Re: [clamav-users] clamav-users Digest, Vol 219, Issue 5

2023-02-13 Thread Lyle Giese via clamav-users
. I will admit that compiling from source is not for everyone. Lyle Giese On 2/11/23 07:36, Mike Lieberman wrote: It was suggested that: "If FreshClam is failing and you're not sure why, you may run freshclam -v for "Verbose Mode" to see the HTTP request & response de

Re: [clamav-users] clamscan exclude-dir on Windows

2023-01-28 Thread Lyle Giese via clamav-users
I would try the 'short' names of these directories. dir /X c:\ And yes the /X is case sensitive.  /X displays the short names. Lyle Giese On 1/28/23 08:58, clamav.mbou...@spamgourmet.com wrote: If it's expecting a regex, perhaps try:   --exclude-dir="/mnt/c/Program Files \(x86\)/&quo

Re: [clamav-users] CDV file?

2022-12-14 Thread Lyle Giese via clamav-users
updates to the firmware in your NAS. Lyle Giese On 12/14/22 20:38, Armando P via clamav-users wrote: I'm sorry, I'm not Knowledgeable enough to know what that means. I just need to know where I can find the latest cvd file, so I can update the anti-virus software. Unfortunately, unlike the one

Re: [clamav-users] clamav milter + sendmail, sendmail not reporting reject

2022-02-08 Thread Lyle Giese via clamav-users
I just reread my message.  Reject is good behavior. Bouncing is not.  At least in my opinion.  Replace reject below with bounce and you have my correct opinion. Sorry, Lyle On 2/8/22 9:49 AM, Lyle Giese via clamav-users wrote: But the reject may NOT be going to the server/service that sent

Re: [clamav-users] clamav milter + sendmail, sendmail not reporting reject

2022-02-08 Thread Lyle Giese via clamav-users
nothing to do with the bad email sent.  This is quite common with any bad email. Lyle Giese On 2/8/22 3:50 AM, Marc wrote: So please explain, why should I not do this, and why I should care about a server that is delivering a spam message to mine? You might not care about the server that sent

Re: [clamav-users] IP List for Virus Definition Domain

2021-09-15 Thread Lyle Giese via clamav-users
FYI, I queried from two distinct locations and got the same IP address.  I then did a traceroute from each of those locations and it took different but short routes into CloudFlare's network.  I presume they use anycast routing.(and I could be wrong). Lyle Giese LCR Computer Services, Inc

Re: [clamav-users] I have some queries about ClamAV

2015-02-02 Thread Lyle Giese
the status output of ClamAV to make decisions on what to do with the file/email passed to ClamAV. This is the primary use of ClamAV on real world systems. Lyle Giese LCR Computer Services, Inc. On 02/02/15 17:37, Jihyun-Chang wrote: Hi Steven, Thank you for your feedback. I have only clamdoc.pdf

Re: [clamav-users] Cannot disable BC.Exploit.CVE_2011_3412 FP

2012-02-07 Thread Lyle Giese
that changes the line number for that definition will also render the local.ign useless. It does work and I have used it, but every time I need it, it takes me more than one try to get it right. Especially since I only use it once every 3 or 4 months at best and it's case sensitive. Lyle Giese LCR

Re: [clamav-users] Cannot disable BC.Exploit.CVE_2011_3412 FP

2012-02-07 Thread Lyle Giese
the local.ign files I created to make sure they do exactly what is needed for my mail system. Lyle Giese LCR Computer Services, Inc. ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

[clamav-users] False Positive - INetMsg.SpamDomain-2w.dl_dropbox_com.UNOFFICIAL

2011-07-07 Thread Lyle Giese
This is a message I hand created with a valid link to a dropbox file. I can post a copy of the orginal message if desired. Thanks, Lyle Giese LCR Computer Services, Inc. 2011-07-07 19:47:38.00:Info:-373696176: msg: log_reason [4124389] Dropped: 2607:fcb8:4480:2::1 i...@mc3computerclub.org

Re: [Clamav-users] can?t compile 0.96.3

2010-09-23 Thread Lyle Giese
1.0.5 installed from source also. I don't mind the warning, it's the hang that prevents configure from finishing. I am not too worried as I have clamav 0.96.2 installed now on this system and it's due to be rebuilt in about another month or so. Lyle Giese LCR Computer Services, Inc

Re: [Clamav-users] How can i scan the POST data

2010-02-21 Thread Lyle Giese
You proably won't find their code using ClamAV. More likely is that they will inject code in an HREF or some java to download the malicious content from a different site. My experience is that that they won't inject code that will be detected by ClamAV, but will inject a pointer to their

Re: [Clamav-users] Install upgrade from 94 to 95.2 freschclam clamscan failure

2009-09-13 Thread Lyle Giese
da...@davidwbrown.name wrote: Hello, I have been running ClamAV (clamd) for some time. I decided to upgrade to 95.2. The configure, make, make install executed without incident. As a test I tried to execute freshclam and clamscan from the root command-line with the following error

Re: [Clamav-users] exceptions where?

2009-08-16 Thread Lyle Giese
if something bad happens to the Barracuda, I still have something to scan for viruses on the mail server. Lyle Giese LCR Computer Services, Inc. ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] Newbie question.

2009-03-11 Thread Lyle Giese
Matus UHLAR - fantomas wrote: Hello, On 10.03.09 21:35, Erik P. Olsen wrote: please set up your mailer to wrap lines below 80 characters per line. 721 to 76 is usually OK. I am running fedora 10, thunderbird 2.0.0.9 and firefox 3.0.7 and I would like to install clamav to catch vira

[Clamav-users] FYI SaneSecurity

2008-12-14 Thread Lyle Giese
FYI Just found this: http://www.sanesecurity.com/ They have shutdown temporarily because of a DDoS problem. ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] Virus not detected on Linux/MacOSX

2008-09-20 Thread Lyle Giese
Austin Try unsubscribing as per the instructions in the header of this message. Lyle Austin Brown wrote: PLEASE REMOVE ME FROM THIS LIST THANKS Date: Fri, 19 Sep 2008 17:28:07 -0700 From: [EMAIL PROTECTED] To: clamav-users@lists.clamav.net Subject: Re: [Clamav-users] Virus not

Re: [Clamav-users] maliciout javascript in WWW pages

2008-08-28 Thread Lyle Giese
... Instead of clamav, I would recommend squidGuard and some blacklist lists there. It's more suited to this task than clamAV. ClamAV probably still won't find the malicious javascript and squidGuard using some of the malicious site blacklists will do a better job. Lyle Giese LCR Computer

[Clamav-users] clamd seg faulting (ver 0.93)

2008-04-16 Thread Lyle Giese
that freshclam is changing out the clamav database at the same time clamd is trying to reload it and causing clamd to crash? I will monitor this closely and see if there is a correlation between the two events going forward and report back on same. Thanks, Lyle Giese LCR Computer Services, Inc

Re: [Clamav-users] Memory usage for clamd is huge

2008-03-30 Thread Lyle Giese
. Lyle Giese LCR Computer Services, Inc. ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://lurker.clamav.net/list/clamav-users.html

Re: [Clamav-users] Source code for test/clam.exe?

2007-12-24 Thread Lyle Giese
Cort, Tom wrote: Hello, clamav comes with a sample virus (ClamAV-Test-File) for testing purposes. It's located in the clamav source tarball in the 'test' directory and named 'clam.exe'. I'd like to distribute it with a free software program I maintain, but I can't find the corresponding

Re: [Clamav-users] I need to refute a 'security expert'

2007-11-16 Thread Lyle Giese
[EMAIL PROTECTED] wrote: [EMAIL PROTECTED] wrote on 11/16/2007 02:52:34 PM: [EMAIL PROTECTED] wrote: Hello all. We've had some consultant make the spurious claim that Clam AV only scans for 'windows viruses' and is really only useful for 'scanning email'. Despite

Re: [Clamav-users] Freshclam Stopped Working

2007-10-30 Thread Lyle Giese
Sean McGlynn wrote: Hello, After changing our DNS services from Netware to OES Linux/BIND, freshclam stopped getting updates. When we run freshclam we get: WARNING: Can't query current.cvd.clamav.net and WARNING: Invalid DNS reply. Falling back to HTTP mode. Connecting via

Re: [Clamav-users] Freshclam Stopped Working

2007-10-30 Thread Lyle Giese
You also have to remember that if your internal dns server is listed in resolv.cfg, it will be queried. And because it's local, your dns queries will gravitate to them as it will probably give back answers faster than the external servers. Lyle Sean McGlynn wrote: I lied. The DNS server order

Re: [Clamav-users] Automatic reloading of signature files

2007-08-31 Thread Lyle Giese
While this may not directly answer your question, I am running the update script for the addons at 17 minutes past the hour. And run freshclam at 21 minutes past the hour.(I don't update the addons every hour...) But I also see in /var/log/messages, clamd doing a selfcheck on the databases every

Re: [Clamav-users] FreshClam and DNS - Debian

2007-07-26 Thread Lyle Giese
Is nscd running on the same host that is running freshclam? On the host running freshclam, what does your /etc/resolv.conf look like? Lyle [EMAIL PROTECTED] wrote: Hello, Today we upgraded our DNS server which is Debian Bind9 ver 1:9.3.4-2etch1. We also upgraded our ClamAV software to the

Re: [Clamav-users] scanPDF Usage

2007-07-10 Thread Lyle Giese
When you compiled clamav, did you enable-experimental? Lyle Michael McCandless wrote: I am using Clamav (0.90.3), compiled from source, on Fedora Core 7. I have checked documentation, wiki, and mailing list archives. My clamd.conf file includes the following: # This option enables

Re: [Clamav-users] scanPDF Usage

2007-07-10 Thread Lyle Giese
McCandless wrote: No, I did not enable-experimental when I compiled. -Original Message- From: Lyle Giese [mailto:[EMAIL PROTECTED] Sent: Tuesday, July 10, 2007 9:42 PM To: ClamAV users ML Cc: [EMAIL PROTECTED] Subject: Re: [Clamav-users] scanPDF Usage When you compiled clamav, did you

[Clamav-users] Clamdmon.sh

2007-04-11 Thread Lyle Giese
I am amazed at the number of people here that apparently not using SOMETHING to monitor clamd. Esp. when the developers include a nice script to check and restart clamd. I run three different mail servers and quickly found clamdmon and just a bit of PERL programming created a means of being

Re: [Clamav-users] clamav vs norton

2007-03-02 Thread Lyle Giese
In this case, was the file really infected or did Norton throw a false positive? At this point, we really don't know which product is producing an error. How about downloading AVG and scanning this file again?( they have free and trial versions) Lyle Jim Maul wrote: Sean Pinegar wrote: I

[Clamav-users] ClamAV Squid

2006-08-11 Thread Lyle Giese
I recently installed a Squid proxy server for one of my customers. We would like to wedge in ClamAV for scanning and looking over the selections of open source software for this, I decided to try out SquicClamAV by Gilles Darold.(http://www.samse.fr/GPL/squidclamav/) Unfortunately, it's

Re: [Clamav-users] ClamAV Squid

2006-08-11 Thread Lyle Giese
Odhiambo Washington wrote: * On 11/08/06 08:18 -0500, Lyle Giese wrote: | I recently installed a Squid proxy server for one of my customers. We | would like to wedge in ClamAV for scanning and looking over the | selections of open source software for this, I decided to try out | SquicClamAV