[clamav-users] Java.Malware fps

2017-04-06 Thread Henrik K
Whos' flooding crappy samples around, and why is ClamAV making sigs of tiny class files like org/eclipse/aether/impl/RemoteRepositoryManager.class? .m2/repository/org/codehaus/plexus/plexus-interpolation/1.19/plexus-interpolation-1.19.jar: Java.Malware.Agent-6205983-0 FOUND .m2/repository/org/c

Re: [clamav-users] Manual cdiff update procedure

2017-04-06 Thread venkat swaminathan
Correct me if i am wrong : freshclam needs configuration where I need to setup update server. But,my client system is connected to single server where only 2 ports are open for operation Port 1 : For executing commands in client machine from remote server Port 2 : Port for file transfer. Based on

Re: [clamav-users] Manual cdiff update procedure

2017-04-06 Thread Joel Esler (jesler)
Why would freshclam not be used? -- Sent from my iPhone > On Apr 6, 2017, at 07:36, venkat swaminathan wrote: > > Thanks Allan, > Mentioned below is my current progress. > all in /tmp/clam folder > > sigtool --unpack-current=daily (Unpacked Existing CVD from /var/lib/clam) > sigtool --verify-c

Re: [clamav-users] Manual cdiff update procedure

2017-04-06 Thread venkat swaminathan
Thanks Allan, Mentioned below is my current progress. all in /tmp/clam folder sigtool --unpack-current=daily (Unpacked Existing CVD from /var/lib/clam) sigtool --verify-cdiff /media/sf_works/python/clamAv/daily-23265.cdiff daily.cvd (Verfied it using sigtool for match) sigtool --run-cdiff /media/s

Re: [clamav-users] Manual cdiff update procedure

2017-04-06 Thread Mark Allan
Yes and no. You can use sigtool to unpack and then apply the individual cdiff scripts in turn (check the man page for details). This will give you a directory full of files which is the equivalent of the current cvd file, however you cannot then repackage and sign the resulting database directo