Re: [clamav-users] ClamAV installation required?

2025-07-16 Thread Andrew C Aitchison via clamav-users
On Wed, 16 Jul 2025, Newcomer01 via clamav-users wrote: inner my cronjob with 'freshclam start' on end 'freshclam stop' - not as daemon Do you have a good reason *not* to use the daemon ? --- On Wed, 16 Jul 2025, Newcomer01 via clamav-users wrote: Then on each Upgrade Ubuntu replaces my wh

Re: [clamav-users] manual download av definitions updates how long ?

2025-06-11 Thread Andrew C Aitchison via clamav-users
On Wed, 11 Jun 2025, Dirk Nichterwitz via clamav-users wrote: Am 10.06.25 um 22:25 schrieb Joel Esler: Manual downloads of the definitions were blocked about 5 years ago. That's not really true. You can already download it from here * |https://database.clamav.net/main.cvd| * |https://databa

Re: [clamav-users] Help with ClamAV 1.0.7 on Ubuntu

2025-06-04 Thread Andrew C Aitchison via clamav-users
On Wed, 4 Jun 2025, Perez Dominguez, Andres via clamav-users wrote: Hello, I wanted to know if there is a way to upgrade max file size scanning for ClamAV 1.0.7, I have seen that there is a limit at 4GB using clamdscan and that when I changed the value of max file size inside /etc/clamav/clamd.c

Re: [clamav-users] ClamAV daemon restarts via/through systemd

2025-06-04 Thread Andrew C Aitchison via clamav-users
On Mon, 2 Jun 2025, Ben Argyle via clamav-users wrote: We're running ClamAV on RHEL 8 from EPEL 8: clamd-1.0.8-1.el8.x86_64 clamav-freshclam-1.0.8-1.el8.x86_64 clamav-1.0.8-1.el8.x86_64 I know it's old, but that's what we've got to work with. Anyway, we're seeing an issue where all of our clam

Re: [clamav-users] ClamAV consumes so much memory that my Postfix service gets killed by OOM Killer from time to time

2025-03-04 Thread Andrew C Aitchison via clamav-users
On Tue, 4 Mar 2025, Turritopsis Dohrnii Teo En Ming via clamav-users wrote: Good day from Singapore, ClamAV consumes so much memory that my Postfix service gets killed by OOM Killer from time to time. Yes, ClamAV needs 1-2GB RAM to store the database of malware to search for and double that

Re: [clamav-users] Scanning multiple uploads at the same time

2025-01-25 Thread Andrew C Aitchison via clamav-users
On Wed, 22 Jan 2025, newcomer01 via clamav-users wrote: Hi Florens, clamav can handle files up to 4GB form 1.2.0 onwards -> https://blog.clamav.net/2023/08/clamav-120-feature-version-and-111-102.html Not quite. MaxScanSize is no longer limited to 2GB or 4GB, but MaxFileSize is still limited

Re: [clamav-users] clamd.conf directives

2025-01-19 Thread Andrew C Aitchison via clamav-users
On Sun, 19 Jan 2025, Diggy via clamav-users wrote: Where can I find which directives in "clamd.conf" apply to which components (clamd, clamdscan, clamonacc) ??? Hmm. Well, 'man clamdscan' does say that It accepts all the options implemented in clamscan but most of them will be ignored

Re: [clamav-users] ClamAV 1.4 as Next Long-Term Stable (LTS)

2025-01-08 Thread Andrew C Aitchison via clamav-users
On Wed, 8 Jan 2025, newcomer01 via clamav-users wrote: That is great news Micah. Thank you and your team for continuously developing clamav! Is there a way to get the 1.4.1 LTS for Ubuntu 24.04.* LTS directly from clamav (via a "special" ppa maybe)? We talked little about that in the past

Re: [clamav-users] Scan Limit Explanation

2025-01-06 Thread Andrew C Aitchison via clamav-users
On Mon, 6 Jan 2025, Marijus Gudiskis via clamav-users wrote: I would like to know the reasoning behind these limits and why are they are relatively conservative: * MaxFileSize 25M * MaxScanSize 100M Do you think this limit would still be safe?: * MaxFileSize 500M * Max

Re: [clamav-users] Using linux command "find" to get modified files list for scan

2024-12-15 Thread Andrew C Aitchison via clamav-users
On Tue, 10 Dec 2024, neel roy via clamav-users wrote: > I think Neel's intention is to reduce the system load. Thanks! Yes, and it's all over internet - discussions about ClamAV CPU usage. I did face the same problem with McAfee but that was 15 years back. So, I think it goes to show that is p

Re: [clamav-users] Using linux command "find" to get modified files list for scan

2024-12-09 Thread Andrew C Aitchison via clamav-users
On Mon, 9 Dec 2024, neel roy via clamav-users wrote: Yes, that I found evident as described in mail below. Yet, no antivirus including ClamAV use this approach in their product. There must be reason(s). I am just trying to find that reason. I do not think it is very useful to only scan file

Re: [clamav-users] [ext] Scanning memory mapped files

2024-12-05 Thread Andrew C Aitchison via clamav-users
On Thu, 5 Dec 2024, neel roy via clamav-users wrote: Hello Ralf, I hope I can ask follow up question. You wrote: > I doesn't (from the clamonacc man page): > The clamonacc daemon registers for file access notifications from the > Linux kernel and in response, submits scans to the clamd sca

Re: [clamav-users] Question on sigtool memory usage

2024-10-03 Thread Andrew C Aitchison via clamav-users
On Thu, 3 Oct 2024, Andrew C Aitchison via clamav-users wrote: On Wed, 2 Oct 2024, Mikhail Soumar via clamav-users wrote: Hello, We are using sigtool to decompile the standard clamav virus signature databases in a low-memory environment. However, the process is too short-lived for us to

Re: [clamav-users] Question on sigtool memory usage

2024-10-03 Thread Andrew C Aitchison via clamav-users
On Wed, 2 Oct 2024, Mikhail Soumar via clamav-users wrote: Hello, We are using sigtool to decompile the standard clamav virus signature databases in a low-memory environment. However, the process is too short-lived for us to accurately measure peak usage. Is there a way we can get an estimate

Re: [clamav-users] Installing CAV to an infected system - that can't be safe?

2024-08-06 Thread Andrew C Aitchison via clamav-users
On Tue, 6 Aug 2024, Philip Rhoades via clamav-users wrote: People, I have been using Linux since the 0.9 kernel days and had to deal with the first worm to an infect a Linux system many years ago. I haven't allowed remote ssh access to any of my LANs for a long time now but of course crap s

Re: [clamav-users] Issue getting private local mirror to work

2024-07-17 Thread Andrew C Aitchison via clamav-users
On Wed, 17 Jul 2024, j via clamav-users wrote: Hello, I have set up cvdupdate on my server and apache to serve the files - no issues there, cvdupdate checks and gets the latest updates. Issue is with downstream servers. I can curl the files directly, but freshclam wont get them. I've set the fo

Re: [clamav-users] Inquiry About Security Measures for Remote Scanning Using Clamdscan

2024-07-05 Thread Andrew C Aitchison via clamav-users
On Fri, 5 Jul 2024, Khodor Barakat wrote: What i am trying to implement is to avoid running clamd as daemon locally and want to use a dedicated server for the scan that will be used by multiple server the scan will be done within the intranet so traffic is not exposed , but wanted to see if ther

Re: [clamav-users] Inquiry About Security Measures for Remote Scanning Using Clamdscan

2024-07-05 Thread Andrew C Aitchison via clamav-users
On Tue, 2 Jul 2024, Khodor Barakat via clamav-users wrote: Hi, everyone I am writing to inquire about the security measures implemented when using ClamAV's clamdscan for remote scanning, particularly when streaming to port 3310. clamdscan -c /etc/clamd.d/remote-scan.conf --fdpass --stream /tm

Re: [clamav-users] Debian 12.6 - clamav-deamon does not use a socket

2024-06-30 Thread Andrew C Aitchison via clamav-users
On Sun, 30 Jun 2024, christian via clamav-users wrote: Am 30.06.2024 um 20:06 schrieb Paul Kosinski via clamav-users: Did you check the permissions on the clamd socket to see if it allows access by rspamd? (I sometimes get burned by mismatched permissions.) It should work with clamav:cl

Re: [clamav-users] [External] Re: Question on ClamAV memory usage with respect to the signature database

2024-06-24 Thread Andrew C Aitchison via clamav-users
On Tue, 18 Jun 2024, Mikhail Soumar via clamav-users wrote: Thank you both for your responses. Regarding the centralized server (or just running it remotely in general), is there a certain limit for how many VM's a central VM running ClamAV can scan? I'm guessing it's a function of disk space

Re: [clamav-users] Question on ClamAV memory usage with respect to the signature database

2024-06-17 Thread Andrew C Aitchison via clamav-users
On Tue, 18 Jun 2024, Mikhail Soumar via clamav-users wrote: We are a team from Microsoft Azure running ClamAV on small Linux VMs, and due to business and cost reasons we cannot use larger VMs. Peak memory usage of ClamAV is between 1.2GB and 1.5GB, which is unsustainable on our VMs, and we are l

Re: [clamav-users] Using clamd@ service vs launching clamd from command line

2024-06-10 Thread Andrew C Aitchison via clamav-users
On Mon, 10 Jun 2024, neel roy via clamav-users wrote: Thanks. On selinux, which is the case with me, running clamd as *standalone process* is more advantageous than running as systemd service. The reason is mentioned in the post by someone else couple of years back. I am facing similar issu

Re: [clamav-users] [EXTERNAL EMAIL] - Re: ClamAV.0.103.11 as clamav-0.103.11-1.aix7.1.ppc.rpm fails to install on AIX7.2 on non AIX dependencies like vim

2024-05-03 Thread Andrew C Aitchison via clamav-users
On Fri, 3 May 2024, Brendan Walsh wrote: IBM has this handy install option called 'install from all available'. Say if you want to install something like clamav in /software/clamav. so you call it with that option and it checks the dependencies and looks thru all the files in the dir and uses

Re: [clamav-users] ClamAV.0.103.11 as clamav-0.103.11-1.aix7.1.ppc.rpm fails to install on AIX7.2 on non AIX dependencies like vim

2024-05-02 Thread Andrew C Aitchison via clamav-users
On Thu, 2 May 2024, Andrew C Aitchison wrote (but the list bounced): On Thu, 2 May 2024, Brendan Walsh via clamav-users wrote: Hi guys, I have been trying to install the IBM version of ClamAV.0.103.11 which I downloaded from IBMs open source page : https://www.ibm.com/support/pages/node/8837

Re: [clamav-users] Help with clamav

2024-04-10 Thread Andrew C Aitchison via clamav-users
un 15 different clam scans on all my vms. That is likely the price you pay for a scan that doesn't require that you send the whole disk over the network. -Original Message- From: clamav-users On Behalf Of Andrew C Aitchison via clamav-users Sent: 05 April 2024 19:49 To: Nathan Mil

Re: [clamav-users] False positive?

2024-04-08 Thread Andrew C Aitchison via clamav-users
There are also reports on Reddit today of ClamAV finding this: https://www.reddit.com/r/flatpak/comments/1byn8og/clamav_detecting_winvirusexpiro100265760_malware/?rdt=45424 One reply says: I ran one of the files tagged as a virus by Clamav through VirusTotal.com; out of 64 anti-virus utilities

Re: [clamav-users] freshclam with lambda and S3

2024-04-07 Thread Andrew C Aitchison via clamav-users
On Wed, 3 Apr 2024, Matthew Hibberd via clamav-users wrote: * I am hosting the ClamAV DB files on S3. * I have a lambda routinely running as a cron job that downloads the latest DB files from S3 to a local dir and runs freshclam against said dir as its database directory. * freshcla

Re: [clamav-users] Help with clamav

2024-04-05 Thread Andrew C Aitchison via clamav-users
ed by them. -Original Message- From: clamav-users On Behalf Of Andrew C Aitchison via clamav-users Sent: 05 April 2024 17:21 To: Nathan Millard via clamav-users Cc: Andrew C Aitchison Subject: Re: [clamav-users] Help with clamav On Fri, 5 Apr 2024, Nathan Millard via clamav-users

Re: [clamav-users] Help with clamav

2024-04-05 Thread Andrew C Aitchison via clamav-users
On Fri, 5 Apr 2024, Nathan Millard via clamav-users wrote: I would like some help setting up clamav to scan remote hosts from a clamd server is this possible? Nearly. In the likely setup, each client reads the files and sends them to the server for checking. For Linux etc. you can get a cent

Re: [clamav-users] Squid and ClamAV issues

2024-03-30 Thread Andrew C Aitchison via clamav-users
On Fri, 29 Mar 2024, Jonathan Lee via clamav-users wrote: Does anyone know how to fix this issue for version 335? "The database server doesn't have the latest patch for the bytecode database (version 335). The server will likely have updated if you check again in a few hours. ERROR: downloadPa

Re: [clamav-users] How does one Obtain ClamAV Linux Anvi-Virus Database File Updates for Systems not Connected to the internet

2024-03-25 Thread Andrew C Aitchison via clamav-users
On Mon, 25 Mar 2024, McCarthy, John D. [US-US] via clamav-users wrote: How does one Obtain ClamAV Linux Anvi-Virus Database File Updates for Systems not Connected to the internet? All our systems are air-gapped (not internet connected) so as ClamAV provides Linux Anvi-Virus Database File Upda

Re: [clamav-users] Debian libmspack breakage to fix y2038

2024-02-29 Thread Andrew C Aitchison via clamav-users
Thanks Scott. Glad to hear that this is under control. On Thu, 29 Feb 2024, Scott Kitterman via clamav-users wrote: On February 29, 2024 12:56:47 PM UTC, Andrew C Aitchison via clamav-users wrote: I haven't fully understood this yet, but Debian is planning a flag-day on 29 March t

[clamav-users] Debian libmspack breakage to fix y2038

2024-02-29 Thread Andrew C Aitchison via clamav-users
I haven't fully understood this yet, but Debian is planning a flag-day on 29 March to fix the y2038 bug on 32bit systems (possibly excluding intel). https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1063130 Since clamav uses libmspack it is listed at https://tracker.debian.org/pkg/libmspack

Re: [clamav-users] Need help with clamd on Ubuntu

2024-01-09 Thread Andrew C Aitchison via clamav-users
On Mon, 8 Jan 2024, Marisa Giancarla via clamav-users wrote: Hello. I am trying to get a fresh install of clamav working on Ubuntu 20.04 and I am having issues when starting clamd. When I try and start it, it comes up for maybe 5 secs then shuts itself> down. Anyone have any suggestions?

Re: [clamav-users] An example of why ClamAV should be able to scan disk images (which are typically over 2 GB)

2024-01-06 Thread Andrew C Aitchison via clamav-users
On Tue, 2 Jan 2024, Paul Kosinski via clamav-users wrote: CVE-2021-44879 Wenqing Liu reported a NULL pointer dereference in the f2fs implementation. An attacker able to mount a specially crafted image ^^^ can take adv

Re: [clamav-users] first questioon????

2023-10-25 Thread Andrew C Aitchison via clamav-users
On Sun, 22 Oct 2023, Rahim Fakir via clamav-users wrote: I would like to know if it is possible to have clamav on the desktop and remotely scan the phone. for example: clamscan -r -i remove=yes ipaddress root.of.cellphone For Android it is likely you can use https://play.google.com/store/apps/

Re: [clamav-users] [ext] Compressing log files with clamav

2023-10-24 Thread Andrew C Aitchison via clamav-users
On Tue, 24 Oct 2023, Vu, Hong-Duc V. via clamav-users wrote: Use logrotate: == Thank you Ralf. I take that to mean there is no compression directive in the configuration file by default. Are there plans to add this feature to a future release, Micah? I guess this might be usef

Re: [clamav-users] Error installing from source

2023-10-13 Thread Andrew C Aitchison via clamav-users
On Fri, 13 Oct 2023, Paul Netpresto wrote: HI You need to find a later version of GCC for your servers. I had a similar problem with some legacy Ubuntu machines. Fortunately an upgrade to GCC 7.5 was available in the Ubuntu release archive. For CentOS 6 the devtoolset-7 suite will give you

Re: [clamav-users] About PDF files detected as encrypted files

2023-10-11 Thread Andrew C Aitchison via clamav-users
On Tue, 10 Oct 2023, Tsutomu Oyamada wrote: Hi, all We received following report from one of our users. The user is uisng Clamd0.103 on AIX7,2. When clamd with the option "ArchiveBlockEncrypted" ON scans a specifc PDF which is locked for editing, it is detected as "Heuristics.Encrypted.PDF FO

Re: [clamav-users] freshclam not working

2023-09-12 Thread Andrew C Aitchison via clamav-users
On Tue, 12 Sep 2023, Joel Esler via clamav-users wrote: Curl won’t work at all.   But it definitely points to a dns problem.  — Sent from my iPhone On Sep 11, 2023, at 13:07, Serge Slivitzky via clamav-users wrote:   Hi all, I'm using clamav on 2 systems built the same way:

Re: [clamav-users] Any hard size limit for scanned files?

2023-08-29 Thread Andrew C Aitchison via clamav-users
On Tue, 29 Aug 2023, Ray wrote: my company is considering moving away from ClamAV. They claim there's a file size limitation for scanned files in ClamAV that a commercial product could overcome. Is that true? I found this comment on an Ubuntu forum, which is not too old. It claims there is

Re: [clamav-users] Help clamdscan faster

2023-08-24 Thread Andrew C Aitchison via clamav-users
On Thu, 24 Aug 2023, Nhat Tran Xuan via clamav-users wrote: Hello, We are running a file management project with file storage using amazon S3. Our core architecture is every time there is an event to upload or edit a file on s3, it will trigger an event to run an ECS task, that ECS will be a co

Re: [clamav-users] Catching javascript in html attachment

2023-08-04 Thread Andrew C Aitchison via clamav-users
On Fri, 4 Aug 2023, Scott via clamav-users wrote: I was looking for a way to write my own detection mechanisms. I know I can detect binary files by creating signatures with sigtool but this javascript can change like one character and the signature would be off. I'm thinking something more gene

Re: [clamav-users] ClamAV Current CDN Rate Limit

2023-07-18 Thread Andrew C Aitchison via clamav-users
On Tue, 18 Jul 2023, Jaspreet Nahal via clamav-users wrote: Hi, I'm building an application using ClamAV as our AV of choice and trying to evaluate the different approaches to avoiding hitting the CDN more than what is absolutely necessary. As a part of this quest, would you be able to share ho

Re: [clamav-users] Question About MaxFileSize

2023-06-08 Thread Andrew C Aitchison via clamav-users
On Thu, 8 Jun 2023, Micah Snyder (micasnyd) wrote: I agree with you. I suspect the majority of cases today is when people have a large archive of files to scan. I think best case scenario for people with a need to scan files larger than the present internal 2GB limit is that archives larger th

Re: [clamav-users] Question About MaxFileSize

2023-05-24 Thread Andrew C Aitchison via clamav-users
On Wed, 24 May 2023, Tachibanaki Nozomi (橘木 希美) wrote: Dear Sir or Madam, Thank you for your help always. I am contacting you to ask about MaxFileSize in clamd.conf. The following description is found in the configuration of /usr/local/etc/clamd.conf. MaxFileSize # Technical design limitation

Re: [clamav-users] How to get rid of or Fix clamonacc error

2023-03-22 Thread Andrew C Aitchison via clamav-users
[ My previous reply did not reach the list, for reasons I do understand. ] On Tue, 21 Mar 2023, Tim McConnell wrote: Hi Andrew, So maybe I'm mis understanding something. I'm expecting the scan to run once daily at 01:00. Is that not what clamonacc does? I keep getting told to remove it but De

Re: [clamav-users] clamdscan: show clean files?

2023-03-13 Thread Andrew C Aitchison via clamav-users
On Mon, 13 Mar 2023, Schulze, Andreas via clamav-users wrote: Hello, we like to scan directories an gather verbose reports. These must include information about the scan result for each file. Using clamdscan, this does not happen: clamdscan inform only on infected files. # clamdscan --version

Re: [clamav-users] linux distribution including clamav-1.0.1

2023-03-07 Thread Andrew C Aitchison via clamav-users
On Tue, 7 Mar 2023, kumar bava via clamav-users wrote: Hi, please help me with the below question, thank you We have been using clamav-0.103.6 and would like to upgrade to the new LTS release(1.0.x). However, I can not find clamav-1.0.1 in EPEL distribution. Our systems are based on rhel7. So

Re: [clamav-users] What was detected?

2023-02-27 Thread Andrew C Aitchison via clamav-users
On Mon, 27 Feb 2023, joe a wrote: 66 On 2/27/2023 4:24 PM, Paul Netpresto wrote: I attempted that just now. Ran clamscan --debug -f some-email.eml After it cranks up and apparently beings actually scanning the email, starts cranking out errors/warnings like: Return-path: : No such file or d

Re: [clamav-users] Funny --include-dir behaviour

2023-02-13 Thread Andrew C Aitchison via clamav-users
Sorry thi is coming sd an attachment. I sent this with the wrong from address so it didn't reach the list the first time. -- Andrew C. Aitchison Kendal, UK and...@aitchison.me.uk--- Begin Message --- On Mon, 13 Feb 2023, newcomer01 via clamav-users wrote:

Re: [clamav-users] about ”Can't allocate memory ERROR”

2023-02-09 Thread Andrew C Aitchison via clamav-users
On Thu, 9 Feb 2023, Tsutomu Oyamada wrote: Hi, Andy. Thanks for your reply. I am aware that version 0.103.4 is still supported by LTS. 0.103.4 came out in Nov 2021. The current supported versions include 0.103.7 from July 2022. Also, my system is AIX. Does that have an effect? I would li

Re: [clamav-users] Problem with freshclam

2022-12-29 Thread Andrew C Aitchison via clamav-users
[ Apologies, my previous reply failed to reach the list. ] On Thu, 29 Dec 2022, newcomer01 wrote: Yes, the "Error-Log" comes only when freshclam will be started from reboot via cron job Did I understand you well? @reboot host -t txt current.cvd.clamav.net /etc/clamav/clamav_opts sigs_updat

Re: [clamav-users] LibClamAV Warning: PNG: Unexpected early end-of-file.

2022-12-12 Thread Andrew C Aitchison via clamav-users
On Mon, 12 Dec 2022, newcomer01 wrote: Well on my PC I changed a lot because the naming was too messy for me. I have "program" clam*d*scan for which I have a clam*d*.conf and a "program" clamscan for which I have a clamscan.conf. And then the normal "program" freshclam with the freshclam.conf

Re: [clamav-users] LibClamAV Warning: PNG: Unexpected early end-of-file.

2022-12-12 Thread Andrew C Aitchison via clamav-users
On Mon, 12 Dec 2022, newcomer01 via clamav-users wrote: can nobody explain, what this message exactly mean? I Get the on lot of my E-mails LibClamAV Warning: PNG: Unexpected early end-of-file. That just means that the PNG file is either not a PNG for or is corrupted - perhaps truncated. Sh

Re: [clamav-users] Ubuntu file needed

2022-12-09 Thread Andrew C Aitchison via clamav-users
On Fri, 9 Dec 2022, newcomer01 via clamav-users wrote: can someone showm me screesnhots on the setted permissons from: / etc/ init.d / clamav-daemon and / etc / init.d / freshclam please? And additionally must this files run as program too? This should have all that information: # ls -l /etc/

Re: [clamav-users] parallel processes fail at startup when clamd is running

2022-11-28 Thread Andrew C Aitchison via clamav-users
On Mon, 28 Nov 2022, JOHN URBAN via clamav-users wrote: We are experiencing a large number of MPI jobs failing indicating the fabric is unavailable when the scans are running. Early in the investigation so not sure if locking, timing, response time or other factors are involved, but I wanted t

Re: [clamav-users] ClamAV scan time improvement

2022-11-09 Thread Andrew C Aitchison via clamav-users
On Tue, 8 Nov 2022, Vijay Kumar Kamannavar via clamav-users wrote: Hello Team, We are leveraging ClamAV agent for our vm's malware detection. we tried to scan a vm with 30GB used space and it took approx 1.30Hrs(we tried to capture certain file extensions to reduce number of files and passed

Re: [clamav-users] [ext] ClamAV 1.0.0 release candidate now available

2022-11-02 Thread Andrew C Aitchison via clamav-users
On Wed, 2 Nov 2022, Micah Snyder (micasnyd) wrote: Hi Andrew, Should cli_cvdverify() even be used to verify .cld files ? Indeed, it should not. Here is my PR to fix the issue. Are you able to try it out to help verify it resolves the issue on your end? https://github.com/Cisco-Talos/clama

Re: [clamav-users] [ext] ClamAV 1.0.0 release candidate now available

2022-10-30 Thread Andrew C Aitchison via clamav-users
On Fri, 28 Oct 2022, Yasuhiro Kimura wrote: From: Ralf Hildebrandt via clamav-users Subject: Re: [clamav-users] [ext] ClamAV 1.0.0 release candidate now available Date: Fri, 28 Oct 2022 09:10:46 +0200 * Micah Snyder (micasnyd) via clamav-users : We are excited to announce the ClamAV 1.0.0 r

Re: [clamav-users] ClamAV 1.0.0 release candidate now available

2022-10-28 Thread Andrew C Aitchison via clamav-users
On Tue, 25 Oct 2022, Micah Snyder (micasnyd) via clamav-users wrote: Read this announcement online at https://blog.clamav.net/2022/10/clamav-100-release-candidate-now.html We are excited to announce the ClamAV 1.0.0 release candidate! You may find the source code and installers for this rele

Re: [clamav-users] ClamAV on RHEL9 with FIPS enabled

2022-10-27 Thread Andrew C Aitchison via clamav-users
On Wed, 26 Oct 2022, Orion Poplawski via clamav-users wrote: On 10/24/22 11:03, Hoevenaar, Jeffrey (GE Aerospace, US) via clamav-users wrote: Hello, It would appear ClamAV will not run on RHEL9 with FIPS enabled. Has anyone else seen this issue? Known issue: https://github.com/Cisco-Talos/c

[clamav-users] Incremental updates and server memory

2022-09-08 Thread Andrew C Aitchison via clamav-users
I guess that this would be a long term project ... The malware databases are updated with cdiffs, which means that the whole database does not have to be re-downloaded with each update. However, the running daemon has to re-read the whole database from disk (temporarily doubling the memory req

Re: [clamav-users] No daily sig since July 28th

2022-08-01 Thread Andrew C Aitchison via clamav-users
On Mon, 1 Aug 2022, Shawn Iverson via clamav-users wrote: Hello, I've noticed that a daily hasn't been posted since the 28th of July. Are daily sigs being posted? # clamscan --version ClamAV 0.103.7/26615/Thu Jul 28 08:58:07 2022 # host -t txt current.cvd.clamav.net. current.cvd.clamav.net

Re: [clamav-users] ClamAV's 'configure' doesn't seem to complain about invalid options

2022-07-22 Thread Andrew C Aitchison via clamav-users
On Thu, 21 Jul 2022, Paul Kosinski via clamav-users wrote: Building 0.103.6, I ran 'configure' with the option "--disable-clamonaccess" (instead of "--disable-clamonacc") and got no error or warning that the option was not recognized. I did this because I realized that I had still been using th

Re: [clamav-users] Where can I download daily.cvd, bytecode.cvd and main.cvd from?

2022-01-17 Thread Andrew C Aitchison via clamav-users
On Mon, 17 Jan 2022, Nick Howitt via clamav-users wrote: On 17/01/2022 14:33, Andrew C Aitchison wrote: Not quite. I have taken over the packaging of this and the justification of packaging the sigs is partly that the tool will work and scan out of the box, partly for the offline considerati

Re: [clamav-users] Where can I download daily.cvd, bytecode.cvd and main.cvd from?

2022-01-17 Thread Andrew C Aitchison via clamav-users
On Mon, 17 Jan 2022, Nick Howitt via clamav-users wrote: Isn't that a bit messy? It would be so much easier to be able to use curl, wget or any browser to get the sigs so we can package them directly Unfortunately the server load was ridiculus and that had to be stopped. Petabyte per day IIRC.

Re: [clamav-users] Problem installing ClamAV 104.1 on CentOS 7

2021-12-07 Thread Andrew C Aitchison via clamav-users
On Mon, 6 Dec 2021, Bowie Bailey via clamav-users wrote: I followed the instructions to install the prerequisites and then went through the steps for the default build.  Everything went fine until I got to the last step. $ sudo cmake --build . --target install sudo: cmake: command not found

Re: [clamav-users] using older clients to download from internal clam proxy

2021-12-02 Thread Andrew C Aitchison via clamav-users
On Thu, 2 Dec 2021, novpenguincne via clamav-users wrote: Thank you for the quick response. So that would lead into the logical next question. What would be the earliest client version that would work? I tried installing the 103.x client on that box but 103.x requires SystemD and this older b

Re: [clamav-users] Nonsensical noreplies from ClamAV team

2021-11-18 Thread Andrew C Aitchison via clamav-users
On Thu, 18 Nov 2021, Alessandro Vesely via clamav-users wrote: Hi all, even though I filter incoming messages with ClamAV, last Monday I received a mail with two suspicious attachments. They were PE32+ executable (DLL) (GUI) x86-64, for MS Windows. I uploaded the samples to virustotal.c

Re: [clamav-users] how to build release 0.104.1 in non-standard systems

2021-11-04 Thread Andrew C Aitchison via clamav-users
On Fri, 5 Nov 2021, anctop--- via clamav-users wrote: We are using ClamAV on our server for protection against virus. However, the build method (using "cmake") for the new 0.104.1 release has prevented us from upgrading promptly as before. While you are getting cmake to do what you need, vers

Re: [clamav-users] Docker Connection Refused on Host

2021-10-10 Thread Andrew C Aitchison via clamav-users
On Sun, 10 Oct 2021, Taylor Schley via clamav-users wrote: ClamD setup in the docker container is: `/run/clamav/clamd.socket` Which is bound to `/tmp/clamd.socket` on the host MacOS. The following works from inside of the container: `clamdtop ‘/run/clamav/clamd.socket’` The fo

Re: [clamav-users] Scanning a zip file fails, extract it, scan with the same options and it passes

2021-10-04 Thread Andrew C Aitchison via clamav-users
What are the compressed and uncompressed sizes of the problem file ? On Fri, 1 Oct 2021, Max Allan via clamav-users wrote: Hi, I have a requirement (from the business) to AV scan all docker containers we create. I started experimenting with tomcat:latest, which is handy because you can follow

Re: [clamav-users] error code 429

2021-09-04 Thread Andrew C Aitchison via clamav-users
[ Top-posting to be consistent with previous message.] I had the same problem as Jim and Paul (which resolved itself at about 03:00 UTC, after ~19 hours). I am running the 0.103.2 from Ubuntu 21.04. On Sun, 5 Sep 2021, Joel Esler (jesler) via clamav-users wrote: We are experimenting with a fe

Re: [clamav-users] can't cmake 1.0.4rc

2021-07-30 Thread Andrew C Aitchison via clamav-users
On Thu, 29 Jul 2021, Gene Heskett via clamav-users wrote: Well, I've screwed around with this for 3 days now, that's long enough. First gotcha for debian people is cmake is not installed, and when installed, it is NOT installed in a directory accessible to the user with a default $PATH, so the

Re: [clamav-users] can't cmake 1.0.4rc

2021-07-30 Thread Andrew C Aitchison via clamav-users
On Fri, 30 Jul 2021, Gene Heskett via clamav-users wrote: I see by synaptic, that both python-test and python3-test are available. Which is preferred? I'd assume python3-test in order to future proof, but assumptions are where we've gone aglay too many times already. My experience on fast-trac

Re: [clamav-users] Long Term Support (LTS) program proposal

2021-07-29 Thread Andrew C Aitchison via clamav-users
Executive Summary: An LTS release every two years, supported for three, starting with 0.103 sound good to me. Thank you. On Wed, 28 Jul 2021, Micah Snyder (micasnyd) via clamav-users wrote: For the past couple of months I've been promoting the idea of having Long Term Support (LTS) feature r

Re: [clamav-users] Freshclam - can't apply latest patch 26246

2021-07-29 Thread Andrew C Aitchison via clamav-users
On Thu, 29 Jul 2021, Asenova, Elia via clamav-users wrote: Thanks for the replies. Yes, deleting daily.cld fixed the problem. My concern is that I'm building a docker image with clamav inside it and I have to delete daily.cld on every new build if I want freshclam to work correctly the first tim

Re: [clamav-users] Freshclam - can't apply latest patch 26246

2021-07-28 Thread Andrew C Aitchison via clamav-users
On Wed, 28 Jul 2021, Asenova, Elia via clamav-users wrote: Hello guys, This is related to a freshclam update problem that I have. Basically when running freshclam I get the following errors: ClamAV update process started at Wed Jul 28 14:30:20 2021 daily database available for update (local ve

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Release Candidate is here!

2021-07-28 Thread Andrew C Aitchison via clamav-users
On Wed, 28 Jul 2021, Rick Cooper wrote: total disregard for the user base, not so much as a poll or query on the lists, When ClamAV 0.103 was released in September 2020 CMake was an *experimental* option. There will be a 0.103 release in September 2021, but is likely to be the last one. 0.10

Re: [clamav-users] can't cmake 1.0.4rc

2021-07-28 Thread Andrew C Aitchison via clamav-users
On Wed, 28 Jul 2021, Gene Heskett via clamav-users wrote: cmake --version RETURN says: cmake version 3.7.2 Ah. INSTALL.md says: ### Build requirements - CMake 3.16 for Windows, and 3.14+ for other operating systems. CMake suite maintained and supported by Kitware (kitware.c

Re: [clamav-users] ClamAV® blog: ClamAV 0.104.0 Release Candidate is here!

2021-07-26 Thread Andrew C Aitchison via clamav-users
On Mon, 26 Jul 2021, Frans de Boer wrote: Here's your problem: 8<-- [DEBUG]: Exit code: 1 [DEBUG]: stdout: Running suite(s): clamd 90%: Checks: 77, Failures: 7, Errors: 0 /home/frans/tw/data/projects/linux/security/clamav/clama

[clamav-users] Signature delimiter - was Re: ClamAV® blog: ClamAV 0.104.0 Release Candidate is here!

2021-07-22 Thread Andrew C Aitchison via clamav-users
On Thu, 22 Jul 2021, G.W. Haywood via clamav-users wrote: "~/clamav-0.104.0-rc/build: $ cmake .. -D CMAKE_BUILD_TYPE="Release"" "CMake Error at CMakeLists.txt:6 (cmake_minimum_required):" "CMake 3.14 or higher is required. You are running version 3.13.4" "" "" "-- Configuring incomplete, erro

Re: [clamav-users] Qnap TS-259Pro+

2021-07-13 Thread Andrew C Aitchison via clamav-users
The TS-259Pro+ appears go have 1GB RAM, which is not really enough to run clamav, so compiling from source is unlikely to be helpful. On Tue, 13 Jul 2021, Eero Volotinen wrote: You probably need to buy newer version of qnap nas or compile clamav from sources. Eero On Tue 13. Jul 2021 at 19.4

[clamav-users] Fw: openSUSE-SU-2021:2242-1: important: Security update for clamav-database

2021-07-07 Thread Andrew C Aitchison via clamav-users
On Wed, 7 Jul 2021, Joe Acquisto-j4 wrote: > On Tue, 6 Jul 2021, Joe Acquisto-j4 wrote: > > On Tue, 6 Jul 2021, G.W. Haywood wrote: > > > On Tue, 6 Jul 2021, Paul Kosinski via clamav-users wrote: > > > > > > > Just FYI: this is the first time I remember seeing openSUSE > > > > notifying something

Re: [clamav-users] clamdscan "Can't get file status ERROR"

2021-06-21 Thread Andrew C Aitchison via clamav-users
On Mon, 21 Jun 2021, Roger Rutishauser wrote: I'm using ClamAV 0.101.1/26207 with default clamd.config settings (except for enhanced logging) Please update to the latest version 0.103.2 See many recent messages in this list - you could be blocked for using an older version. I have a PDF (siz

Re: [clamav-users] Regarding increasing ClamAV file size while using docker

2021-06-08 Thread Andrew C Aitchison via clamav-users
On Tue, 8 Jun 2021, Karthik Iyer via clamav-users wrote: Hi, I would like to scan files as big as 100 gb. At present you cannot: https://lists.clamav.net/pipermail/clamav-users/2021-April/011018.html The code is not 64bit clean (maybe not even 32bit clean - the developers only guarantee

Re: [clamav-users] Manually copy and use local filesystem as DownloadMirror/PrivateMirror

2021-05-17 Thread Andrew C Aitchison via clamav-users
Anish, What sort of scanning are you doing on these client machines ? Which databases are you using with ClamAV ? What data is stored on these clients ? What operating system(s) are they running ? I ask since the way some of us run ClamAV there is little benefit on running it on each client mac

Re: [clamav-users] clamav incremental scan?

2021-05-09 Thread Andrew C Aitchison via clamav-users
On Tue, 4 May 2021, Michael Wang wrote: I do not disagree with you on the separate functionality of the scheduling engine and scanning engine. The question is: does such an engine exist? ClamWin has a scheduler https://clamwin.com/content/view/71/1/ but, although based on ClamAV, Cla

Re: [clamav-users] ClamAV® blog: ClamAV 0.103.2 security patch release

2021-04-14 Thread Andrew C Aitchison via clamav-users
Joel, You can add a direct link to the PGP key now as this is completely independant of the released packages. Better yet would be to 1) Sign the new key with the old one (which doesn't actually expire until Monday) 2) Get other (public domain) software people to sign your key. This assumes t

Re: [clamav-users] Unable to Update

2021-04-13 Thread Andrew C Aitchison via clamav-users
On Tue, 13 Apr 2021, j via clamav-users wrote: I've been getting the following message'WARNING: getpatch: Can't download daily-26093.cdiff from database.clamav.net WARNING: getpatch: Can't download daily-26093.cdiff from database.clamav.net WARNING: getpatch: Can't download daily-26093.cd

Re: [clamav-users] Error 429 when updating database

2021-04-08 Thread Andrew C Aitchison via clamav-users
On Thu, 8 Apr 2021, Joel Esler (jesler) via clamav-users wrote: Still, 102.4 should work properly, shouldn't it? It does. But 103.2 handles the downloads and interactions SO MUCH BETTER (I’ve been watching the updates for 103.2’s FreshClam all morning, and it’s working so much better. P

Re: [clamav-users] vistumbler as false positive

2021-04-08 Thread Andrew C Aitchison via clamav-users
On Thu, 8 Apr 2021, Eero Volotinen wrote: https://raw.github.com/acalcutt/Releases/master/Vistumbler/VistumblerMDB/v10/Vistumbler_v10-7.exe Looks like this is (vistumbler) detected as false positive. and On Thu, 8 Apr 2021, Arnaud Jacques wrote: At first look, ClamAV is not the only one t

Re: [clamav-users] clamscan suddenly taking 25 minutes for a single mail

2021-04-06 Thread Andrew C Aitchison via clamav-users
On Tue, 6 Apr 2021, Eddie via clamav-users wrote: A POP3 proxy program I have running on a Debian 10.8 system, uses clamscan to check incoming e-mails.  At some point in the very early morning (US West Coast time) it suddenly started taking a very long time to scan each mail,  So much that the

Re: [clamav-users] ClamAV 0.103.1 on RHEL 6.7 x32

2021-04-06 Thread Andrew C Aitchison via clamav-users
On Tue, 6 Apr 2021, Sorin Petrut Niculae via clamav-users wrote: Can anyone confirm if is possible to use ClamAV on RHEL 6.7 x32 I was able to install and copy the ddbb files (manually) to /usr/local/share/clamav but when I run clamscan I got the next error message: * [redhat@redhat clamav

Re: [clamav-users] Need help | Install clamav from source package

2021-03-28 Thread Andrew C Aitchison via clamav-users
Could you take the latest OpenSuSE source package and build that ? That might be an easier way to get SuSE-friendly config files than starting from the source on the ClamAV site. If the latest ClamAV source package on the latest OpenSuSE doesn't work, try the latest ClamAV source from an older

Re: [clamav-users] Heuristics, only on or off?

2021-03-23 Thread Andrew C Aitchison via clamav-users
On Tue, 23 Mar 2021, Joe Acquisto-j4 wrote: In log find (snipped) ". . .infected by Heuristics.OLE2.ContainsMacros.VBA" and ". . .infected by Heuristics.Phishing.Email.SpoofedDomain" I love the first one but loathe the second one. Is there some secret sauce to allow discriminating between t

Re: [clamav-users] Number of signatures downloaded has reduced significantly

2021-03-23 Thread Andrew C Aitchison via clamav-users
On Tue, 23 Mar 2021, Pierre Olivier KAPLAN wrote: A few days ago, it seems that you have changed your hosts and your signatures file base format. Since, we noticed that the amount of included signatures has been divided by 3 (from 1.904 M to 641 k). A lot of hashes have disappeared. Did the ge

Re: [clamav-users] ClamAV® blog: ClamAV, CVDs, CDIFFs and the magic behind the curtain

2021-03-20 Thread Andrew C Aitchison via clamav-users
On Fri, 19 Mar 2021, Joel Esler (jesler) via clamav-users wrote: https://blog.clamav.net/2021/03/clamav-cvds-cdiffs-and-magic-behind.html ClamAV, CVDs, CDIFFs and the magic behind the curtain 3. ... This is an expensive operation in terms of bandwidth because daily.cvd and main.cvd are, cu

Re: [clamav-users] Restriction of downloads

2021-03-13 Thread Andrew C Aitchison via clamav-users
On Sat, 13 Mar 2021, Matus UHLAR - fantomas wrote: I just found that my "antivirus essentiel" installed package provided by Synology is unable to update virus definition file since 03/06/2021 ! On 13/03/2021 00:47, G.W. Haywood via clamav-users wrote: Then should you not be talking to Syno

  1   2   >