Re: [clamav-users] the problem of endless loop

2016-12-20 Thread Joel Esler (jesler)
The 0.97.x tree is EOL: http://blog.clamav.net/2016/05/clamav-097-engine-end-of-life.html I recommend upgrading to a newer version. -- Joel Esler | Talos: Manager | jes...@cisco.com On Dec 19, 2016, at 6:56 PM, Tsutomu Oyamada mailto:oyam...@promark-inc.com>> wro

Re: [clamav-users] No notice of OLE2.ContainsMacros

2016-12-20 Thread G.W. Haywood
Hi there, On Tue, 20 Dec 2016, Mark Foley wrote: ... running clamscan --block-macros=yes does find the "ContainsMacros" notice. ... (if I specify --block-macros=yes, apparently the settings in /usr/local/etc/clamd.conf aren't used). Check the documentation. The settings in clamd.conf are fo

Re: [clamav-users] the problem of endless loop

2016-12-20 Thread G.W. Haywood
Hi there, On Tue, 20 Dec 2016, Joel Esler wrote: The 0.97.x tree is EOL: http://blog.clamav.net/2016/05/clamav-097-engine-end-of-life.html I recommend upgrading to a newer version. I think the OP was suggesting that one of his two bugs (an endless loop) might still be present in the latest

Re: [clamav-users] No notice of OLE2.ContainsMacros

2016-12-20 Thread Mark Foley
On Tue, 20 Dec 2016 17:26:10 "G.W. Haywood" wrote: > To: clamav-users@lists.clamav.net > Subject: Re: [clamav-users] No notice of OLE2.ContainsMacros > > On Tue, 20 Dec 2016, Mark Foley wrote: > > > ... running clamscan --block-macros=yes does find the > > "ContainsMacros" notice. ... (if I specif

Re: [clamav-users] No notice of OLE2.ContainsMacros

2016-12-20 Thread Reindl Harald
Am 21.12.2016 um 01:32 schrieb Mark Foley: I did not know about clamdscan! Thanks for that info. I've replaced clamscan with clamdscan in my script for 2 reasons: First, while clamscan with the --block-macros=yes switch did work for .doc[x|m] quarantined messaged, it found macro enabled .xls fi

[clamav-users] Win.Trojan.URLspoof-2 signtuare and WARC files

2016-12-20 Thread Christopher Marczewski
Hello Jay, Al is correct. Signature drop requests can come in the form of an FP submission . Signature submissions or suggestions for modifications should be sent to our community-sigs mailing list.