Re: [clamav-users] Freshclam to not write to syslog?

2023-04-04 Thread Brent Clark via clamav-users
On 2023/04/04 15:47, Marc wrote: My logging goes to syslog, maybe remove this UpdateLogFile? I have only this in my config. LogSyslog yes LogFacility LOG_MAIL Thanks Guys Stefano gave me a hint and to check systemd. Low and behold: cat ./multi-user.target.wants/clamav-freshclam.service [U

[clamav-users] Freshclam to not write to syslog?

2023-04-04 Thread Brent Clark via clamav-users
Good day Guys I would like to double check something per taining to Freshclam Is it possible to get Freshclam to not write to syslog (want all logging to /var/log/clamav/freshclam.log )? Currently I have the following in my freshclam conf file. UpdateLogFile /var/log/clamav/freshclam.log Log

Re: [clamav-users] ClamAV 0.103.8, 0.105.2 and 1.0.1 patch versions published

2023-02-20 Thread Brent Clark via clamav-users
Good day Guys Anyone on Debian Buster and Bullseye? How serious is this? Does anyone have any suggestions. Cause there is no packages available. If anyone can share their thoughts / experiences. Regards Brent On 2023/02/18 21:13, unison.subject_0t--- via clamav-users wrote: Vulnerabilities*

Re: [clamav-users] Looks like we've gotten a new variant of Emotet getting through...

2020-12-21 Thread Brent Clark via clamav-users
Hiya Can you please submit to Sanesecurity too. https://sanesecurity.com/contact-us/ Regards Brent On 2020/12/21 18:44, eric-l...@truenet.com wrote: I’m going to start posting a few to https://www.clamav.net/reports/malware Sincerely, Eric Tykwinski TrueNet, Inc. P: 610-429-8300 __

Re: [clamav-users] ClamAV - Emotet - Malware not detected

2020-09-16 Thread Brent Clark via clamav-users
Hiya Thanks so much. I know the community and the internet as a whole, stands to gain from your efforts / work. Regards Brent On 2020/09/16 15:45, G.W. Haywood via clamav-users wrote: Hi there, On Wed, 16 Sep 2020, Brent Clark via clamav-users wrote: Did you submit to Sanesecurity too

Re: [clamav-users] ClamAV - Emotet - Malware not detected

2020-09-16 Thread Brent Clark via clamav-users
Hiya Did you submit to Sanesecurity too? If not. Can you please consider submitting there too. Please see: https://sanesecurity.com/contact-us/ Many thanks Regards Brent On 2020/09/16 15:04, G.W. Haywood via clamav-users wrote: Hi there, On Wed, 16 Sep 2020, Joel Esler (jesler) via clamav-us

Re: [clamav-users] A better zip bomb

2019-11-08 Thread Brent Clark via clamav-users
Good day Arnaud Thanks so much for this. Really appreciate the fast reply and help. Regards Brent Clark On 2019/11/08 10:23, Arnaud Jacques wrote: Hello Brent, https://www.bamsoftware.com/hacks/zipbomb/ I took the liberty of spinning up a vagrant instance to find out for myself. Here y

[clamav-users] A better zip bomb

2019-11-08 Thread Brent Clark via clamav-users
Good day ClamAV and Steve I have a client declaring that ClamAV signatures is not detecting zip bombs. https://www.bamsoftware.com/hacks/zipbomb/ I took the liberty of spinning up a vagrant instance to find out for myself. Here you can see I scanned the zip file, thats made available from the

Re: [clamav-users] Freshclam to only pull safebrowsing.cvd

2019-09-06 Thread Brent Clark via clamav-users
Thanks so much Regards Brent On 2019/09/06 11:01, G.W. Haywood via clamav-users wrote: Hi there, On Fri, 6 Sep 2019, Brent Clark via clamav-users wrote: We have project to have a to have freshclam *only* pull / update safebrowsing.cvd what I find is, when I run my custom freshclam.conf

[clamav-users] Freshclam to only pull safebrowsing.cvd

2019-09-06 Thread Brent Clark via clamav-users
Good day Guys We have project to have a to have freshclam *only* pull / update safebrowsing.cvd what I find is, when I run my custom freshclam.conf file it still pulls daily.cvd, main.cvd, bytecode.cvd Anyone know how I can switch this off? Many thanks Regards Brent

Re: [clamav-users] Possible FP Doc.Trojan.Agent-6923110-0

2019-04-10 Thread Brent Clark via clamav-users
To whitelist a specific signature from the database you just add the signature name into a local file with the .ign2 extension and store it inside /var/lib/clamav. i.e. echo 'Doc.Trojan.Agent-6923110-0' >> /var/lib/clamav/whitelist.ign2 HTH Regards Brent Clark On 2019/04/10 13:46, Graeme Fow

Re: [clamav-users] [External] Re: Scan very slow

2019-04-10 Thread Brent Clark via clamav-users
1 daily_Win.Tool.ldb *   12051 daily_Win.Trojan.ldb*     1967 daily_Win.Virus.ldb      966 daily_Win.Worm.ldb Malware and Trojan take the longest, but they also have a majority of the signatures. On Tue, Apr 9, 2019 at 11:19 AM Steve Basford mailto:steveb_cla...@sanesecurity.com&

Re: [clamav-users] [External] Re: Scan very slow

2019-04-09 Thread Brent Clark via clamav-users
Cant those be adopted / managed by Sanesecurity? For all you know, those are already in Sanesecurity. Regards Brent Clark On 2019/04/09 12:25, Mark Allan via clamav-users wrote: The scan times are definitely better than they were - in fact, they're back to how they were before last week's incl

Re: [clamav-users] ClamAV definitions vs LMD/maldet

2019-03-06 Thread Brent Clark via clamav-users
On 2019/03/06 05:01, J.R. via clamav-users wrote: I'm pretty sure the clamav-unofficial-sigs script downloads the same signature files as maldet. The maldet program itself gives you turn-key ability for various scanning, logging, and cleaning options... clamav-unofficial-sigs does vagrant@