Re: [clamav-users] undetected virus

2012-01-24 Thread Joel Esler
This has been handled. On Tue, Jan 24, 2012 at 3:52 AM, polloxx wrote: > On Tue, Jan 24, 2012 at 9:05 AM, Al Varnell wrote: > > On Jan 23, 2012, at 11:44 PM, polloxx wrote: > > > >> We received a virus not detected by Clamav. VirusTotal shows a 23/43 > >> detection ratio. Trend Micro recogises

Re: [clamav-users] sigtool verifies but freshclam fails

2012-01-24 Thread Greg Cirino
| On 01/24/2012 01:05 AM, Greg Cirino wrote: |> Ok, I'm not sure what is happening, but I did a wget of the main.cvd and |> ran the sigtool against it with the following command: |> |> sigtool --info=main.cvd |> |> and got this: |> |> File: main.cvd |> Build time: 11 Oct 2011 10:34 -0400 |> Versio

Re: [clamav-users] [LibClamAV] cli_tgzload: Invalid checksum for file main.mdb

2012-01-24 Thread Török Edwin
On 01/24/2012 12:46 AM, Greg Cirino wrote: > > Why is libclamav looking for main.mdb on a linux system? > main.cvd consists of a number of signature files, one of which is a .mdb file. A .mdb file is a plain text file that stores MD5 hash signatures in this format: size:hash:VirusName Best rega

Re: [clamav-users] sigtool verifies but freshclam fails

2012-01-24 Thread Török Edwin
On 01/24/2012 01:05 AM, Greg Cirino wrote: > Ok, I'm not sure what is happening, but I did a wget of the main.cvd and > ran the sigtool against it with the following command: > > sigtool --info=main.cvd > > and got this: > > File: main.cvd > Build time: 11 Oct 2011 10:34 -0400 > Version: 54 > Si

Re: [clamav-users] undetected virus

2012-01-24 Thread polloxx
On Tue, Jan 24, 2012 at 9:05 AM, Al Varnell wrote: > On Jan 23, 2012, at 11:44 PM, polloxx wrote: > >> We received a virus not detected by Clamav. VirusTotal shows a 23/43 >> detection ratio. Trend Micro recogises it as TROJ_GEN.R06C8AN. >> Yesterday I submitted a sample to Clamav. But till now i

Re: [clamav-users] undetected virus

2012-01-24 Thread Al Varnell
On Jan 23, 2012, at 11:44 PM, polloxx wrote: > We received a virus not detected by Clamav. VirusTotal shows a 23/43 > detection ratio. Trend Micro recogises it as TROJ_GEN.R06C8AN. > Yesterday I submitted a sample to Clamav. But till now it's not detected. > https://www.virustotal.com/file/d6a2ae