Re: [clamav-users] Odd behavior when scanning eicar test files

2021-04-28 Thread Haukur Valgeirsson via clamav-users
Thanks for the reply :-) I will poke at this a little more and try to be as detailed as I can then file a bugreport. Will add a few inline replies here too. On 27.4.2021 16:09, G.W. Haywood via clamav-users wrote: This seems to be saying you have a clamd.conf, otherwise freshclam wouldn't b

Re: [clamav-users] Odd behavior when scanning eicar test files

2021-04-27 Thread Haukur Valgeirsson via clamav-users
est regards, Haukur On 27.4.2021 09:54, Haukur Valgeirsson via clamav-users wrote: Hi again. Now I am getting really confused. I repeated the tests but now scanning the eicar files in different directories in the same scan. I compiled the file list into a file that I read into an array in bash

Re: [clamav-users] Odd behavior when scanning eicar test files

2021-04-27 Thread Haukur Valgeirsson via clamav-users
appreciated! Best regards, Haukur On 26.4.2021 15:30, Haukur Valgeirsson via clamav-users wrote: Uhm... now this is strange. When I run the script I wrote, it behaves as one would expect (md5 sum must match the file, md5 from eicar.com covers eicar.com.txt too, but not the zips and the md5

Re: [clamav-users] Odd behavior when scanning eicar test files

2021-04-26 Thread Haukur Valgeirsson via clamav-users
, Haukur Valgeirsson via clamav-users wrote: Sorry, adding more details for reproducability. My original idea was to use maldet, which uses clamscan so whitelisting and path exclusions need to happen in clamav, they don't seem to be passed on to clamscan. Environment: 4.19.0-10-amd64 #1 SMP D

Re: [clamav-users] Odd behavior when scanning eicar test files

2021-04-26 Thread Haukur Valgeirsson via clamav-users
ase 24 times a day Checks 24 DatabaseMirror db.local.clamav.net DatabaseMirror database.clamav.net On 26.4.2021 13:42, G.W. Haywood via clamav-users wrote: Hi there, On Mon, 26 Apr 2021, Haukur Valgeirsson via clamav-users wrote: I am setting up daily scanning and was figuring out how to

[clamav-users] Odd behavior when scanning eicar test files

2021-04-26 Thread Haukur Valgeirsson via clamav-users
Hi. I am setting up daily scanning and was figuring out how to whitelist based on file signatures, and decided to use the eicar test files to tune the settings.  Used 'sigtool --md5 eicarcom2.zip > falsepossigs.fp' to create the sig to whitelist and proceeded to run test scans and the results