Re: [clamav-users] clamav-scanner-systemd

2020-11-25 Thread Graeme Fowler via clamav-users
stem) then you also need the 'clamd' package too. Also, you have only a few days to the EOL of CentOS 6 - https://wiki.centos.org/About/Product Graeme From: clamav-users on behalf of Will Watters via clamav-users Reply to: ClamAV users ML Date: Wednesday, 25 November 2020 at 13:

Re: [clamav-users] Possible threat in thunderbird?

2020-05-19 Thread Graeme Fowler via clamav-users
I would like to apologise for the comically incorrect grammar that Gboard gave me in that final sentence. Should be: " You can always look at the quarantine folder to see what the messages are, and then delete them from your Gmail account if they are unnecessary." Graeme From: cl

Re: [clamav-users] Possible threat in thunderbird?

2020-05-18 Thread Graeme Fowler via clamav-users
e what the messages are, and then delete them from your Gmail account of there is and unnecessary. Graeme From: clamav-users on behalf of Bud Rozwood via clamav-users Sent: 19 May 2020 02:19 To: clamav-users@lists.clamav.net Cc: Bud Rozwood Subject: [clamav-users

Re: [clamav-users] ClamAV Server Agent

2020-04-22 Thread Graeme Fowler via clamav-users
-of-scope for the environment you're working in *unless* they have client-provided data flowing through them. If they're not in the payment path and the content is all static then they should be considered out of scope. Graeme From: clamav-users on behalf of Karmendra Suthar via

Re: [clamav-users] What would be a basic scan of my file system (Linux, CentOS 7)?

2020-02-01 Thread Graeme Fowler via clamav-users
unning web apps, force them to keep them updated. If they don't, get rid of them. * if you find changes in system directories or files in /dev, burn the machine and start again. I'm sure other opinions will be forthcoming! Graeme From: c

Re: [clamav-users] ClamAV - What does the “clamd@scan” service do by default?

2020-01-27 Thread Graeme Fowler via clamav-users
basic command would be: clamdscan / ...but you need to configure clamd in /etc/clamd.d/scan.conf to do this. More details for EPEL based ClamAV packages are here: https://src.fedoraproject.org/rpms/clamav https://src.fedoraproject.org/rpms/clamav/blob/master/f/clamd-README G

Re: [clamav-users] unexplainable tar behaviour

2019-10-30 Thread Graeme Fowler via clamav-users
false positives, but you will need to provide your file. Graeme ___ clamav-users mailing list clamav-users@lists.clamav.net https://lists.clamav.net/mailman/listinfo/clamav-users Help us build a comprehensive ClamAV guide: https://github.com/vrtadmin/clamav-faq http://www.clamav.net/contact.html#ml

Re: [clamav-users] Packaging ClamAV

2019-08-12 Thread Graeme Fowler via clamav-users
On 12/08/2019, 16:21, "Nick Howitt" wrote: > > Then you can't start clamd on installation? Run a postinstall scriptlet that calls freshclam as part of the package installer, perhaps? Graeme ___ clamav-users mail

Re: [clamav-users] Yara rules in ClamAV

2019-07-09 Thread Graeme Fowler via clamav-users
> Is there any user document that shows how to load YARA rules in ClamAV ? https://www.clamav.net/documents/using-yara-rules-in-clamav ___ clamav-users mailing list clamav-users@lists.clamav.net https://lists.clamav.net/mailman/listinfo/clamav-users

Re: [clamav-users] Probably something simple but new to ClamAV

2019-06-04 Thread Graeme Fowler via clamav-users
clamconf will show you what you want (with a lot more detail if required): [graeme@whelk ~]$ clamconf -n | egrep 'version.+sigs' bytecode.cld: version 328, sigs: 94, built on Wed Jan 2 14:42:37 2019 daily.cld: version 25469, sigs: 1587497, built on Mon Jun 3 08:59:22 2019 main.cvd:

Re: [clamav-users] clamd using ~1GB memory on Debian Stretch

2019-05-14 Thread Graeme Fowler via clamav-users
clamscan for every message. If you need the immediacy, you need to accept the memory usage (but memory is cheap, right?). If you need the memory, use the slower method. If you're running a mail server that receives one email per day... maybe do that in a di

Re: [clamav-users] Possible FP Doc.Trojan.Agent-6923110-0

2019-04-10 Thread Graeme Fowler via clamav-users
road, but equally it may be entirely based on observed malware - and if we've got genuine files using the same code as malware or the other way round, that leaves us in a bit of a pickle. Graeme From: clamav-users on behalf of Brent Clark via cla

[clamav-users] Possible FP Doc.Trojan.Agent-6923110-0

2019-04-10 Thread Graeme Fowler via clamav-users
. Unfortunately I cannot send the file as it contains some fairly sensitive information :( Graeme -- Graeme Fowler Senior IT Services Specialist / LU Postmaster, Systems Infrastructure, IT Services Loughborough University ___ clamav-users mailing list

Re: [clamav-users] Are signatures for Windows only?

2019-03-27 Thread Graeme Fowler via clamav-users
d defence-in-depth approach, but without it we'd have a significant gap. Graeme ___ clamav-users mailing list clamav-users@lists.clamav.net https://lists.clamav.net/mailman/listinfo/clamav-users Help us build a comprehensive ClamAV guide: ht

Re: [clamav-users] Are signatures for Windows only?

2019-03-26 Thread Graeme Fowler via clamav-users
Have emailed you off-list. Graeme From: Joel Esler (jesler) Sent: 25 March 2019 22:08 To: ClamAV users ML Cc: Graeme Fowler Subject: Re: [clamav-users] Are signatures for Windows only? That’s super interesting. I’d be interested in what the 6500

Re: [clamav-users] Are signatures for Windows only?

2019-03-25 Thread Graeme Fowler via clamav-users
. Picking a random recent day, we had 135000 rejections, 6500 of which were from ClamAV. By comparison, we accepted & delivered 25000 messages to 66000 recipients (non-unique). I know we're not unique in this regard, and I'm thankful ClamAV exists for many r

Re: [clamav-users] About clamav's requirements for system resources

2018-11-05 Thread Graeme Fowler
eb form on one of our websites; the form sent several hundred thousand messages via one of the MTA servers which got a touch upset. We never did work out why. Is that helpful in any way? Graeme From: clamav-users on behalf of "Micah Snyder (micasnyd)" Reply-To: ClamAV users ML D

Re: [Clamav-users] Missing Freshclam after upgrade to clamav-0.90.3-1.fc7

2007-09-16 Thread Graeme Nichols
Hi Bill, On 17/09/2007, Bill Randle <[EMAIL PROTECTED]> wrote: > > On Mon, 2007-09-17 at 12:42 +1000, Graeme Nichols wrote: > > Hello Bill, > > > > On 17/09/2007, Bill Randle <[EMAIL PROTECTED]> wrote: > > > > > > On Sun, 2007-09-16 at 20:4

Re: [Clamav-users] Missing Freshclam after upgrade to clamav-0.90.3-1.fc7

2007-09-16 Thread Graeme Nichols
Hello Bill, On 17/09/2007, Bill Randle <[EMAIL PROTECTED]> wrote: > > On Sun, 2007-09-16 at 20:42 -0400, Daniel Staal wrote: > > --As of September 17, 2007 10:22:35 AM +1000, Graeme Nichols is alleged > to > > have said: > > > > > 1. The package I used to

Re: [Clamav-users] Missing Freshclam after upgrade to clamav-0.90.3-1.fc7

2007-09-16 Thread Graeme Nichols
package as clamav. I have installed AVG for Linux for the present until the clamav problem is sorted. Simple package installation and setup. For my system it works extremely well. Thanks to everyone who has responded. Your views are appreciated and respected, Regards, Graeme. On 16/09/2007, G.W

Re: [Clamav-users] Missing Freshclam after upgrade to clamav-0.90.3-1.fc7

2007-09-15 Thread Graeme Nichols
Hello Dennis, Thank you. On 16/09/2007, Dennis Peterson <[EMAIL PROTECTED]> wrote: > > Graeme Nichols wrote: > > Hi Dennis, > > > > On 15/09/2007, Dennis Peterson <[EMAIL PROTECTED]> wrote: > >> John Rudd wrote: > >>> Graeme Nichols wro

Re: [Clamav-users] Missing Freshclam after upgrade to clamav-0.90.3-1.fc7

2007-09-14 Thread Graeme Nichols
Hi Dennis, On 15/09/2007, Dennis Peterson <[EMAIL PROTECTED]> wrote: > > John Rudd wrote: > > Graeme Nichols wrote: > > > >> Anyone any ideas please? > > > > Build and install from source? > > Works every time it's tried as the rpm

Re: [Clamav-users] Missing Freshclam after upgrade to clamav-0.90.3-1.fc7

2007-09-14 Thread Graeme Nichols
Hi Giorgio, On 14/09/2007, Giorgio Bellussi <[EMAIL PROTECTED]> wrote: > > Graeme Nichols wrote: > > Hello Dennis, > > > > I have already done that. There is *no* freshclam on my system I'm > afraid. > > > > See the following: > > > >

Re: [Clamav-users] Missing Freshclam after upgrade to clamav-0.90.3-1.fc7

2007-09-14 Thread Graeme Nichols
Hi Fajar, On 14/09/2007, Fajar A. Nugraha <[EMAIL PROTECTED]> wrote: > > Graeme Nichols wrote: > > Hello Dennis, > > > > I have already done that. There is *no* freshclam on my system I'm > afraid. > > > > > > > The clamav-0.90.3-1.fc7

Re: [Clamav-users] Missing Freshclam after upgrade to clamav-0.90.3-1.fc7

2007-09-13 Thread Graeme Nichols
alled OK according to the above. Anyone any ideas please? On 14/09/2007, Dennis Peterson <[EMAIL PROTECTED]> wrote: > > Graeme Nichols wrote: > > Hello, > > > > I upgraded to the above version of clamav (yum update clamav) which went > > well and without error an

[Clamav-users] Missing Freshclam after upgrade to clamav-0.90.3-1.fc7

2007-09-13 Thread Graeme Nichols
ocate it either. Was there and worked just fine *before* I upgraded. Am I missing something very basic? Ta. -- Kind Regards, Graeme. ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://lurker.clamav.net/list/clamav-users.html

Re: [Clamav-users] problem after upgrading clamav

2007-09-01 Thread Graeme Nichols
ic 100% |=| 951 B00:00 Could not find update match for clamav-update No Packages marked for Update/Obsoletion Anything else I should try? Ta, Graeme. On 01/09/07, Pavel Urban <[EMAIL PROTECTED]> wrote: > > Graeme Nichols wrote: > > Hello Folks, > > >

[Clamav-users] problem after upgrading clamav

2007-08-31 Thread Graeme Nichols
rs to have disappeared. Doing a search (find / -name freshclam) results in nothing found. What do people think has happened? No funnies please. This is serious. -- Kind Regards, Graeme. ___ Help us build a comprehensive ClamAV guide: visit http://wiki.

Re: [Clamav-users] Upgrade from version: 0.88.7 to version: 0.91.1 on FC6 error.

2007-08-14 Thread Graeme Nichols
Hello Andrew, The errors you are getting mean that you can't upgrade because some installed items are needed by your existing version of calmav. Uninstall your existing version of clamav and then install the new version. It has worked for me before. Cheers, Graeme.

Re: [Clamav-users] Error when starting clamd at boot time

2007-06-25 Thread Graeme Nichols
On 25/06/07, René Berber <[EMAIL PROTECTED]> wrote: > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Graeme Nichols wrote: > > > I have begun to get the following error when starting clamd at boot > time. > > > > ERROR: > > > > P

Re: [Clamav-users] Error when starting clamd at boot time

2007-06-25 Thread Graeme Nichols
On 25/06/07, René Berber <[EMAIL PROTECTED]> wrote: > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Graeme Nichols wrote: > > > I have begun to get the following error when starting clamd at boot > time. > > > > ERROR: > > > > P

[Clamav-users] Error when starting clamd at boot time

2007-06-24 Thread Graeme Nichols
was not being updated automatically) so I used the GUI to set it to start at boot time and now I get the above error. However, if I then run freshclam I am told that the definition file is up to date. My system is FC6 recently upgraded from FC4 Any ideas anyone? -- Kind Regards, Graeme

[Clamav-users] Errors with freshclam

2007-02-28 Thread Graeme Nichols
ified: Can't connect to clamd through /var/run/clamav/clamd.socket connect(): No such file or directory [EMAIL PROTECTED] disk]# Kind regards, Graeme. ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://lurker.clamav.net/list/clamav-users.html

Re: [Clamav-users] ClamAV 0.90 rpm for Fedora core 2

2007-02-26 Thread Graeme Nichols
command: rpmbuild --rebuild clamav-0.90-3.rf.src.rpm Apologies for my earlier incorrect reply. -- -- Kind regards, Graeme. -- Download my GnuPG public key from

Re: [Clamav-users] ClamAV 0.90 rpm for Fedora core 2

2007-02-26 Thread Graeme Nichols
, Graeme. -- Download my GnuPG public key from:- http://www.users.tpg.com.au/gnichols/graemenichols.pub -- Wisdom is knowing what to do with what you know

Re: [Clamav-users] Problem with clamd.conf

2007-02-22 Thread Graeme Nichols
Gary V wrote: ERROR: Parse error at line 44: Option AllowSupplementaryGroups requires boolean argument. Kind regards, Graeme. man clamd.conf man freshclam.conf Gary V Hello Gary, Thank you. I managed to get it working *after* I realised there were two .conf files involved. I hang my

Re: [Clamav-users] Problem with clamd.conf

2007-02-21 Thread Graeme Nichols
SM wrote: At 17:04 21-02-2007, Graeme Nichols wrote: I suddenly started having the following problem today. The error message is pretty explicit but freshclam is being picky with my 'fix' The initial error follows: [EMAIL PROTECTED] etc]# freshclam ERROR: Parse error at line

Re: [Clamav-users] Problem with clamd.conf

2007-02-21 Thread Graeme Nichols
Steve Holdoway wrote: On Thu, 22 Feb 2007 12:04:37 +1100 Graeme Nichols <[EMAIL PROTECTED]> wrote: I then uncommented the AllowSupplementaryGroups line and added '=1' to the end and got the following error: try true (: Steve Hello

[Clamav-users] Problem with clamd.conf

2007-02-21 Thread Graeme Nichols
=1' to ' 1' it again runs, sort of, but still complains about the option needing a boolean argument. Can someone tell me what the format for that argument is supposed to be please? My clamd.conf file is attached if that helps. Ta. -- ----

Re: [Clamav-users] Creation of binary .rpm package.

2007-02-20 Thread Graeme Nichols
Eric Hoeve wrote: Graeme Nichols wrote: Hello, I tried to create a binary .rpm package from the clamav-0.90.tar.gz tarball using the command 'rpmbuild -tb clamav-0.90.tar.gz' which failed with the following errors: [EMAIL PROTECTED] download]# rpmbuild -tb clamav-0.90.tar.gz error:

Re: [Clamav-users] Creation of binary .rpm package.

2007-02-20 Thread Graeme Nichols
Lorenzo Ortega wrote: hello try to download some rpm from: http://dag.wieers.com/rpm/packages/clamav/ bests Hello Lorenzo, thank you very much for that information. I'll go look. Regards, Graeme. Graeme Nichols escribió: Bill Randle wrote: On Tue, 2007-02-20 at

Re: [Clamav-users] Creation of binary .rpm package.

2007-02-19 Thread Graeme Nichols
Bill Randle wrote: On Tue, 2007-02-20 at 13:44 +1100, Graeme Nichols wrote: Bill Randle wrote: On Tue, 2007-02-20 at 12:58 +1100, Graeme Nichols wrote: Hello, I tried to create a binary .rpm package from the clamav-0.90.tar.gz tarball using the command 'rpmbuild -tb clamav-0.90.t

Re: [Clamav-users] Creation of binary .rpm package.

2007-02-19 Thread Graeme Nichols
Bill Randle wrote: On Tue, 2007-02-20 at 12:58 +1100, Graeme Nichols wrote: Hello, I tried to create a binary .rpm package from the clamav-0.90.tar.gz tarball using the command 'rpmbuild -tb clamav-0.90.tar.gz' which failed with the following errors: Is there a .spec file ava

[Clamav-users] Creation of binary .rpm package.

2007-02-19 Thread Graeme Nichols
-------- Kind regards, Graeme. -- Download my GnuPG public key from:- http://www.users.tpg.com.au/gnichols/graemenichols.pub -- Two men came before Nasrudin whe

[Clamav-users] Error: Cannot open/read repomd.xml file for repository: crash-hat

2007-02-17 Thread Graeme Nichols
at/. '5' is the highest directory. When will '6' be added so I can update ClamAv?? Thanks. -- ------ Kind regards, Graeme. -- Downl

Re: [Clamav-users] malware acl condition: clamd: connection to, 127.0.0.1, port 3310 failed (Bad file descriptor)

2004-10-19 Thread Graeme
Odhiambo Washington said: > * Graeme <[EMAIL PROTECTED]> [20041019 19:18]: wrote: >> Just upgraded my FreeBSD 4.10 to exim 4.43 exiscan patch 28 and clamav >> 0.80 using ports. >> >> I mow get the error >> >> malware acl condition: clamd: connection

[Clamav-users] malware acl condition: clamd: connection to, 127.0.0.1, port 3310 failed (Bad file descriptor)

2004-10-19 Thread Graeme
Just upgraded my FreeBSD 4.10 to exim 4.43 exiscan patch 28 and clamav 0.80 using ports. I mow get the error malware acl condition: clamd: connection to, 127.0.0.1, port 3310 failed (Bad file descriptor) Any help would be appreciated Thanks Graeme