4 and JPEG files through ClamAV. But it always says - Data Scanned as 0.0 MB. I guess that the files are bigger than one of the limits in the config file (often /etc/clamav/clamd.conf ). I would

[clamav-users] freshclam frequency ?

2020-09-02 Thread Andrew C Aitchison via clamav-users
The sample freshclam.conf clamav-0.103.0-rc2/etc/freshclam.conf.sample has the lines: # Number of database checks per day. # Default: 12 (every two hours) #Checks 24 but https://blog.clamav.net/2020/07/freshclam-cdiffs-effect-on-bandwidth.html requests: To