[clamav-users] Clamd logging dictionary to aid integration with SIEM application

2015-09-17 Thread Chris Needham2
r our SIEM application. Any help would be greatly appreciated! Cheers, Chris N Unless stated otherwise above: IBM United Kingdom Limited - Registered in England and Wales with number 741598. Registered office: PO Box 41, North Harbour, Portsmouth, Hampshi

[clamav-users] Settings for apparmor on ubuntu

2016-08-14 Thread Wastchak, Chris
familiar with apparmor). Thanks in advance, Chris The information contained in this message may be confidential and legally protected under applicable law. The message is intended solely for the addressee(s). If you are not the intended recipient, you are hereby

[clamav-users] Install from source on Ubuntu 8.04 Hardy

2016-10-25 Thread Chris Nelson
OS Ubuntu 8.04.3 Hardy - installed ClamAV 0.99.2 yesterday, and can't seem to get the daemon / clamd to function. Installed in /usr/local/sbin - previously had 0.97 and earlier but had the mpool_malloc() loop issue so had to torch it. Here's what I get now when loading rc.local @boot: ---clip

Re: [clamav-users] Daily 23161 broke Clam

2017-03-03 Thread Chris Conn
, php and httpd among others. Hope this helps, Chris On 3/3/2017 3:14 PM, Steven Morgan wrote: Hi Aaron and Leonardo, What are the versions of libpcre on your systems? Thanks, Steve ___ clamav-users mailing list clamav-users@lists.clamav.net

Re: [clamav-users] Daily 23161 broke Clam

2017-03-03 Thread Chris Conn
RHEL5 (or CentOS5...) their clamd is now broken due to a package from the base repository being older than what that particular signature requires. RHEL5 is not EOL for another 30 days :) Chris On 3/3/2017 3:33 PM, Leonardo Rodrigues wrote: Em 03/03/17 17:31, Chris Conn escreveu: Updating the

Re: [clamav-users] Daily 23161 broke Clam

2017-03-03 Thread Chris Conn
Hello, I hope you don't mind my contact off-list, I don't want to make noise on it for all. Apologies. This new build, are we talking about a daily.cvd (23162?) or a new build of clam/pcre? Thanks again in advance for your help, Chris On 3/3/2017 4:00 PM, Alain Zidouemba wrot

Re: [clamav-users] Daily 23161 broke Clam

2017-03-03 Thread Chris Conn
the future, or would it simply disable pcre support in previous version of clamd that have not been upgraded? Thanks, Chris On 3/3/2017 6:13 PM, Joel Esler (jesler) wrote: A new daily with the Sig dropped. Probably what we will do to prevent this from happening again, is to have 0.99.3 (the

Re: [clamav-users] Daily 23161 broke Clam

2017-03-03 Thread Chris Conn
;extended life phase" that RHEL5 systems can obtain, so the April 1st date is not necessarily accurate). Your favorite distro probably handles this versioning better than RH does. Chris On 3/3/2017 6:53 PM, Scott Kitterman wrote: As far as I can tell, pcre 7 came out before 2008. I think a

[clamav-users] Freshclam memory use

2017-05-25 Thread Chris Coleman
Hello ClamAV mailing list, On Debian Jessie 8, 32 bit, 256MB ram, 14MB in use. Why is |freshclam| so memory hungry that it bombs out with |Failed to load new database|, when there's 242 MB of free RAM available? What can be done to improve the code so the definition updates don't burn through so

[clamav-users] Run script on file scanned but no virus found

2017-11-02 Thread Chris Johnson
there a way of getting clamd to run a script when a virus is not found? Chris Johnson ___ clamav-users mailing list clamav-users@lists.clamav.net http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users Help us build a comprehensive Clam

Re: [clamav-users] Run script on file scanned but no virus found

2017-11-02 Thread Chris Johnson
Because it takes too long to launch. Clamd called from php took about 5 seconds, on access detects the file in under .05seconds Chris Johnson On 2 November 2017 at 15:34, Reindl Harald wrote: > > > Am 02.11.2017 um 16:28 schrieb Chris Johnson: >> >> PHP checks for the e

Re: [clamav-users] Run script on file scanned but no virus found

2017-11-03 Thread Chris Johnson
OK, so I've not used sockets before but with a little tweaking and a lot of googling I've got it working and it appears to work really well. Thank you Off to integrate it into the code now, or to tell someone else to do it for me ;-) Chris Johnson On 2 November 2017 at 19:42, K

Re: [Clamav-users] PDF-9669 False Positives?

2010-01-08 Thread Chris Hardie
ation and fix, someone is supposed to be calling me back shortly. Chris -- http://www.chrishardie.com/ ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] The EOL tweets

2010-04-16 Thread Chris Meadors
I was told to download the new update. Clamav on a server has no GUI, it method of informing the user is it's log file. Anyone running 0.94 has been warned for over two years that they're out of date. Today that warning became a requirement. -- Chris _

Re: [Clamav-users] The EOL tweets

2010-04-16 Thread Chris Meadors
sn't handle the type of signature which they plan to use in the future. 0.95 just ignores this new signature, as it will do with the actual malware signatures which will be coming soon. -- Chris ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] The EOL tweets

2010-04-16 Thread Chris Meadors
malformatted hexstring error. -- Chris ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] The EOL tweets

2010-04-16 Thread Chris Meadors
oviding updates for the heavily used 0.95, even if changes were made for 0.96. -- Chris ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] Lots of "pread fail" warnings during scanning

2010-04-18 Thread Chris Meadors
/sys -- Chris ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] Clubbing a deceased equine

2010-04-21 Thread Chris Meadors
Would this idea help minimise any future issues like this? It was pointed out even before that suggestion was made that 0.95 and later have a versioning system inside the signature DB which allows clam to selectively load only parts of the DB. New incompatible signature types can be created and 0.9

Re: [Clamav-users] (no subject)

2010-04-21 Thread Chris Knight
ers are a little more considerate in how they treat the many 'upgrade orphans' that will always exist. -Chris ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] Yet more clubbing of deceased equine.

2010-04-23 Thread Chris Knight
On Fri, Apr 23, 2010 at 1:39 PM, Christopher X. Candreva wrote: > On Fri, 23 Apr 2010, Simon Hobson wrote: > >> So, it still runs the software it used to run ? Yes >> It's running software that is  EOL ? Most definitely >> And Microsoft have sent it a poison pill ? No they haven't > > And is it hi

Re: [Clamav-users] Yet more clubbing of deceased equine.

2010-04-23 Thread Chris Meadors
On 4/23/2010 8:02 PM, Chris Knight wrote: 1) Release a new version that pulls updates from a new hostname. 2) Wait a couple of weeks, or even six months 3) Shut down old servers, 4. Orphan *all* previous versions, including the still heavily used, and valid, 0.95s which were released

Re: [Clamav-users] Yet more clubbing of deceased equine.

2010-04-23 Thread Chris Knight
On Fri, Apr 23, 2010 at 5:07 PM, Chris Meadors wrote: > On 4/23/2010 8:02 PM, Chris Knight wrote: > >> 1) Release a new version that pulls updates from a new hostname. >> 2) Wait a couple of weeks, or even six months >> 3) Shut down old servers, > > 4.

Re: [Clamav-users] Yet more clubbing of deceased equine.

2010-04-24 Thread Chris Knight
On Sat, Apr 24, 2010 at 6:36 AM, Stephen Gran wrote: > On Fri, Apr 23, 2010 at 05:02:07PM -0700, Chris Knight said: >> On Fri, Apr 23, 2010 at 1:39 PM, Christopher X. Candreva >> wrote: >> > On Fri, 23 Apr 2010, Simon Hobson wrote: >> > >> >> So, it

Re: [Clamav-users] Resources for integrating with spamassassin+amavisd

2010-05-03 Thread Chris Meadors
srupt most every block by changing the start offsets through out the entire file. -- Chris ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

[Clamav-users] how to write a signature skip 0~N spaces between two sub-pattern ?

2010-07-22 Thread Chris Hsiung
I want to write a extended signature to scan a html file just like the RegExp: "<[\s|\r|\n|\t]*script" i dont want use {-n} because i want skip only space chars exactly. but i don't know how to convert "[\s|\r|\n|\t]*" into extended signature format. or this feature is not support ? Sorry for my

Re: [clamav-users] Major new false positive? BC.Exploit.CVE_2012_0184

2012-05-11 Thread Chris Conn
_0165). Anyone else seeing this? Yes, we were talking about this on IRC a short while ago on #clamav. Its been fixed, run freshclam and you are all good. Chris ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clama

[clamav-users] Problems with signature mirrors today?

2012-11-09 Thread Chris Stone
200.236.31.1 (due to previous errors) Ignoring mirror 128.177.8.248 (due to previous errors) Ignoring mirror 209.198.147.20 (due to previous errors) Ignoring mirror 65.19.179.67 (due to previous errors) Problems? Everyone else seeing this as well? Chris ___ Help

Re: [clamav-users] Problems with signature mirrors today?

2012-11-09 Thread Chris Stone
Yes, looks good to me now Thanks! Chris On Fri, Nov 9, 2012 at 11:21 AM, Matt Olney wrote: > Folks, > > We seem to have resolved the issue. Mirrors should be syncing now. Let us > know if you see anything else. > > Matt > > On Fri, Nov 9, 2012 at 12:51 PM

[Clamav-users] Problems with 0.90.1 on Sol9 (sparc)

2007-03-16 Thread Chris Adams
W576310: /tmp/clamav-8f6bff1f5bbae163780ecae88004cefb/msg.Giaiwi: Unable to open file or directory ERROR I do not have --enable-experimental on my configure; I did try it yesterday just to see if it made any difference (it didn't appear to). Any suggestions? -- Chris Adams <[EMAIL PROTECTED]> Systems and Network

[Clamav-users] Install woes

2007-04-17 Thread Chris Burkhart
I tried to install clamav with Automatix under Ubuntu and I keep getting" this error: Setting up clamav-base (0.88.4-1ubuntu2.1) ... X Error: BadDevice, invalid or uninitialized input device 166 Major opcode: 146 Minor opcode: 3 Resource id: 0x0 Failed to open device X Error: BadDevice, invalid o

Re: [Clamav-users] MSRBL-Images file shrinks

2007-04-24 Thread Chris Burton
nounce list: http://lists.8086.net/mailman/listinfo/msrbl-announce Regards, Chris Burton ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://lurker.clamav.net/list/clamav-users.html

[Clamav-users] Downloading updates from AV server

2007-07-10 Thread Chris Arnold
RROR: Can't download daily.cvd from web.electrichendrix.com/AV Trying again in 5 secs... This use to work. I am able to access the server no problems just not the updates. Chris ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://lurker.clamav.net/list/clamav-users.html

Re: [Clamav-users] clamd stuck at 100% cpu usage

2007-09-28 Thread Chris Adams
I have had load problems with clamd running 100% on Solaris 9 (V480, quad UltraSPARC III 900MHz). I moved ClamAV to a Linux (Fedora 7 x86_64 on dual Xeon 2.8GHz) this week, and that system runs ~90% idle (it did get down to 85% idle once). I tried using PCRE on Solaris, but it didn't seem to

Re: [Clamav-users] 0.92 and memory usage

2007-12-19 Thread Chris Blaise
Fabio, We've seen this too. See if my patch helps. https://wwws.clamav.net/bugzilla/show_bug.cgi?id=736 Chris -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Fabio Pedretti Sent: Tuesday, December 18, 2007 10:21 AM To: clamav-

[Clamav-users] Email.Phishing.RB-3083

2008-03-21 Thread Chris Burton
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, I've submitted this as a FP - it looks like someone got a bit excited when adding signatures IMO ;) It matches on http://www.sng.ecs.soton.ac.uk/mailscanner/images/1x1spacer.gif which is the default image MailScanner replaces "Web Bugs" with.

Re: [Clamav-users] Frequency of virus attacks

2008-06-13 Thread Chris Adams
h, I have blocked almost 37 million messages as spam, delivered 1.7 million messages after filtering, and only blocked 1680 messages as viruses. -- Chris Adams <[EMAIL PROTECTED]> Systems and Network Administrator - HiWAAY Internet Services I don't speak for anyb

Re: [Clamav-users] automated response

2008-07-27 Thread Chris Meadors
Christopher Checca wrote: > I will be out of the office until 08-04-2008. > > Christopher Checca > Packard Transport, Inc. > 24021 South Municipal Dr > PO Box 380 > Channahon, IL. 60410 > 815 467 9260 > 815 467 6939 Fax > [EMAIL PROTECTED] > www.packardtransport.com Wonder if he's gone on hol

[clamav-users] ClamAV yum update fails on Amazon AMI ...

2019-01-21 Thread Chris Jobson
-1.30.amzn1.noarch (amzn-updates) group(virusgroup) How do I resolve this? thanks Chris ___ clamav-users mailing list clamav-users@lists.clamav.net http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users Help us build a

Re: [clamav-users] ClamAV yum update fails on Amazon AMI ...

2019-01-23 Thread Chris Jobson
Many thanks - I’ll see if that helps -chris > On 22 Jan 2019, at 17:39, Micah Snyder (micasnyd) wrote: > > Hi Chris, > > I haven't tried using the Amazon Linux packages. If no one else here has > prior ClamAV experience using the Amazon Linux packages, you should be

Re: [clamav-users] Pdf.Exploit.CVE_2019_7057-6900620-0 signature causes error on clamav start

2019-03-21 Thread Chris Conn
Yes the last time this happened was 30 days before Centos5 went EOL.  :)  I recall posting in that thread. Cheers all, Chris ___ clamav-users mailing list clamav-users@lists.clamav.net https://lists.clamav.net/mailman/listinfo/clamav-users He

[clamav-users] clamav-milter and ClamdSocket tcp with multi-host A record

2019-11-13 Thread Chris Conn
instead of spreading the load over multiple servers. In any case, is there another way I should be configuring this, or is this normal/expected behaviour? Thanks in advance, Chris ___ clamav-users mailing list clamav-users@lists.clamav.net https

[clamav-users] EPEL Centos8 clamav maintainer

2019-12-20 Thread Chris Conn
there seems to be no way to start the daemon via systemd.  Maybe I am doing something fundamentally wrong, but under Centos7 it is clearly more intuitive. Thanks in advance, Chris ___ clamav-users mailing list clamav-users@lists.clamav.net

Re: [Clamav-users] whish list ?

2003-11-29 Thread McKeever Chris
ing plugins do have the 'template' formatted message --- Chris McKeever If you want to reply directly to me, please use cgmckeever--at--prupref---dot---com http://www.prupref.com Prudential Preferred Properties www.prupref.com -

Re: [Clamav-users] ClamAV vs Commercial Products

2003-12-01 Thread McKeever Chris
On 01 Dec 2003 14:00 , Joshua French <[EMAIL PROTECTED]> sent: >Hello, > >I am trying to find out the difference(s) between ClamAV's virus db and >any given commercial product. In the latter, I've noted that they have >covered 70-80k viruses, whereas ClamAV has somewhere around 10k in its >defi

Re: [Clamav-users] Oversized Zip, again ...

2003-12-02 Thread McKeever Chris
mav on its own. > >You can now setup the limit with ArchiveMaxCompressionRatio in >clamav.conf. > Tomasz - thanks for the update, is this with the current .65 (downloaded a week ago) or a required patch (CVS, etc) --- Chris McKeever If you want to r

[Clamav-users] missing viruses

2003-12-03 Thread McKeever Chris
one. Any suggestions? Thanks --- Chris McKeever If you want to reply directly to me, please use cgmckeever--at--prupref---dot---com http://www.prupref.com Prudential Preferred Properties www.prupref.com

Re: [Clamav-users] missing viruses

2003-12-03 Thread McKeever Chris
On Wed, 03 Dec 2003 16:21 , Thomas Lamy <[EMAIL PROTECTED]> sent: >McKeever Chris wrote: > >> I am running qmail-scanner with clamav (0.65) >> I have one machine that acts as a gateway, and then sends it to the main email >> server. >> The gateway is the o

[Clamav-users] clamdscan error

2003-12-04 Thread McKeever Chris
ssues? --- Chris McKeever If you want to reply directly to me, please use cgmckeever--at--prupref---dot---com http://www.prupref.com Prudential Preferred Properties www.prupref.com --- This SF.net email is sponsored by

Re: [Clamav-users] clamdscan error

2003-12-04 Thread McKeever Chris
On Thu, 04 Dec 2003 22:13 , Thomas Lamy <[EMAIL PROTECTED]> sent: >McKeever Chris wrote: > >> # clamdscan --version >> clamdscan / ClamAV version 0.65 >> >> >> ]# clamdscan >> connect(): No such file or directory >> ERROR: C

[Clamav-users] what error is this?

2003-12-08 Thread Chris Tan
Dear all, make: don't know how to make ../docs/clamav-milter.8. Stop *** Error code 1 Stop in /root/clamav-0.65. the last time i had errors with clamav-milter was the getopt.h thingy.. now it seems to be this prob that giving me probs .. any work ards &/or whats this prob ?? OS : freebsd 4.9

Re: [Clamav-users] Re: what error is this?

2003-12-08 Thread Chris Tan
le.in Wed Nov 12 16:55:36 2003 >@@ -122,7 +122,7 @@ > @BUILD_CLAMD_TRUE@@[EMAIL PROTECTED] = >../clamd/cfgfile.o ../clamd/others.o ../clamscan/getopt.o >[EMAIL PROTECTED]@@[EMAIL PROTECTED] = ../docs/clamav-milter.8 >[EMAIL PROTECTED]@@[EMAIL PROTECTED] = ../docs/man/clamav-milter.8 >

[Clamav-users] savemail panic ?

2003-12-09 Thread Chris Tan
Dec 9 20:52:26 freebsd sm-mta[83809]: hB9CqONG083809: Milter: data, reject=550 5.7.1 Virus detected by ClamAV - http://clamav.elektrapro.com Dec 9 20:52:26 freebsd sm-mta[83809]: hB9CqONG083809: to=<[EMAIL PROTECTED]>, delay=00:00:01, pri=34995, stat=Virus detected by ClamAV - http://clamav.elekt

[Clamav-users] freshclam exit code

2003-12-10 Thread Chris Berry
o get email telling me the database was up to date. Does anyone know why it was set up this way, and what should I do about it? Chris Berry [EMAIL PROTECTED] Systems Administrator JM Associates & Coast Business Service "When your only tool is a hammer, al

Re: [Clamav-users] freshclam exit code

2003-12-12 Thread Chris Berry
; /usr/local/bin/freshclam --quiet -l /var/log/clam-update.log if [ $? -le 1 ]; then exit 0 else exit $? fi Hmm, that looks better than the way I did it, thanks. Chris Berry [EMAIL PROTECTED] Systems Administrator JM Associates & Coast Business Service "When your only tool is a hammer, all

[Clamav-users] Tag line in body of email

2003-12-17 Thread Chris Earle
Is it possible to write a 'tag line' to the bottom of all processed email, including a simple text line, and possibly the status of clamav's output? IE: at end of e-mail body This email has been scanned using ClamAV: E-Mail Status: Clean ---

[Clamav-users] Which list

2004-01-06 Thread Chris Hastie
-To: header of posts is not set to the list address? Or have I misunderstood the purpose of the clamav-virusdb list? -- Chris Hastie --- This SF.net email is sponsored by: IBM Linux Tutorials. Become an expert in LINUX or just sharpen your

[Clamav-users] SCO.a

2004-01-26 Thread McKeever Chris
qAAA Any suggestions? It finds other virii fine when they are still encoded, maybe the definitions need to be added for its MIME version? thanks --- Chris McK

Re: [Clamav-users] SCO.a

2004-01-27 Thread McKeever Chris
it finds it fine when it is still an attachment, or after the file has been extracted from the email? --- Chris McKeever If you want to reply directly to me, please use cgmckeever--at--prupref---dot---com http://www.prupref.com On Tue, 27 Jan 2004 09:24

Re: [Clamav-users] SCO.a

2004-01-28 Thread McKeever Chris
TED]> sent: > > >Nigel, > >I have several examples of this. Even with older virii. > >Would you be interested in them as well? > >Shawn > >On Tue, 27 Jan 2004 08:52:58 + Nigel Horne [EMAIL PROTECTED]> >exclaimed: > >> On Tuesday 27 Jan 2004 3:11 a

Re: [Clamav-users] SCO.a

2004-01-28 Thread McKeever Chris
Nigel - I sent a message to you that made it through the system after I turned off the second AV for the mail. so that is an *original* copy of an email that got through thanks --- Chris McKeever If you want to reply directly to me, please use cgmckeever

[Clamav-users] clamd doesn't seem to scan attachments nested inside attached emails

2004-01-31 Thread chris lange
pick it up. is this a limitation of clam or is my configuration to blame? aside from that i think clamav is a fantastic project. many many thanks to all the contributers. chris --- The SF.Net email is sponsored by EclipseCon 2004 Premiere Con

[Clamav-users] sco.a+clamav+qmailscan

2004-02-02 Thread McKeever Chris
having an issue with sco.. Any ideas? --- Chris McKeever If you want to reply directly to me, please use cgmckeever--at--prupref---dot---com http://www.prupref.com Prudential Preferred Properties www.prupref.com

[Clamav-users] ClamAV process seems to be taking forever

2004-02-04 Thread Chris Barnes
has: MaxThreads 50 Why is the maxthreads seem to be ignored? Or am I just doing something really dumb? -- + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Chris Barnes AOL IM: CNBarnes [EMAIL PROTECTED] Yahoo IM: chrisnbar

[Clamav-users] Re: ClamAV process seems to be taking forever

2004-02-04 Thread Chris Barnes
r > clamav. I'm not sure, I don't know RH :> I didn't set it up (someone else did). Where would I make such a change? /etc/clamav.conf ? -- + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Chris Barnes AOL IM: CN

[Clamav-users] Re: ClamAV process seems to be taking forever

2004-02-05 Thread Chris Barnes
Ing. Germán González B. <[EMAIL PROTECTED]> wrote: > In RH > /etc/sysconfig/clamav-milter Gracias. -- + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Chris Barnes AOL IM: CNBarnes [EMAIL PROTECTED] Yahoo IM:

[Clamav-users] unrar

2004-02-13 Thread Chris Conn
ot; if the "thefile.rar" is in the /root directory with 700 permissions set, causing the archive to be unreadable by non-root user. Therefore, I belive it has to do with a permissions problem. What is the path of files scanned by the cl

Re: [Clamav-users] unrar

2004-02-14 Thread Chris Conn
re. I've attached my own updated clamav-wrapper which addresses this issue. You will need to uncomment the lines about unrar in it. Hello, You are absolutely correct, I apologize; I took the wrong email in my adressbook when I was sending this. in any case, thanks for the f

[Clamav-users] Re: clamdmail how with sendmail?

2004-02-17 Thread Chris Barnes
Grzegorz Staleñczyk <[EMAIL PROTECTED]> wrote: > Because, my sendmail is from Solaris package and I can't recompile it > with milter :-(( Definately look into using MailScanner. -- + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +

[Clamav-users] Virus List

2004-02-22 Thread Chris A
Dear List, Is there a way to display a list of virii that the current pattern files protect against? I've searched the man pages, but not found any clues. Thanks, Chris --- SF.Net is sponsored by: Speed Start Your Linux Apps Now. Buil

[Clamav-users] Re: Virus List

2004-02-22 Thread Chris A
here is no mention of the -l or --list-sigs option. Howerver, it works. Thanks again, Chris --- SF.Net is sponsored by: Speed Start Your Linux Apps Now. Build and deploy apps & Web services for Linux with a free DVD software kit from IBM. Click

[Clamav-users] amavisd-new and clamav: getting clamd.ctl location right

2004-02-27 Thread Chris Evans
ume I must have done something else that caused this change but it was all this morning and I can't think of anything. Chris PSYCTC: Psychotherapy, Psychology, Psychiatry, Counselling and Therapeutic Communities; practice, research, teaching and consultancy. Chris E

Re: [Clamav-users] Password-protected .zip file viruses

2004-03-02 Thread Chris Meadors
you think it is something that can reasonably be done for thousands of files a day. -- Chris --- SF.Net is sponsored by: Speed Start Your Linux Apps Now. Build and deploy apps & Web services for Linux with a free DVD software kit from IBM. Click Now! h

Re: [Clamav-users] Password-protected .zip file viruses

2004-03-03 Thread Chris Meadors
to use that to open it, is small enough to make the virus unviable. Good point. That should take less than a second. My 700 MHz machine can try every word in an unabridged English dictionary in about 15 seconds. Though there could be HTML bodies with the password. -- Chris

[Clamav-users] Re: Password-protected .zip file viruses

2004-03-03 Thread Chris Barnes
virus has the password in the body of the message. At worse, using only the words in the body of the message should suffice (greatly increasing the speed). -- + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Chris Barnes AOL IM:

[Clamav-users] Re: Simple patch for dealing with password zip files

2004-03-04 Thread Chris Barnes
, I can't think of a good reason why anyone in my department would password protect a .zip file when sending directly from 1 person to another. I suspect I'll keep this "temporary" fix for good. -- + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Chris

Re: [Clamav-users] TCP on Clam Milter

2004-03-07 Thread Chris Meadors
before restarting. That is not convenient. So i want to ask if this possible to run milter on a TCP port but not on socket? Don't use `kill -9`. Just a `kill` would have done, and probably cleaned up the socket. See: http://www.sektorn.mooo.com/era/unix/award.html#uuk9letter --

Re: [Clamav-users] network scanning questions

2004-03-09 Thread Chris Meadors
ohol Policies? Now what exactly will the new version of ClamAV be doing? :) Maybe http://www.i-cap.org/home.html? -- Chris --- This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux tutorial presented by Daniel Robbins, President

[Clamav-users] clamscan configuration

2004-03-10 Thread Chris Lopeman
there no configuration file for clamscan? Is there no way to get it to use the clamav.conf? Thanks, Chris --- This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux tutorial presented by Daniel Robbins, President and CEO of

[Clamav-users] freshclam no connect

2004-03-10 Thread Chris Lopeman
make it not notify? Except for a couple of thing I don't understand about the product I am quite impressed. connect(): Connection refused ERROR: Can't connect to clamd. Thanks, Chris --- This SF.Net email is sponsored by: IBM Linux

Re: [Clamav-users] clamscan configuration

2004-03-14 Thread Chris Lopeman
Response below Odhiambo Washington wrote: * Chris Lopeman <[EMAIL PROTECTED]> [20040311 05:42]: wrote: Hi All, I have installed clam scan on Fedora. My needs are simple. I want to run a periodic scan of almost all files on the system. This seems simple enough. Howe

Re: [Clamav-users] freshclam no connect

2004-03-14 Thread Chris Lopeman
documentation is the last thing considered on any project. Even with my troubles, I find the documentation quite impressive. This is a great project and product. Thanks again Krištof Petr wrote: Chris Lopeman wrote: Hi All, I have seen the opposite question posed but not this one. I get the error

Re: [Clamav-users] clamscan configuration

2004-03-14 Thread Chris Lopeman
Yes I know that.  Is the answer that there is no configuration file for clamscan? Tomasz Kojm wrote: On Sun, 14 Mar 2004 10:19:02 -0600 Chris Lopeman <[EMAIL PROTECTED]> wrote: Now don't get me wrong. ClamAV is an impressive product with impressive documentation. Bu

[Clamav-users] Encrypted RAR Signature

2004-03-16 Thread Chris Meadors
r only those with the "ArchiveDetectEncrypted" option set? -- Chris --- This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux tutorial presented by Daniel Robbins, President and CEO of GenToo technologies. Learn everyth

Re: [Clamav-users] Freshclam died

2004-03-16 Thread Chris Meadors
Steven P. Donegan wrote: Hmmm, I just do a freshclam from chron rather than let it run as a daemon - as a new user (I just downloaded, installed, integrated with my anti-spam/anti-virus proxy - home built, today). Is doing this in any way a negative thing? I don't think it hurts, and from the r

Re: [Clamav-users] Postmaster bounces and such.

2004-03-21 Thread Chris Meadors
ror. If the relaying host generates a bounce to the wrong person, it is their problem. -- Chris --- This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux tutorial presented by Daniel Robbins, President and CEO of GenToo technologies.

Re: [Clamav-users] Virus ID

2004-03-23 Thread Chris Meadors
possible). Along with current outbreak info. While that would be a big task for the core developers, I'm sure there'd be a few people in the Clam community who could submit this information. A Wiki type interface would be perfect for this. -- Chris ---

Re: [Clamav-users] RE: memory leak?

2004-03-25 Thread Chris Meadors
mments in the .conf file. -- Chris --- This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux tutorial presented by Daniel Robbins, President and CEO of GenToo technologies. Learn everything from fundamentals to system administra

Re: [Clamav-users] Spam/Virus stats using mrtg

2004-04-02 Thread Chris Meadors
ter, and not have to run through the file for every virus name, but this works for me: for VIRUS in $(grep FOUND clamd.log | cut -d ':' -f 4 | cut -d ' ' -f 2 | sort | uniq); do echo -n "$VIRUS: " grep -c "$VIRUS" clamd.log done -- Ch

[Clamav-users] segmentation fault in 0.70 ?due to filename of infected virus?

2004-05-04 Thread Chris Conn
ash in such a way? This is obviously the scan that caused the segmentation fault, however is this the reason? Thanks in advance, Chris --- This SF.Net email is sponsored by: Oracle 10g Get certified on the hottest thing ever to hit the mar

Re: [Clamav-users] segmentation fault in 0.70 ?due to filename of infected virus?

2004-05-05 Thread Chris Conn
dscan on every one. It will find 2 to 5 hundred Klez viruses per day. In your expert opinion, what would be the reason for this segmentation fault that occurred at the exact second it scanned this Klez virus? Chris --- This SF.Net email is spon

Re: [Clamav-users] segmentation fault in 0.70

2004-05-05 Thread Chris Conn
out this? Wed May 5 10:33:25 2004 -> Segmentation fault :-( Bye.. May 5 10:33:25 MailScanner[31779]: /var/spool/MailScanner/incoming/31779/./i45EXMfl013601/%nTips.exe: Eicar-Test-Signature FOUND Therefore, there are some strange coincidences going

Re: [Clamav-users] segmentation fault in 0.70 ?due to filename of infected virus?

2004-05-05 Thread Chris Conn
Tomasz Kojm wrote: On Wed, 05 May 2004 09:32:48 -0400 Chris Conn <[EMAIL PROTECTED]> wrote: Hello, This server processes between 30 and 100 thousand emails per day, calling clamdscan on every one. It will find 2 to 5 hundred Klez viruses per day. In your expert opinion, what would

Re: [Clamav-users] segmentation fault in 0.70 ?due to filename of infected virus?

2004-05-05 Thread Chris Conn
, I have re-instated my clamd and have disabled the LogSyslog in the clamd.conf and I am happy to say that my Eicar-test signature virus does get caught and no longer crashes the clamd process =) Thank you for this workaround. Sincerely, Chris

Re: [Clamav-users] Virus found in virgin RHES 3 installation?

2004-05-07 Thread Chris Meadors
ore at the top of that list. That is the core kernel memory. So it is very unlikely that a Windows trojan is installed in that file. It just happened that the random pattern of bits in the core at that time triggered a false positive. -- Chris

Re: [Clamav-users] One seems to have sneaked by W32.BEAGLE.X

2004-05-16 Thread McKeever Chris
-round-about-way, I am suggesting that maybe the email originated internally and never hit the clambox --- Chris McKeever If you want to reply directly to me, please use cgmckeever--at--prupref---dot---com http://www.prupref.com Prudential Preferred

Re: [Clamav-users] One seems to have sneaked by W32.BEAGLE.X

2004-05-16 Thread McKeever Chris
--- Chris McKeever If you want to reply directly to me, please use cgmckeever--at--prupref---dot---com http://www.prupref.com Prudential Preferred Properties Chicago and Illinois NorthShore Real Estate Experts On Sun, 16 May 2004 13:42 , Eric Becker <[EM

Re: [Clamav-users] Freshclam not responding

2004-06-01 Thread McKeever Chris
I have found that freshclam just like to stop occasionally, I run a cron job to see that it is still running, I guess one could get a little more creative and set it to star tback p if it is ofund to be missing --- Chris McKeever If you want to reply

Re: [Clamav-users] OT: Question Re: possibly infected W2K Server

2004-06-01 Thread McKeever Chris
(http://www.clamwin.com\) do it? I run it on multiple >desktop systems. > > --- Chris McKeever If you want to reply directly to me, please use cgmckeever--at--prupref---dot---com http://www.prupref.com";>www.prupref.com Prudential Preferred Properties http://www.prupref.c

[Clamav-users] clamav 0.72 - clama-milter

2004-06-08 Thread Chris Tan
heya, under clamav-milter -h, it shows --from=email.. however, when i input an email, the return message i get is /usr/local/sbin/clamav-milter: option `--from' doesn't allow an argument when i tried running -a [EMAIL PROTECTED], clamav-milter doesnt run (didnt try using just -a option) i r

<    1   2   3   4   5   >