Re: [Clamav-users] How to mirror the signatures?

2008-12-04 Thread Török Edwin
On 2008-12-04 03:34, Michelle Konzack wrote: > > * Do not Cc: me, because I READ THIS LIST, if I write here * > *Keine Cc: am mich, ich LESE DIESE LISTE wenn ich hier schreibe* > ***

Re: [Clamav-users] clamstats

2008-12-04 Thread Török Edwin
On 2008-12-04 05:49, Chris wrote: > I'm a bit confused. Looking at my clamstats for 30 Nov I see: > > Last Database UpdateSun Nov 30 23:32:57 2008 > > Total viruses detected 407 > Total Database Signatures 469,236 >

Re: [Clamav-users] How to mirror the signatures?

2008-12-04 Thread Michelle Konzack
Hello Edwin, Am 2008-12-04 11:04:28, schrieb Török Edwin: > Hi, > > First of all make sure you are using the volatile repository for Debian, > which has up to date packages that support incremental updates. > (in other words, avoid using 0.90, it can't cope with the amount of > signatures we have

Re: [Clamav-users] Hardware acceleration for virus scanning

2008-12-04 Thread aCaB
Babu.N wrote: > Hi, > > I remember that clamAV once supported Sensory networks' Nodal core > acceleration. But I don't find this support in the source code > (clamav-0.94.2) I have downloaded today. > > Does ClamAV support hardware acceleration for virus scanning ? Please clarify. Hi Babu.N I

[Clamav-users] Mabezat virus

2008-12-04 Thread Zvi Kave
Hi all, I saw that Mabezat viruses are in virus DB, but for some reason it is not detected. Someone knows why?? Zvi ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] Mabezat virus not detected

2008-12-04 Thread Zvi Kave
_ > Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net > http://www.clamav.net/support/ml > > __ Information from ESET NOD32 Antivirus, version of virus > signature database 3664 (20081204) __ > > The message

Re: [Clamav-users] Mabezat virus not detected

2008-12-04 Thread McDonald, Dan
On Thu, 2008-12-04 at 18:37 +0200, Zvi Kave wrote: > I forgot to specify that it is ClamAV 0.94.2 in Fedora 8. > sigtool -l shows this: > # sigtool -v -l | grep -i mabezat > W32.Mabezat-1 > W32.Mabezat-2 > W32.Mabezat > W32.Mabezat-3 > > NODE32 detects it from Windows as W32/Mabezat.A Have you su

[Clamav-users] Twitter

2008-12-04 Thread Nigel Horne
Folks, We'd like to hear any feedback people have who are following our Twitter channel at http://twitter.com/clamav. If you're finding these updates useful please let us know. Also let us know if there is anything else that you'd like us to put on that channel. Best Regards, -Nigel Horne ___

Re: [Clamav-users] Twitter

2008-12-04 Thread Julio Canto
Nigel Horne escribió: > Folks, > > We'd like to hear any feedback people have who are following our Twitter > channel at http://twitter.com/clamav. > > If you're finding these updates useful please let us know. Also let us > know if there is anything else that you'd like us to put on that chann

Re: [Clamav-users] Twitter

2008-12-04 Thread McDonald, Dan
On Thu, 2008-12-04 at 12:45 -0500, Nigel Horne wrote: > Folks, > > We'd like to hear any feedback people have who are following our Twitter > channel at http://twitter.com/clamav. the RSS feed from twitter truncates it much shorted, and you have a lot of repeated characters, so it's not as usefu

Re: [Clamav-users] Twitter

2008-12-04 Thread Henrik K
On Thu, Dec 04, 2008 at 12:45:51PM -0500, Nigel Horne wrote: > Folks, > > We'd like to hear any feedback people have who are following our Twitter > channel at http://twitter.com/clamav. > > If you're finding these updates useful please let us know. Also let us > know if there is anything else

Re: [Clamav-users] Twitter

2008-12-04 Thread David F. Skoll
Henrik K wrote: > I can't help thinking that ClamAV staff might have something better to do > than set up such things. Ok, atleast 76 people use it.. I agree... and posting daily CVD updates seems silly, given that the information is available via DNS anyway. "host -t txt current.cvd.clamav.net"

Re: [Clamav-users] Twitter

2008-12-04 Thread James Kosin
McDonald, Dan wrote: > On Thu, 2008-12-04 at 12:45 -0500, Nigel Horne wrote: >> Folks, >> > > how about: > Daily CVD 8721 (sigs: 32788, new: 1) at 04 Dec 2008 13-26 + > The proper phrasing is "on" and not "at" James signature.asc Description: OpenPGP digital signature ___

Re: [Clamav-users] Twitter

2008-12-04 Thread Kelson
I checked out the Twitter feed when it was announced. I didn't find it useful, primarily because I don't feel the need to know when each update hits. That's what I use freshclam for. As far as DB updates go, the only notification I need is when freshclam fails, or when an unusually long time

Re: [Clamav-users] Twitter

2008-12-04 Thread Henrik K
On Thu, Dec 04, 2008 at 11:52:56AM -0800, Kelson wrote: > > It doesn't take that long to set up an automatic process that will post > without user intervention, or link an RSS feed to the account. It > probably took them less time than it took me to write this email. Sure, I'm just having a ran

Re: [Clamav-users] Twitter

2008-12-04 Thread Spiro Harvey
> We'd like to hear any feedback people have who are following our > Twitter channel at http://twitter.com/clamav. Who is the intended audience? If an admin is not running freshclam out of cron or equivalent scheduler, then they obviously don't care about updates. If they are running it out of cr

[Clamav-users] Where is the list of detected malware?

2008-12-04 Thread Derek Currie
Hi folks, This has to be the newbie question of the century for Clamav, but... How can I view the list of malware detectable by Clamav? I'd like to be able to know what new malware it can detect with each definition/ signature update. I've found myself caught in a place where I never know if

Re: [Clamav-users] Where is the list of detected malware?

2008-12-04 Thread Brandon Perry
Check out sigtool. (man sigtool) On Thu, Dec 4, 2008 at 3:05 PM, Derek Currie <[EMAIL PROTECTED]> wrote: > Hi folks, > > This has to be the newbie question of the century for Clamav, but... > > How can I view the list of malware detectable by Clamav? I'd like to > be able to know what new malware

Re: [Clamav-users] Where is the list of detected malware?

2008-12-04 Thread Brandon Perry
You may also upload a sample of the virus to VirusTotal and see what they say. On Thu, Dec 4, 2008 at 4:10 PM, Brandon Perry <[EMAIL PROTECTED]>wrote: > Check out sigtool. (man sigtool) > > > On Thu, Dec 4, 2008 at 3:05 PM, Derek Currie <[EMAIL PROTECTED]> wrote: > >> Hi folks, >> >> This has to

Re: [Clamav-users] Where is the list of detected malware?

2008-12-04 Thread Tomasz Kojm
On Thu, 04 Dec 2008 16:05:07 -0500 Derek Currie <[EMAIL PROTECTED]> wrote: > Hi folks, > > This has to be the newbie question of the century for Clamav, but... > > How can I view the list of malware detectable by Clamav? I'd like to > be able to know what new malware it can detect with each de

Re: [Clamav-users] Where is the list of detected malware?

2008-12-04 Thread Stephen Gran
On Thu, Dec 04, 2008 at 04:05:07PM -0500, Derek Currie said: > Hi folks, > > This has to be the newbie question of the century for Clamav, but... > > How can I view the list of malware detectable by Clamav? I'd like to > be able to know what new malware it can detect with each definition/ > si

Re: [Clamav-users] Where is the list of detected malware?

2008-12-04 Thread Derek Currie
On Dec 4, 2008, at 12/04, 5:13 PM, Tomasz Kojm wrote: > On Thu, 04 Dec 2008 16:05:07 -0500 > Derek Currie <[EMAIL PROTECTED]> wrote: > >> Hi folks, >> >> This has to be the newbie question of the century for Clamav, but... >> >> How can I view the list of malware detectable by Clamav? . . . >> >

Re: [Clamav-users] clamstats

2008-12-04 Thread Chris
On Thursday 04 December 2008 3:00 am, Török Edwin wrote: > On 2008-12-04 05:49, Chris wrote: > > if (/main\.(?:cvd|inc).+\(version:\s(\d+),\ssigs:\s(\d+),/) { > > .inc is no longer used, you should replace that with cld. > > > if (/main\.(?:cld|inc).+\(version:\s(\d+),\ssigs:\s(\d+),/)

Re: [Clamav-users] clamstats

2008-12-04 Thread Chris
On Thursday 04 December 2008 3:00 am, Török Edwin wrote: > > if (/main\.(?:cld|inc).+\(version:\s(\d+),\ssigs:\s(\d+),/) { > > Use 'cvd|cld' and not cld|inc or cvd|inc. > I forgot to ask about this line Edwin: if (/daily\.(?:cld|inc).+\(version:\s(\d+),\ssigs:\s(\d+),/) { Should it be changed al

Re: [Clamav-users] Non-Windows Malware

2008-12-04 Thread Derek Currie
Greetings folks, This is a reply to a thread started way back in April of 2008 (when it used to have the unfortunate subject line "Non-Windoze Viruses"). Concerning the controversy about whether Clamav has definitions for Mac OS X malware, I managed to find the answer is YES, but only sort of

Re: [Clamav-users] Non-Windows Malware

2008-12-04 Thread Spiro Harvey
> What then is the benefit of Clamav on the Mac platform? same reason why it's on Linux.. to protect windows users. It's my experience that malware and virus scares for Macs are bogus. I work for an ISP and we have ClamAV and the sendmail milter running to scan all incoming and outgoing emails

Re: [Clamav-users] Non-Windows Malware

2008-12-04 Thread Dennis Peterson
Spiro Harvey wrote: > > No doubt some people run mail servers on OS-X that are delivering mail > to windows users, so it is possible for those people to run clam. I used to build very nice headless Mac Mini mail MTA's for rapid deployment at corporate acquisitions. They work very well running

Re: [Clamav-users] clamstats

2008-12-04 Thread Török Edwin
On 2008-12-05 03:19, Chris wrote: > On Thursday 04 December 2008 3:00 am, Török Edwin wrote: > > >>> if (/main\.(?:cld|inc).+\(version:\s(\d+),\ssigs:\s(\d+),/) { >>> >> Use 'cvd|cld' and not cld|inc or cvd|inc. >> >> > I forgot to ask about this line Edwin: > > if (/daily\.(?:cld|in