Re: [clamav-users] In ClamAV database: What is .ndu, .mdu ?

2013-03-08 Thread Kaushik Vaidyanathan
Thank you Tom and Al. On Fri, Mar 8, 2013 at 3:36 PM, Tom Judge wrote: > On 3/8/13 5:22 PM, Al Varnell wrote: > > On 3/8/13 1:37 PM, "Kaushik Vaidyanathan" wrote: > > > >> Can someone throw some light on what *.mdu or .ndu* files? > >> > > m

[clamav-users] In ClamAV database: What is .ndu, .mdu ?

2013-03-08 Thread Kaushik Vaidyanathan
Hi Can someone throw some light on what *.mdu or .ndu* files? Thank you.. ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [clamav-users] AC/BM signatures in debug mode

2013-02-25 Thread Kaushik Vaidyanathan
Makes sense. Thanks Dave On Mon, Feb 25, 2013 at 5:00 PM, Al Varnell wrote: > On 2/25/13 4:01 PM, "David Raynor" wrote: > > > On Mon, Feb 25, 2013 at 4:47 PM, Kaushik Vaidyanathan < > > kvaid...@andrew.cmu.edu> wrote: > > > >> Hi > >&

[clamav-users] AC/BM signatures in debug mode

2013-02-25 Thread Kaushik Vaidyanathan
Hi I have a basic question. When I run clamscan with --debug option I see that #AC sigs and #BM sigs reported for the different engines clamscan spawns. If I add the AC and BM for all engines its somewhere around 110K-120K signatures, However I see the sigtool info report for main.cvd and daily.c

Re: [clamav-users] Does Filesize(HDB) or PESectionSize(MDB) of executables play any role in virus pattern matching?

2013-02-14 Thread Kaushik Vaidyanathan
Hi Alain Thanks Alain. Is the "FileSize" or "PESectionSize" used as a pre-processing(or filtering) step while scanning files? What I mean is does ClamAV use the size of the file to filter out all virus patterns that dont have the same filesize as that of the file under inspection? After finding

[clamav-users] Does Filesize(HDB) or PESectionSize(MDB) of executables play any role in virus pattern matching?

2013-02-13 Thread Kaushik Vaidyanathan
Hi Do the FileSize field in a HDB signature serve any purpose during pattern matching, or pattern matching relies only on the MD5 checksum? Similarly for the MDB signature whats the role of PESectionSize in pattern matching? Does PESectionSize get used while filtering and/or preprocessing during

Re: [clamav-users] Is there a way to download old clamAV cvd file from 2007, 2009, 2011 etc.?

2013-02-05 Thread Kaushik Vaidyanathan
onsistent.. On Mon, Feb 4, 2013 at 12:26 PM, Shawn Webb wrote: > On Mon, Feb 4, 2013 at 1:52 PM, Kaushik Vaidyanathan < > kvaid...@andrew.cmu.edu> wrote: > > > Hi > > > > I was wondering if there is a way to access clamAV databases (main.cvd > and > >

[clamav-users] Is there a way to download old clamAV cvd file from 2007, 2009, 2011 etc.?

2013-02-04 Thread Kaushik Vaidyanathan
Hi I was wondering if there is a way to access clamAV databases (main.cvd and daily.cvd) which were released in 2007, 2009 etc.. Thank you! ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [clamav-users] CVD database

2013-01-28 Thread Kaushik Vaidyanathan
Thanks Al. That helps a lot in understanding what each .cvd file is and how it gets used. On Mon, Jan 28, 2013 at 11:53 AM, Al Varnell wrote: > On 1/28/13 10:41 AM, "Kaushik Vaidyanathan" wrote: > > > Hi > > > > Can someone help me understand what each cv

[clamav-users] CVD database

2013-01-28 Thread Kaushik Vaidyanathan
Hi Can someone help me understand what each cvd file(main, daily, safebrowsing and bytecode) capture? I am interested in understanding how the signature counts have been increasing over the years. How can I go about coming up with the total number of signatures clamav would use during its scan? t

Re: [clamav-users] Question on clamAV signatures

2013-01-23 Thread Kaushik Vaidyanathan
xpressions(ldb, ndb). thanks a lot! -Kaushik On Wed, Jan 23, 2013 at 7:03 PM, David Raynor wrote: > On Wed, Jan 23, 2013 at 9:56 PM, Al Varnell wrote: > > > On 1/23/13 5:52 PM, "Kaushik Vaidyanathan" wrote: > > > > > I had a couple of basic questions:

[clamav-users] Question on clamAV signatures

2013-01-23 Thread Kaushik Vaidyanathan
Hi I had a couple of basic questions: a) Of the different signature formats in the cvd file(like mdb, ldb, ndb) which format does clamav use? Does it pick a format(ldb, mdb, ndb etc.) depending on the nature of the file under inspection? b) I guess ldb files are tough to create automatically. If