Re: [clamav-users] Question About MaxFileSize

2023-05-24 Thread Andrew C Aitchison via clamav-users
On Wed, 24 May 2023, Tachibanaki Nozomi (橘木 希美) wrote: Dear Sir or Madam, Thank you for your help always. I am contacting you to ask about MaxFileSize in clamd.conf. The following description is found in the configuration of /usr/local/etc/clamd.conf. MaxFileSize # Technical design limitation

[clamav-users] clamav-milter exclude files from scanning

2023-05-24 Thread Christian
Hi all, we have a mailserver with clamav-milter and clamd Version 0.103.8+dfsg-0ubuntu0.16.04.1+esm1. There we have a cdb ruleset to block some filetypes: /var/lib/clamav/archive_blocker.cdb withe following content: attach.blockgz2:*:*:\.[Gg][Zz]$:*:*:*:*:*:* Now I want to exclude some file e

Re: [clamav-users] Vbs.Trojan.AsyncRAT-9889434-1

2023-05-24 Thread Christopher Marczewski
Hello Andrew, Please ensure you're using the latest CVDs. Vbs.Trojan.AsyncRAT-9889434-2 was recently published to address some FPs encountered from revision 1 of the signature. On Wed, May 17, 2023 at 4:42 AM Andrew Salway via clamav-users < clamav-users@lists.clamav.net> wrote: > Hello > > > >

Re: [clamav-users] ClamAV 1.0.1

2023-05-24 Thread Paul Netpresto
Hi I have found that 1.0.1 and 0.103.8 both behave badly if they find a malformed db. Agreed freshclam checks out the clamav/cisco db's. I have yet to determine what unofficial db caused the failure. They should all have been verified before being placed in /var/lib/clamav/ Clamd ends up on

Re: [clamav-users] ClamAV 1.0.1

2023-05-24 Thread Alexeyd 1000 via clamav-users
Hello! I believe this is how to contact the customer care. I was wondering whether or not ClamAV has real time protection for your system? And if so, how do I turn it on? I can't find it in my GUI settings and it does not seem to be running either way. Thanks! Alex On Wed, May 24, 2023, 12:00 AM P

Re: [clamav-users] ClamAV 1.0.1

2023-05-24 Thread Steve Basford via clamav-users
On 24 May 2023 18:52:04 Paul Netpresto wrote: Hi I have found that 1.0.1 and 0.103.8 both behave badly if they find a malformed db. Agreed freshclam checks out the clamav/cisco db's. I have yet to determine what unofficial db caused the failure. They should all have been verified before be

Re: [clamav-users] ClamAV 1.0.1

2023-05-24 Thread Steve Basford via clamav-users
On 24 May 2023 18:52:04 Paul Netpresto wrote: Hi I have found that 1.0.1 and 0.103.8 both behave badly if they find a malformed db. Agreed freshclam checks out the clamav/cisco db's. I have yet to determine what unofficial db caused the failure. They should all have been verified before be

Re: [clamav-users] ClamAV 1.0.1

2023-05-24 Thread Paul Netpresto
Hi Steve Note it would be nice if clamd said which db it did not like .. I reckon the start of the problem is "Database reload failed, keeping the previous instance" when there is no previous instance. Mon May 22 13:04:40 2023 -> Reading databases from /var/lib/clamav/ Mon May 22 13:05:01 202

Re: [clamav-users] ClamAV 1.0.1

2023-05-24 Thread Steve Basford via clamav-users
Could you do a ls of the clamav database folder... So I can see what databases you are using Does the database name appear in the logs when clamd.con # Enable verbose logging. # Default: no LogVerbose yes If you run clamscan -- database=clamav database folder test.file does it report database

Re: [clamav-users] ClamAV 1.0.1

2023-05-24 Thread Steve Basford via clamav-users
On 24 May 2023 21:57:33 Steve Basford via clamav-users wrote: Could you do a ls of the clamav database folder... So I can see what databases you are using Sorry all should have been of list... Duh ;) Cheers, Steve Twitter: @sanesecurity ___ Manage

Re: [clamav-users] ClamAV 1.0.1

2023-05-24 Thread Paul Netpresto
Hi Steve I am sure I can get to the bottom of how/what db was malformed. I am more concerned on how clamd behaves when reloading db's hits an issue and there is no previous  DB instance  available. I am 99% sure clamd simply terminated prior to multi instance DB images being introduced . Now