Re: [Clamav-users] Spyware detection...

2005-09-16 Thread Stephen J. Smoogen
On 9/15/05, Joanna Roman [EMAIL PROTECTED] wrote: Whoever is about to submit the spywares, may I ask whether those spywares come in via port 80 or port 21 ? 95% of the spyware I have dealt with sends out data from itself on one of 3 channels: 1) 80/tcp 2) 443/tcp 3) 53/tcp or udp

Re: [Clamav-users] Spyware detection...

2005-09-15 Thread Stephen J. Smoogen
Well I am interested in seeing how this could be done. What is the documentation I need to start looking at on how to make signatures for clamav? On 9/14/05, Dan MacNeil [EMAIL PROTECTED] wrote: Thomas Hruska wrote: [asks in a somewhat forceful way that clam detect spyware] Perhaps you might

Re: [Clamav-users] Spyware detection...

2005-09-15 Thread Jason Englander
On Thu, 15 Sep 2005, Stephen J. Smoogen wrote: Well I am interested in seeing how this could be done. What is the documentation I need to start looking at on how to make signatures for clamav? http://www.clamav.net/ - documentation - latest - signatures.pdf

Re: [Clamav-users] Spyware detection...

2005-09-15 Thread Stephen J. Smoogen
And this just proves that spending 2 hours actively trying to look for something... and failing should be just cause for my internet license to be revoked. Sorry about the obvious question with obvious answer. On 9/15/05, Jason Englander [EMAIL PROTECTED] wrote: On Thu, 15 Sep 2005, Stephen J.

Re: [Clamav-users] Spyware detection...

2005-09-15 Thread Joanna Roman
--- Christopher X. Candreva [EMAIL PROTECTED] wrote: On Mon, 12 Sep 2005, Stephen J. Smoogen wrote: I am currently looking at doing the same thing. I have a set of boxes that I am planning to 'infect' with spyware and then start making signatures for them. It is a rather slow process

Re: [Clamav-users] Spyware detection...

2005-09-14 Thread Dan MacNeil
Thomas Hruska wrote: [asks in a somewhat forceful way that clam detect spyware] Perhaps you might offer to pay the clamav group to add the features you desire. free is speech not beer. ___ http://lurker.clamav.net/list/clamav-users.html

Re: [Clamav-users] Spyware detection...

2005-09-12 Thread Joanna Roman
--- Thomas Hruska [EMAIL PROTECTED] wrote: Dennis Peterson wrote: Meanwhile, why don't you create signatures for known spyware and place them in your configuration? ClamAV allows this, you know. If you get good at it you can share them. dp Actually I didn't know that. I was

RE: [Clamav-users] Spyware detection...

2005-09-12 Thread ANONYMOUS
I think what you're looking for is Spybot Search Destroy. Google it because I forgot the exact URL. And it's completely free. ___ http://lurker.clamav.net/list/clamav-users.html

Re: [Clamav-users] Spyware detection...

2005-09-12 Thread Stephen J. Smoogen
On 9/11/05, Thomas Hruska [EMAIL PROTECTED] wrote: Thank you but I already know the tool doesn't exist or I wouldn't be wandering around this forum. Since the tool doesn't exist, I found the _closest_ possible tool to the tool I am looking for and ClamAV happens to be that tool. You should

Re: [Clamav-users] Spyware detection...

2005-09-12 Thread Christopher X. Candreva
On Mon, 12 Sep 2005, Stephen J. Smoogen wrote: I am currently looking at doing the same thing. I have a set of boxes that I am planning to 'infect' with spyware and then start making signatures for them. It is a rather slow process at the moment.. There doesn't seem to be any reason a

Re: [Clamav-users] Spyware detection...

2005-09-12 Thread Dennis Peterson
--- Thomas Hruska [EMAIL PROTECTED] wrote: Aren't there already spyware signatures in ClamAV database ?

[Clamav-users] Spyware detection...

2005-09-11 Thread Thomas Hruska
I hate to crosspost, but since it appears no one reads the Win32 list, I switched my subscription to the main users list. I've got ClamAV working and that is all good and fine. However, I looked in the archives of the clamav-users list and saw that still as of June 2005, ClamAV is completely

Re: [Clamav-users] Spyware detection...

2005-09-11 Thread Dale Walsh
On Sep 11, 2005, at 10:07 PM, Thomas Hruska wrote: I hate to crosspost, but since it appears no one reads the Win32 list, I switched my subscription to the main users list. I've got ClamAV working and that is all good and fine. However, I looked in the archives of the clamav-users list

Re: [Clamav-users] Spyware detection...

2005-09-11 Thread Dennis Peterson
Thomas Hruska said: I hate to crosspost, but since it appears no one reads the Win32 list, I switched my subscription to the main users list. Everything you require can be found at Google. As you observed, ClamAV is not in the spyware detection business. dp

Re: [Clamav-users] Spyware detection...

2005-09-11 Thread Thomas Hruska
Dale Walsh wrote: What your asking for sounds simple however, how do you establish detection?? Can't you use the existing signature scanning technology in ClamAV to identify known spyware vendors? Spyware vendors distribute either embedded libraries or have specific DLLs or EXEs -

Re: [Clamav-users] Spyware detection...

2005-09-11 Thread Thomas Hruska
Dennis Peterson wrote: Thomas Hruska said: I hate to crosspost, but since it appears no one reads the Win32 list, I switched my subscription to the main users list. Everything you require can be found at Google. As you observed, ClamAV is not in the spyware detection business. dp No it

Re: [Clamav-users] Spyware detection...

2005-09-11 Thread Dennis Peterson
Thomas Hruska said: Dennis Peterson wrote: Thomas Hruska said: I hate to crosspost, but since it appears no one reads the Win32 list, I switched my subscription to the main users list. Everything you require can be found at Google. As you observed, ClamAV is not in the spyware detection

Re: [Clamav-users] Spyware detection...

2005-09-11 Thread Thomas Hruska
Dennis Peterson wrote: Thomas Hruska said: Dennis Peterson wrote: Thomas Hruska said: I hate to crosspost, but since it appears no one reads the Win32 list, I switched my subscription to the main users list. Everything you require can be found at Google. As you observed, ClamAV is not

Re: [Clamav-users] Spyware detection...

2005-09-11 Thread Dennis Peterson
Thomas Hruska said: Dennis Peterson wrote: Thank you but I already know the tool doesn't exist or I wouldn't be wandering around this forum. Since the tool doesn't exist, I found the _closest_ possible tool to the tool I am looking for and ClamAV happens to be that tool. You should be

Re: [Clamav-users] Spyware detection...

2005-09-11 Thread Thomas Hruska
Dennis Peterson wrote: Meanwhile, why don't you create signatures for known spyware and place them in your configuration? ClamAV allows this, you know. If you get good at it you can share them. dp Actually I didn't know that. I was under the impression that it was completely central

[clamav-users] Spyware detection

2003-07-10 Thread Gerardo Reynoso Cobos
Which is the status of spyware detection withc clamav? I searched through viruses.db and could not find signatures for some samples of spyware. Previusly, I had some troubles with a sony vaio and tgcmd.exe (=spyware). I tried to detect it running clamscan via smbmount without result. Is it