[clamav-users] how to avoid false positive in clamAV

2017-04-05 Thread Gaurav Kumar Garg
Hi ClamAV user, developer, I am new to clamAV. I like its design. While scanning i saw few false positive virus. I search on internet and found out that i can avoid these false positive by writing md5 sum to local.ign file and putting this file in /var/lib/clamav/* directory. then restarting

Re: [clamav-users] how to avoid false positive in clamAV

2017-04-05 Thread Mark Allan
To whitelist specific files this way, you need to add the m5sum to a file with the .fp extension. So, in your example, it should be sigtool --md5 my_file_name.exe >> local.fp If you want to ignore the signature altogether, you add the signature name to a file with the extension ign2. For wha

Re: [clamav-users] how to avoid false positive in clamAV

2017-04-05 Thread Al Varnell
Not sure where on the internet you found these instructions, but I believe they are old. The new way is to use the ".ign2" extension containing for signatures to be completely ignored and an ".fp" file with :: for individual files to be ignored so that the signature will still pick up any actu

Re: [clamav-users] freshclam exit codes

2017-04-05 Thread Benny Pedersen
I get Access denied, can login OK, but cant see any problems at all, is there a point with open source on closed bugzillas? ___ clamav-users mailing list clamav-users@lists.clamav.net http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users Help

Re: [clamav-users] freshclam exit codes

2017-04-05 Thread Andreas Schulze
Am 05.04.2017 um 12:52 schrieb Benny Pedersen: > I get Access denied, can login OK, but cant see any problems at all, is there > a point with open source on closed bugzillas? maybe you've simple to create an account? -- A. Schulze DATEV eG ___ clamav-

Re: [clamav-users] freshclam exit codes

2017-04-05 Thread Benny Pedersen
Already have, it did not help On April 5, 2017 1:25:39 PM Andreas Schulze wrote: Am 05.04.2017 um 12:52 schrieb Benny Pedersen: I get Access denied, can login OK, but cant see any problems at all, is there a point with open source on closed bugzillas? maybe you've simple to create an accou

[clamav-users] clamav antivm.yar malicious_document.yar and errors

2017-04-05 Thread Rejaine Monteiro
Hello, I'm having some errors with these signatures in clamav-0.99.2. Any tips on what it is about or how to solve? LibClamAV Error: yyerror(): /var/lib/clamav/antidebug_antivm.yar line 497 undefined identifier "pe" LibClamAV Error: yyerror(): /var/lib/clamav/antidebug_antivm.yar line 512 un

Re: [clamav-users] clamav antivm.yar malicious_document.yar and errors

2017-04-05 Thread Steve Basford
On Wed, April 5, 2017 3:24 pm, Rejaine Monteiro wrote: > > Hello, I'm having some errors with these signatures in clamav-0.99.2. > Any tips on what it is about or how to solve? > See here: 3rd Party download script: https://github.com/extremeshok/clamav-unofficial-sigs/issues/151 -- Cheers,

[clamav-users] password protected encrypted .docx files

2017-04-05 Thread Dino Edwards
Any way to get clamav to block password protected Microsoft word files? Thanks ___ clamav-users mailing list clamav-users@lists.clamav.net http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users Help us build a comprehensive ClamAV guide: https

Re: [clamav-users] clamav antivm.yar malicious_document.yar and errors

2017-04-05 Thread Rejaine Monteiro
Hello! I thought there might be some solution other than just disabling Yara. But the project does not seem to be 100% compatible with Clamav yet, then I will follow the instruction and disable it. Thanks. Em 05-04-2017 11:47, Steve Basford escreveu: On Wed, April 5, 2017 3:24 pm, Rejaine

Re: [clamav-users] password protected encrypted .docx files

2017-04-05 Thread Benny Pedersen
Dino Edwards skrev den 2017-04-05 16:48: Any way to get clamav to block password protected Microsoft word files? Yes, it is - you can turn ArchiveBlockEncrypted off in clamd.conf (it's off by default) if not working pastebin your clamconf (clamav section only) _

[clamav-users] Manual cdiff update procedure

2017-04-05 Thread venkat swaminathan
Hello All, I am very new to clamav and trying to understand some update procedure. I\i have daily.cvd and its new cdiff file. is there a procedure document where i will be able follow and update daily.cvd with newly downloaded cdiff files. thanks Venkat.S ___

Re: [clamav-users] password protected encrypted .docx files

2017-04-05 Thread Dino Edwards
Didn't realize the ArchiveblockEncrypted included MS Word files. I thought it would be for password protected zip rar and such -Original Message- From: clamav-users [mailto:clamav-users-boun...@lists.clamav.net] On Behalf Of Benny Pedersen Sent: Wednesday, April 5, 2017 11:22 AM To: clam

Re: [clamav-users] password protected encrypted .docx files

2017-04-05 Thread Reindl Harald
technically .docx *are* zip files Am 05.04.2017 um 21:08 schrieb Dino Edwards: Didn't realize the ArchiveblockEncrypted included MS Word files. I thought it would be for password protected zip rar and such -Original Message- From: clamav-users [mailto:clamav-users-boun...@lists.clamav.