[clamav-users] 10 years of ClamAV

2012-06-19 Thread Tomasz Kojm
products and distributions and, of course, the Open Source community as a whole. Finally, we would like to thank all who have trusted ClamAV for scanning and protecting some of the most valuable data on their networks. Sincerely, Tomasz Kojm tomasz.k...@gmail.com (twitter: @tkojm) Luca Gibelli l

Re: [clamav-users] From a newbie: ClamAV scans shut down Google Chrome

2012-05-17 Thread Tomasz Kojm
On Thu, 17 May 2012 10:25:50 -0400 james henrydoss james.henryd...@gmail.com wrote: Hi, Is there any documentation available (other than user manual) to understand the clam-AV code design. Source code. -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http

Re: [clamav-users] False positive submission page down (for a few days now)?

2012-04-19 Thread Tomasz Kojm
fine for me. What's exactly the problem on your side? -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Thu Apr 19 14:57:05 CEST 2012

Re: [clamav-users] FW: Virus/worm detection missed

2012-04-13 Thread Tomasz Kojm
clamav version .97.4 (although clamd -V says 97.3). The virus and worm were not caught by Clamav. Should I just submit the problem email bodies to clamav to review? Please submit the files at http://www.clamav.net/lang/en/sendvirus/submit-malware/ Thanks! -- oo. Tomasz

Re: [clamav-users] Cannot disable BC.Exploit.CVE_2011_3412 FP

2012-02-08 Thread Tomasz Kojm
is not complete. The correct one is: BC.Exploit.CVE_2011_3412.{CVE_2011_3412} HTH, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B

Re: [clamav-users] Cannot disable BC.Exploit.CVE_2011_3412 FP

2012-02-08 Thread Tomasz Kojm
On Wed, 8 Feb 2012 14:03:18 +0100 Ralf Hildebrandt ralf.hildebra...@charite.de wrote: * Tomasz Kojm tk...@clamav.net: On Wed, 8 Feb 2012 11:02:54 +1100 Bill Maidment b...@maidment.vu wrote: I have manually patched 0.97.3, re-compiled, re-installed and restarted clamd, but the ign2 file

Re: [clamav-users] Cannot disable BC.Exploit.CVE_2011_3412 FP

2012-02-07 Thread Tomasz Kojm
local.ign2, I'm looking into it -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Tue Feb 7 23:09:12 CET 2012

Re: [clamav-users] Cannot disable BC.Exploit.CVE_2011_3412 FP

2012-02-07 Thread Tomasz Kojm
On Tue, 07 Feb 2012 23:11:24 +0100 Tomasz Kojm tk...@clamav.net wrote: On Tue, 7 Feb 2012 23:07:05 +0100 Ralf Hildebrandt ralf.hildebra...@charite.de wrote: Have you tried that for a bytecode signature? sigtool --find-sigs=BC.Exploit.CVE_2011_3412 doesn't emit a line number. Fields

Re: [clamav-users] ClamAV not update

2012-01-30 Thread Tomasz Kojm
' -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Mon Jan 30 12:08:23 CET 2012 ___ Help us

Re: [clamav-users] ClamAV not update

2012-01-30 Thread Tomasz Kojm
On Mon, 30 Jan 2012 13:37:52 +0200 Sergey Tsabolov ( aka linuxman ) serg...@greeklug.gr wrote: Στις 30/01/2012 01:09 μμ, ο/η Tomasz Kojm έγραψε: On Mon, 30 Jan 2012 12:58:55 +0200 Sergey Tsabolov ( aka linuxman ) serg...@greeklug.gr wrote: I not need worry about all this WARNING

Re: [clamav-users] Heuristics.OLE2.ContainsMacros false positive

2012-01-26 Thread Tomasz Kojm
. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Thu Jan 26 12:44:52 CET 2012 ___ Help us build

Re: [clamav-users] Heuristics.OLE2.ContainsMacros false positive

2012-01-25 Thread Tomasz Kojm
detect all office documents, which contain macros. In most cases it's not a good idea to enable it. -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B

Re: [clamav-users] Heuristics.OLE2.ContainsMacros false positive

2012-01-25 Thread Tomasz Kojm
. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Wed Jan 25 16:26:09 CET 2012 ___ Help us build a comprehensive

Re: [clamav-users] Heuristics.OLE2.ContainsMacros false positive

2012-01-25 Thread Tomasz Kojm
is now fixed in clamav-devel and the 0.97 branch. Thanks, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Wed Jan 25 18:59:05 CET

Re: [clamav-users] Configuration Test

2011-11-23 Thread Tomasz Kojm
(created in the /test directory after 'make'). -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Wed Nov 23 19:18:00 CET 2011

Re: [clamav-users] Disable specific virus signatures?

2011-11-22 Thread Tomasz Kojm
On Tue, 22 Nov 2011 12:47:46 -0500 Shobana Narayanaswamy snar...@opnet.com wrote: Is there a way to delete a signature that you are not interested in? Yes, please search the archives on how to whitelist sigs or look into signatures.pdf -- oo. Tomasz Kojm tk...@clamav.net

Re: [clamav-users] clamd abending at selfcheck

2011-10-21 Thread Tomasz Kojm
on the problem. Also please consider upgrading to 0.97.3, which is the latest stable. -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B

Re: [clamav-users] clamd abending at selfcheck

2011-10-20 Thread Tomasz Kojm
the problem began: Please post the output of 'clamconf -n' -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Thu Oct 20 21:01:14 CEST 2011

Re: [clamav-users] clamd exits with libclamav error

2011-10-10 Thread Tomasz Kojm
only need to add a single line to freshclam.conf to benefit from automatic and *safe* updates. Hopefully, more vendors will decide to join this initiative soon! Regards, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg

Re: [clamav-users] clamav doesn`t start

2011-09-19 Thread Tomasz Kojm
. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Mon Sep 19 10:19:09 CEST 2011 ___ Help us build

Re: [clamav-users] Yet Another US Mirror Issue-Solved

2011-09-19 Thread Tomasz Kojm
On Sat, 17 Sep 2011 10:25:50 -0400 Dan dantear...@gmail.com wrote: At 1:33 PM +0200 9/16/2011, Tomasz Kojm wrote: On Thu, 15 Sep 2011 12:28:50 -0400 Dan dantear...@gmail.com wrote: At 10:43 AM +0200 9/15/2011, Tomasz Kojm wrote: OK, now please post the output of 'freshclam --list-mirrors

Re: [clamav-users] Yet Another US Mirror Issue-Solved

2011-09-16 Thread Tomasz Kojm
update went right back to .125 in all but 2 cases. One Can't connect was followed by a second Can't connect. OK, so that's the expected behavior. -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg

Re: [clamav-users] Yet Another US Mirror Issue-Solved

2011-09-16 Thread Tomasz Kojm
to another mirror and successfully updated the database. -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Fri Sep 16 13:14:17 CEST

Re: [clamav-users] Yet Another US Mirror Issue-Solved

2011-09-16 Thread Tomasz Kojm
On Thu, 15 Sep 2011 12:28:50 -0400 Dan dantear...@gmail.com wrote: At 10:43 AM +0200 9/15/2011, Tomasz Kojm wrote: OK, now please post the output of 'freshclam --list-mirrors' Mirror #9 IP: 88.198.67.125 Successes: 13 Failures: 0 Last access: Fri Aug 26 10:45:31 2011 Ignore

Re: [clamav-users] Yet Another US Mirror Issue-Solved

2011-09-15 Thread Tomasz Kojm
. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Thu Sep 15 10:17:13 CEST 2011 ___ Help us build

Re: [clamav-users] Yet Another US Mirror Issue-Solved

2011-09-15 Thread Tomasz Kojm
On Thu, 15 Sep 2011 01:41:29 -0700 Al Varnell alvarn...@mac.com wrote: Looks to be OK. OK, now please post the output of 'freshclam --list-mirrors' -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg

Re: [clamav-users] Yet Another US Mirror Issue-Solved

2011-09-15 Thread Tomasz Kojm
. Could you check your logs to see if that actually happened? -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Thu Sep 15 14:07:40 CEST 2011

Re: [clamav-users] Database not updating

2011-09-13 Thread Tomasz Kojm
better if there was some sort of explanation. There was a problem with our internal file distribution mechanism, which should be fixed now. Sorry for the inconvenience. -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg

Re: [clamav-users] improving ClamAV private mirroring?

2011-09-12 Thread Tomasz Kojm
On Fri, 15 Jul 2011 13:58:43 +0200 Tomasz Kojm tk...@clamav.net wrote: On Thu, 14 Jul 2011 23:15:20 -0400 James Ralston qralston+ml.clamav-us...@andrew.cmu.edu wrote: But freshclam falls over fairly badly if you try to use it to update internal clients from a private mirror, even though

Re: [clamav-users] Clarification of report needed

2011-09-02 Thread Tomasz Kojm
by the ClamAV project. # Default: no #OfficialDatabaseOnly no You can do the same in clamscan with --official-db-only Regards, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg

Re: [clamav-users] ClamaV reporting problems on CentOS 6

2011-08-27 Thread Tomasz Kojm
in no output whatsoever - or at least no report was received after I changed it. How can I return to the old behaviour? Thanks There were no changes to the output format in clamscan since early versions. You can use '-i' to only display infected files. -- oo. Tomasz Kojm tk

Re: [clamav-users] Third Party web interface

2011-07-26 Thread Tomasz Kojm
have been removed so that viruses can be passed on. The 3rd party signatures will be distributed inside separate .cvd files and you will need to enable them in freshclam.conf. They'll have nothing to do with the official databases. Regards, -- oo. Tomasz Kojm tk

Re: [clamav-users] daily.cvd update issue.

2011-07-20 Thread Tomasz Kojm
a social media tool for support. It was hard enough getting the email lists allowed after 3 years on my internal mail vs. home email. This is NOT happening. Twitter is just another way to deliver information about the updates to our *users*, not to our software. -- oo. Tomasz

Re: [clamav-users] improving ClamAV private mirroring?

2011-07-15 Thread Tomasz Kojm
, freshclam performes a number of checks - it won't install corrupted db file, etc. So it should still be more effective than wget. Regards, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg

Re: [clamav-users] improving ClamAV private mirroring?

2011-07-14 Thread Tomasz Kojm
inside the CLD container. Cheers, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Thu Jul 14 23:33:11 CEST 2011

Re: [clamav-users] How to disable blocking Encrypted.pdf alone

2011-06-20 Thread Tomasz Kojm
to be blocked. Is this configurable? Yes, it is - you can turn ArchiveBlockEncrypted off in clamd.conf (it's off by default) -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg

Re: [clamav-users] How to disable blocking Encrypted.pdf alone

2011-06-20 Thread Tomasz Kojm
On Mon Jun 20 2011 13:40:06 GMT+0200 (CET) ANANT S ATHAVALE a...@isac.gov.in wrote: Dear Tomasz Kojm, But by setting ArchiveBlockEncrypted = off, I will not be able to detect even encrypted zip, am I right? Yes, you're right. However please keep in mind we create sigs for encrypted malware

Re: [clamav-users] Mirror Issues

2011-06-20 Thread Tomasz Kojm
for discussions on this issue so please open a bug report (bugs.clamav.net) and we'll try to find a good solution. Thanks, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg

Re: [clamav-users] Create md5 sig from HTML file

2011-04-29 Thread Tomasz Kojm
the HTML file if possible. -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Fri Apr 29 16:44:24 CEST 2011

Re: [clamav-users] Database reload improvement

2011-03-11 Thread Tomasz Kojm
On Fri, 11 Mar 2011 14:30:55 +0100 aCaB aca...@digitalfuture.it wrote: Whatever. Still 90 secs is unreasonable especially considering the older version was way better. This can be caused by the bytecode.cvd. Please try without it. -- oo. Tomasz Kojm tk...@clamav.net

Re: [clamav-users] daily database broken again

2011-02-28 Thread Tomasz Kojm
will never install a database that cannot be properly loaded (unless one explicitly disables the TestDatabases option in freshclam.conf). -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg

[clamav-users] Possible problem with older versions of ClamAV (0.96-0.96.3)

2011-02-17 Thread Tomasz Kojm
one of these releases, we strongly advise to upgrade it. Thank you, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Thu Feb 17 10:43

Re: [clamav-users] Possible problem with older versions of ClamAV (0.96-0.96.3)

2011-02-17 Thread Tomasz Kojm
On Thu, 17 Feb 2011 11:53:02 +0100 Stephan von Krawczynski sk...@ithnet.com wrote: On Thu, 17 Feb 2011 10:46:34 +0100 Tomasz Kojm tk...@clamav.net wrote: Dear users, ClamAV versions older than 0.96.4 are affected by a bug in the logical signature parser, which can make them load

Re: [clamav-users] What happened to 12663 ?

2011-02-11 Thread Tomasz Kojm
is also one of the options. The current version of freshclam has a special option TestDatabases, which is enabled by default and makes sure the new databases can be loaded properly before they get installed in the system. Regards, -- oo. Tomasz Kojm tk...@clamav.net

Re: [clamav-users] Updating of clam stats has stopped

2010-12-31 Thread Tomasz Kojm
. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Fri Dec 31 13:16:34 CET 2010 ___ Help us build a comprehensive

Re: [clamav-users] WARNINGS on startup - ignore, comment out or?

2010-12-22 Thread Tomasz Kojm
. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Wed Dec 22 08:58:24 CET 2010 ___ Help us build a comprehensive

Re: [clamav-users] WARNINGS on startup - ignore, comment out or?

2010-12-22 Thread Tomasz Kojm
errors. Hi, clamconf is already doing this. -- Tomasz Kojm ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [clamav-users] Signature wildcard usage

2010-12-20 Thread Tomasz Kojm
of them at the same time. Regards, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Mon Dec 20 11:00:52 CET 2010

Re: [clamav-users] Why does virus name now include size and hash ?

2010-12-09 Thread Tomasz Kojm
/show_bug.cgi?id=2409 -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Thu Dec 9 15:30:09 CET 2010

Re: [Clamav-users] Upcoming release of ClamAV (0.96.5)

2010-11-29 Thread Tomasz Kojm
On Mon, 22 Nov 2010 15:12:57 +0100 Tomasz Kojm tk...@clamav.net wrote: Dear Users, we're going to release a new version of ClamAV on Monday, November 29. ClamAV 0.96.5 will include bugfixes and minor feature enhancements, such as improved handling of detection statistics, better file logging

Re: [Clamav-users] Reload fails

2010-11-22 Thread Tomasz Kojm
? If so, do I delete the file? Yes, this is the problem. 'touch' should be called with '-c' to avoid creating new files. -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg

[Clamav-users] Upcoming release of ClamAV (0.96.5)

2010-11-22 Thread Tomasz Kojm
running ./configure make check) the latest code available in our Git repository - the latest snapshot tarball can be grabbed here: http://git.clamav.net/gitweb?p=clamav-devel.git;a=snapshot;h=refs/heads/master;sf=tgz Thank you in advance, -- oo. Tomasz Kojm tk...@clamav.net

Re: [Clamav-users] Upcoming release of ClamAV

2010-10-22 Thread Tomasz Kojm
: Great, thanks for the feedback! Best regards, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Fri Oct 22 11:31:29 CEST 2010

[Clamav-users] Upcoming release of ClamAV

2010-10-19 Thread Tomasz Kojm
in advance, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Tue Oct 19 16:21:33 CEST 2010

Re: [Clamav-users] Freshclam OnOutdated fails to execute

2010-09-22 Thread Tomasz Kojm
before even making the DNS query), therefore to be consistent OnOutdatedExecute never gets called on error conditions. -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg

Re: [Clamav-users] What ever happened to the Release Candidate for 0.96.3??

2010-09-22 Thread Tomasz Kojm
on our end why are we bothering to do thisit seems like we're running tests, submitting results and no-one is even looking at the output. Just my 2 cents from out here Could you elaborate more on the problems you were facing with 0.96.3? -- oo. Tomasz Kojm tk

Re: [Clamav-users] What ever happened to the Release Candidate for 0.96.3??

2010-09-22 Thread Tomasz Kojm
, it actually only applies to FreeBSD users. It will be disabled for other OSes with the next release. Regards, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B

Re: [Clamav-users] What ever happened to the Release Candidate for 0.96.3??

2010-09-22 Thread Tomasz Kojm
is coming back from them. Thanks for your support. The 0.96.3 was tested on your boxes and confirmed to work fine before we released it. Since the tests are fully automated, we missed the ULIMIT warning issue but as I wrote above, it can just be ignored. Cheers, -- oo. Tomasz

Re: [Clamav-users] What ever happened to the Release Candidate for 0.96.3??

2010-09-22 Thread Tomasz Kojm
. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Wed Sep 22 20:09:50 CEST 2010 ___ Help us build a comprehensive ClamAV

Re: [Clamav-users] Tracking false positives

2010-09-15 Thread Tomasz Kojm
Sanesecurity.Spam.10995:4:*:46726f6d3a20{-50}5066697a6572*5375626a6563743a20{-100}2520 real0m3.076s user0m2.952s sys 0m0.124s -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg

Re: [Clamav-users] Again - clamav.whitelist file

2010-09-15 Thread Tomasz Kojm
clamav.whitelist file so I can see an good example of what I should be doing? In the directory with ClamAV databases you create a new file with a .ign2 extension and list virus names (one name per line) you want to ignore. -- oo. Tomasz Kojm tk...@clamav.net

Re: [Clamav-users] Tracking false positives

2010-09-14 Thread Tomasz Kojm
it: http://www.sanesecurity.com/clamav/decodesigs.htm You can easily decode signatures locally, eg.: $ sigtool --find-sigs HTML.Phishing.Bank-1313 | sigtool --decode-sigs -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg

Re: [Clamav-users] False positive in rar-packed executable file

2010-09-14 Thread Tomasz Kojm
for DOS.Form.a in the file. Hi Peter, the signature should be blacklisted with the next daily.cvd update. You can turn it off locally anytime with: (the dbpath may vary) $ echo DOS.Form.a (Clam) /usr/local/share/clamav/ignore.ign2 BTW, we're at 0.96.2 now -- oo. Tomasz Kojm tk

Re: [Clamav-users] attache case files caught in clamav

2010-09-06 Thread Tomasz Kojm
effect? We have also noticed this between DB versions 11659 and 11707. If you believe this is a false positive, please report it at http://cgi.clamav.net/sendvirus.cgi (please don't forget to mark it false positive) -- oo. Tomasz Kojm tk...@clamav.net

Re: [Clamav-users] size of virus defination database

2010-08-30 Thread Tomasz Kojm
by using IE 7. Where and I compare the correct size so that I know the file that I downloaded is the completed one? Thanks for your help… You can run 'sigtool -i /path/to/daily.cvd' to verify the database integrity. -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http

Re: [Clamav-users] SELinux problem with 0.96.2 on CentOS 5.4

2010-08-25 Thread Tomasz Kojm
tclass=dir rpm -V does not show anything as mislabeled. What is 0.96.2 doing that 0.96.1 didn't that isn't allowed when it runs in its own clamd_t domain? https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2200 -- oo. Tomasz Kojm tk...@clamav.net

[Clamav-users] ClamAV Releases

2010-08-16 Thread Tomasz Kojm
, be November 2010. As always we appreciate your support, use, and continued involvement in the ClamAV community. If you have bugs, feature requests, or cool ideas please check out the bug tracker and open your requests (http://bugs.clamav.net). Thanks, -- oo. Tomasz Kojm tk

Re: [Clamav-users] using --on-update-execute=EXIT_1 doesn't clean up properly

2010-07-15 Thread Tomasz Kojm
report and provide all the necessary information as requested at http://www.clamav.net/lang/en/bugs/ Thanks, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B

Re: [Clamav-users] Clamscan scanning /sys despite clamd.conf entry

2010-06-15 Thread Tomasz Kojm
# This directive can be used multiple times # Default: scan all ExcludePath ^/proc/ ExcludePath ^/sys/ ExcludePath ^/dev/ clamscan doesn't use clamd.conf at all. For clamscan you need to use the command line options --exclude/--exclude-dir -- oo. Tomasz Kojm tk

Re: [Clamav-users] PUA.HTML.Infected.WebPage-1

2010-06-04 Thread Tomasz Kojm
. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Fri Jun 4 10:17:08 CEST 2010 ___ Help us build a comprehensive

Re: [Clamav-users] Clamav 0.96 is not matching md5 signatures when the offset is *

2010-05-28 Thread Tomasz Kojm
engines. The field you're referring to is the file size and not offset and it's mandatory. -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B

Re: [Clamav-users] Reload process

2010-05-25 Thread Tomasz Kojm
On Tue, 25 May 2010 00:20:06 +0200 Sarocet saro...@gmail.com wrote: Tomasz Kojm wrote: These are poor examples, which are almost identical (only 6 bytes differ). Now, take a notepad.exe and create a malicious file with the same file size and MD5. Thanks, Read again the scenario. Both

Re: [Clamav-users] Reload process

2010-05-25 Thread Tomasz Kojm
On Tue, 25 May 2010 16:27:48 +0200 Sarocet saro...@gmail.com wrote: Tomasz Kojm wrote: This scenario makes no much sense to me. First of all, as I wrote in the previous email the files you provided as example are almost identical (they only differ in high nibbles of six bytes) and they share

Re: [Clamav-users] Reload process

2010-05-25 Thread Tomasz Kojm
On Tue, 25 May 2010 07:56:17 -0700 Dennis Peterson denni...@inetnw.com wrote: On 5/25/10 7:51 AM, Tomasz Kojm wrote: On Tue, 25 May 2010 16:27:48 +0200 Sarocetsaro...@gmail.com wrote: Tomasz Kojm wrote: This scenario makes no much sense to me. First of all, as I wrote in the previous email

Re: [Clamav-users] Read mirrors.dat

2010-05-24 Thread Tomasz Kojm
is collected by freshclam during updates. Any mirror that was ever visited by freshclam gets stored/updated in the mirrors.dat file with an appropriate status. That's why the files may differ between systems. Regards, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http

Re: [Clamav-users] Reload process

2010-05-24 Thread Tomasz Kojm
sizes Send the malicious one after a while. The hash in on the cache so it bypasses the AV. Profit. Good luck, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B

Re: [Clamav-users] Reload process

2010-05-24 Thread Tomasz Kojm
the drive (or so it says :) Md5 is broken, guys. These are poor examples, which are almost identical (only 6 bytes differ). Now, take a notepad.exe and create a malicious file with the same file size and MD5. Thanks, -- oo. Tomasz Kojm tk...@clamav.net

Re: [Clamav-users] Duplicate signature files

2010-05-21 Thread Tomasz Kojm
in freshclam.conf, which is turned on by default. Why this check fails for bytecode.cvd on your box is a different issue but the good thing is that the update that could possibly affect your clamd was not installed. Regards, -- oo. Tomasz Kojm tk...@clamav.net

Re: [Clamav-users] (no subject)

2010-04-16 Thread Tomasz Kojm
!) since 2008. You should really update your OS first. -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Fri Apr 16 11:06:50 CEST 2010

Re: [Clamav-users] (no subject)

2010-04-16 Thread Tomasz Kojm
because of very many reasons, such as your - incompatibility (eg convert MySQL databases hundreds of thousands of tables in utf8). Your suggestion - remove clamav and forget about the antivirus? You can always try to compile from source -- oo. Tomasz Kojm tk...@clamav.net

Re: [Clamav-users] The EOL tweets

2010-04-16 Thread Tomasz Kojm
with freshclam (for specific releases). Thanks, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Fri Apr 16 16:24:53 CEST 2010

Re: [Clamav-users] clamav-0.96: make distclean fails in libclamav...

2010-04-07 Thread Tomasz Kojm
. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Wed Apr 7 20:49:56 CEST 2010 ___ Help us build

Re: [Clamav-users] Question on change in freshclam return codes

2010-04-02 Thread Tomasz Kojm
=Exit_n option is appreciated. By using --on-update-execute=EXIT_1 you will mimic the behavior of freshclam = 0.95.3. -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg

Re: [Clamav-users] HTTPUserAgent must be disabled for SubmitDetectionStats

2010-03-26 Thread Tomasz Kojm
bugzilla Regards, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Fri Mar 26 17:55:12 CET 2010

Re: [Clamav-users] clamd reload - reloading logfile failed ?

2009-12-14 Thread Tomasz Kojm
as a bug. Fixed Thanks, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Mon Dec 14 14:27:05 CET 2009

Re: [Clamav-users] Virus Event ?

2009-11-06 Thread Tomasz Kojm
in freshclam.conf(5), one can pass %v to OnOutdatedExecute to get the version number of the latest ClamAV release Regards, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B

Re: [Clamav-users] Virus Event ?

2009-11-05 Thread Tomasz Kojm
) and $CLAM_VIRUSEVENT_FILENAME (not directly available in the config file) HTH, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Thu Nov 5 22:55

Re: [Clamav-users] Apparently Old .cld files block new .cvd updates. Security Fail ?

2009-10-29 Thread Tomasz Kojm
. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Thu Oct 29 15:38:44 CET 2009 ___ Help us build

Re: [Clamav-users] Why does ClamAV does not detect this via amavisd-new

2009-10-27 Thread Tomasz Kojm
to the amavisd-new maintainers. Thanks, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Tue Oct 27 11:56:10 CET 2009

Re: [Clamav-users] clamdscan return code problem

2009-10-26 Thread Tomasz Kojm
, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Mon Oct 26 08:56:22 CET 2009 ___ Help us

Re: [Clamav-users] ExcludePath rears its ugly head again

2009-10-26 Thread Tomasz Kojm
/show_bug.cgi?id=1656 Regards, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Mon Oct 26 09:36:41 CET 2009

Re: [Clamav-users] clamdscan return code problem

2009-10-26 Thread Tomasz Kojm
at bugs.clamav.net Thanks, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Mon Oct 26 08:55:52 CET 2009

Re: [Clamav-users] Why does ClamAV does not detect this via amavisd-new

2009-10-26 Thread Tomasz Kojm
'^MAIL$', # retain full original message for virus checking (can be slow) Regards, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B

Re: [Clamav-users] ExcludePath rears its ugly head again

2009-10-26 Thread Tomasz Kojm
On Mon, 26 Oct 2009 10:48:11 -0400 Scott Mohnkern mohnk...@gmail.com wrote: Is there an expected release date for .95.3? October 28 as announced on our website -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg

Re: [Clamav-users] [Fwd: Advance Warning: End of Life Announcement:ClamAV 0.94.x]

2009-10-08 Thread Tomasz Kojm
on this issue. The development branch of ClamAV will soon support win32 natively and then the installation at VirusTotal will be updated as well. Thanks, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg

Re: [Clamav-users] Local mirror question

2009-10-08 Thread Tomasz Kojm
the master and the slaves. Cheers, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg \..._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Thu Oct 8 12:35:47 CEST 2009

Re: [Clamav-users] [Fwd: Advance Warning: End of Life Announcement: ClamAV 0.94.x]

2009-10-07 Thread Tomasz Kojm
news on these changes after/when 0.95.3 is released*. Steve, 0.95.3 will be a bugfix-only release and won't include any new features Regards, -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg/tkojm.gpg

Re: [Clamav-users] [Fwd: Advance Warning: End of Life Announcement: ClamAV 0.94.x]

2009-10-07 Thread Tomasz Kojm
On Wed, 07 Oct 2009 21:44:00 +0100 Steve Basford steveb_cla...@sanesecurity.com wrote: ... so will boundary support (B) /.ign2 format be introduced later next year? They will be included in 0.96 which is currently scheduled for February 2010. Regards, -- oo. Tomasz Kojm

Re: [Clamav-users] ClamAV 0.95.3

2009-10-01 Thread Tomasz Kojm
On Thu Oct 01 2009 08:44:09 GMT+0200 (CEST) Thiyaga m.thiy...@gmail.com wrote: Hi, When can we expect the stable 0.95.3 version to be released? We don't have the date for 0.95.3 yet but will post here and on www.clamav.net when it's established. Thanks, -- oo. Tomasz

Re: [Clamav-users] DNSDatabaseInfo to disable

2009-09-22 Thread Tomasz Kojm
On Tue Sep 22 2009 16:01:06 GMT+0200 (CEST) Frédéric SOSSON fsos...@gmail.com wrote: Hello, I would like to disable DNSDatabaseInfo mechanism. Is it possible ? freshclam --no-dns -- oo. Tomasz Kojm tk...@clamav.net (\/)\. http://www.ClamAV.net/gpg

  1   2   3   4   5   6   7   8   9   10   >