[clamav-users] invalid icon entries?

2014-08-09 Thread Tom
When I run clamscan (clamav-0.98.4-1.el6.rf.x86_64), I get this output: LibClamAV Warning: cli_scanicon: found 3 invalid icon entries of 3 total LibClamAV Warning: cli_scanicon: found 3 invalid icon entries of 3 total LibClamAV Warning: cli_scanicon: found 12 invalid icon entries of 12 total Are

[Clamav-users] How do yo start clamd?

2004-11-27 Thread Tom
I killed freshclam and clamd. How do I restart it? Yes, I already RTM and determined that the supplied clamdwatch script will not run - even after I update the paths and socket name! The setup requires a cron job command. The last item in the cron statement is a clamav-daemon command... Example:

[Clamav-users] Re: How do yo start clamd?

2004-11-28 Thread Tom
[EMAIL PROTECTED] sbin]# /sbin/service clamd restart clamd: unrecognized service Tom ___ http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users

Re: [clamav-users] My malware submissions are bouncing. Help!

2013-11-27 Thread Tom Judge
I have passed this information on to our operations group. Thanks Tom On Wed, Nov 27, 2013 at 5:23 PM, TR Shaw wrote: > > > Any ideas? > > btw, Happy Thanksgiving! > > This is the mail system at host si01.clam.sourcefire.com. > > I'm sorry to have to inform

Re: [clamav-users] Submissions being rejected :-(

2014-01-21 Thread Tom Judge
Our OPs team are reporting that this issue is now fixed. Could you please try your submission again? Thanks Tom On Tue, Jan 21, 2014 at 8:52 AM, TR Shaw wrote: > This is the mail system at host si01.clam.sourcefire.com. > > I'm sorry to have to inform you that your message

Re: [clamav-users] Avoit Short-Circuiting on (untrusted) Pattern match

2014-02-18 Thread Tom Judge
Hi Torge, You can use the ALLMATCHSCAN command for clamd, this will return all the signatures that matched on the file rather than just the first. Tom On Tue, Feb 18, 2014 at 10:42 AM, Torge Husfeldt wrote: > Hi, > > We are scanning webhosing-files from a relatively large user-

Re: [clamav-users] Keeping the ClamAV process open?

2014-03-03 Thread Tom Judge
7;d machine. As Dennis mentioned you should defiantly use clamd for this work to significantly reduce your overhead. Tom > Thanks. > > ___ > Help us build a comprehensive ClamAV guide: > https://github.com/vrtadmin/clamav-faq > http:

Re: [clamav-users] custom signatures wont work :(

2014-03-13 Thread Tom Judge
I think you will find that you file is too small, try making the file larger than 6 bytes. Tom On Thu, Mar 13, 2014 at 6:44 PM, krz...@gmail.com wrote: > I've spend on this about 6 hours without any effect. Please help :( > I had it working some time ago but today I've f

Re: [clamav-users] Still fighting with ClamAV and Ubuntu

2014-07-24 Thread Tom Judge
Looks like you are missing the clamav group (or other group that clamd is set to run as in the config file). Tom On Wed, Jul 23, 2014 at 5:10 PM, Chris wrote: > Still trying to get this to work with SA. I'm pretty sure it's not going > to until I get the correct reply: > &g

Re: [Clamav-users] VIRUS? PHISH? "Western Union Transfer MTCN: 0258258718"

2009-05-12 Thread Tom Shaw
s including ClamAV. If you want, you can forward to virus-samp...@oitc.com and we'll make a temporary signature for it until ClamAV folks build a analyzed signature. These signatures are contained in winnow_malware.hdb distributed along with the sanesecurity sigs. We have submitted this one

Re: [Clamav-users] freshclam permissions on database directory

2009-06-11 Thread Tom Shaw
>on the clamav database directory. I note this error in various fora at least >for MacOS and Windows. > >My question is: >What is the ideal secure solution for freshclam and clamav database >permissions? What user/group is freshclam running as? Using 0.95.1 on 10.5.7, I use a

Re: [Clamav-users] freshclam permissions on database directory

2009-06-11 Thread Tom Shaw
hclam as a deamon but as a periodic process run by launchd as _clamav:_clamav. Likewise for clamd. THis allows for automatic process restart by launchd if there is a problem (for example the bug that caused 0.94.2 to randomly crash using unofficials on some systems). Using launchd rather than startup scripts or cron jobs is much cleaner under OSX. As for DB I agree that the files should be _clamav:_clamav -rw-r--r- Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] freshclam permissions on database directory

2009-06-11 Thread Tom Shaw
At 7:24 AM -0700 6/11/09, Dennis Peterson wrote: >Tom Shaw wrote: > >> >> Under OSX you should not run freshclam as a deamon but as a periodic >> process run by launchd as _clamav:_clamav. Likewise for clamd. THis >> allows for automatic process restart by

Re: [Clamav-users] ClamAV update auf 0.95.2

2009-06-18 Thread Tom Shaw
allation is OUTDATED!" However, the "ERROR: chdir_tmp: Can't create directory" indicates your istall has permissions problems. Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] ClamAV update auf 0.95.2

2009-06-20 Thread Tom Shaw
At 10:26 PM +0200 6/20/09, Udo Stifter wrote: >Am 2009-06-18 10:04, Tom Shaw schrieb: > > > At 1:35 AM +0200 6/18/09, Udo Stifter wrote: > > > >Hallo, > > > > > > > >zur Zeit nutze ich ClamAV 0.95.1 auf meinem PowerMac G4 (933 MHz, > > >

Re: [Clamav-users] question about Clamav anti virus for old mac OS 9.2

2009-06-22 Thread Tom Shaw
ou could email the suspect file(s) to virustotal so check them. Or you could turn off Macros in Word and copy the contents to new files. Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] question about Clamav anti virus for old mac OS 9.2

2009-06-22 Thread Tom Shaw
At 8:04 PM -0400 6/22/09, John Jasen wrote: >Tom Shaw wrote: > >> You could copy your MS Word files to an OSX machine and check them. >> You could search on eBay for an old AV program that worked on OS 8/9. >> You could email the suspect file(s) to virustotal so chec

Re: [Clamav-users] question about Clamav anti virus for old mac OS 9.2

2009-06-23 Thread Tom Shaw
.geckoandfly.com/2009/03/19/download-the-best-mac-os-x-anti-spyware-and-anti-virus-software-for-free/ I have to say you might be better off just hiring a local Mac guy for a couple of hours to make this painless. Tom -- Tom Shaw - Chief Engineer, OITC , http://www.oitc.com/ local wx: http://www.

[Clamav-users] Zeus .bin files

2009-06-26 Thread Tom Shaw
Just a question on signatures... Does the signature team not do Zeus/ZBot configuration files? We have submitted a number (20+) of ".bin" files over the last 6-8 weeks but have yet to see these files detected using "Official" signatures. Should we not subm

[Clamav-users] Signature dups

2009-06-30 Thread Tom Shaw
Does freshclam or clam on load/reload look for and remove dup signatures? Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] Signature dups

2009-06-30 Thread Tom Shaw
u must have something like this internally if for any reason to cull dups and to checkout or signature creation so adding some exposure of the DB shouldn't be an issue. Unfortunately nothing has come from this Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

[Clamav-users] List bounces

2009-06-30 Thread Tom Shaw
owner of snigelpost.org's mailserver and request kindly for them to configure their mailserver to be compliant with RFC 2821. TIA, Tom PS Sorry about the rant ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http:/

Re: [Clamav-users] clamd 0.95.2 unrar

2009-07-09 Thread Tom Shaw
At 3:20 PM -0700 7/9/09, MrC wrote: On 7/9/2009 3:14 PM, Tom Shaw wrote: I searched the archive and could not find a solution. I have been running without unrar support for a bit because I didn't have time to run this down. I compiled 0.95.2 from source and it has been running flawlessly

Re: [Clamav-users] clamd 0.95.2 unrar

2009-07-09 Thread Tom Shaw
Steve I don't have sudo ldconfig . I am on BSD unix (OSX) Tom At 10:23 AM +1200 7/10/09, steve wrote: Content-Type: multipart/signed; micalg="pgp-sha1"; protocol="application/pgp-signature"; boundary="=-jynSTeQe1Oi6eCI5r7n5" You might fix this with

[Clamav-users] clamd 0.95.2 unrar

2009-07-09 Thread Tom Shaw
iface.la lrwxrwxrwx1 root wheel 23 Jun 16 19:32 libclamunrar_iface.so -> libclamunrar_iface.6.so Help is appreciated. Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] clamd 0.95.2 unrar

2009-07-09 Thread Tom Shaw
OK Got it fixed. Looks like incompatibilities of libraries. All is fine now. Thanks for your help pointing me in the right direction. Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

[Clamav-users] Signature/Weirdness

2009-09-14 Thread Tom Shaw
I am running ClamAV 0.95.2/9806/Mon Sep 14 14:37:58 2009 when I run clamscan on a file I get no detection yet when I submit the same file to virustotal (0.94.1/20090912) I get Trojan.Zbot-4583 detected. My clamav install has been operating fine for months on OSX 10.5. Ideas? Tom

Re: [Clamav-users] Signature/Weirdness

2009-09-14 Thread Tom Shaw
At 12:59 PM -0700 9/14/09, Bill Landry wrote: Tom Shaw wrote: I am running ClamAV 0.95.2/9806/Mon Sep 14 14:37:58 2009 when I run clamscan on a file I get no detection yet when I submit the same file to virustotal (0.94.1/20090912) I get Trojan.Zbot-4583 detected. My clamav install has

Re: [Clamav-users] Signature/Weirdness

2009-09-14 Thread Tom Shaw
At 2:00 PM -0700 9/14/09, Bill Landry wrote: > At 12:59 PM -0700 9/14/09, Bill Landry wrote: Tom Shaw wrote: I am running ClamAV 0.95.2/9806/Mon Sep 14 14:37:58 2009 when I run clamscan on a file I get no detection yet when I submit the same file to virustotal (0.94.1/20090912) I

Re: [Clamav-users] Submission policies

2009-09-15 Thread Tom Shaw
systems at http://www.oitc.com/winnow/clamsigs/MalwareSignatures.html Samples can be sent to virus-samples at oitc.com Tom At 10:55 PM +0200 9/15/09, Giampaolo Tomassoni wrote: > The answer is very simply, resources. The submission interface receives around 20,000 unique samples a day, wh

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Tom Shaw
same sort of fake invoices I've been receiving here, using the Sanesecurity signatures: I also have malware detection for these in winnow_malware.hdb. See http://www.oitc.com/winnow/clamsigs/MalwareSignatures.html Tom ___ Help us build a com

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Tom Shaw
st plain rejecting with them? Sounds like the latter. I don't run ClamAV via SpamAssassin. I have it called by amavisd-new, which does what it does: quarantine. Sure hope your not using heuristics, phishing and/or safebrowsing options in ClamAV if you feel th

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Tom Shaw
At 10:39 PM +0300 9/23/09, Jari Fredriksson wrote: >> I don't run ClamAV via SpamAssassin. I have it called by amavisd-new, which does what it does: quarantine. Sure hope your not using heuristics, phishing and/or safebrowsing options in ClamAV if you feel that way. I use amavisd-new d

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Tom Shaw
es to detect phish all of which can cause a certain percentage of FPs. Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Tom Shaw
t more than my winnow_malware.hdb which would have caught your virus. Point being you might just want to consider what you have running... Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Tom Shaw
might just want to consider what you have running... Tom Come'on Tom. Winnow might very well cought that, but I got it caught with F-Prot and BitDefender too. The trojan itself is not my problem. My problem was that ClamAV did not get it, and did not allow me to report it in their websit

Re: [Clamav-users] DHL invoices

2009-09-24 Thread Tom Shaw
were blocked using Sanesecurity.Malware.12505.UNOFFICIAL. Luca, I have a couple of samples as well blocked by winnow.malware.7065.UNOFFICIAL winnow.malware.7066.UNOFFICIAL if you need them. They were originally submitted on 9/18. Tom ___ Hel

Re: [Clamav-users] DHL invoices

2009-09-24 Thread Tom Shaw
At 9:53 AM -0400 9/24/09, Tom Shaw wrote: At 2:19 PM +0100 9/24/09, Steve Basford wrote: > Yeah, we already know that. Can you please cut&paste the full message returned by the form? Thanks, Hi Luca, I've *just* uploaded 4 copies of the dhl invoice malware that have been mis

[Clamav-users] IRS Scam

2009-09-28 Thread Tom Shaw
://www.computerworld.com/s/article/9138527/IRS_scam_now_world_s_biggest_e_mail_virus_problem?source=CTWNLE_nlt_dailyam_2009-09-28 Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] Some Virus not detected by Clamav

2009-10-13 Thread Tom Shaw
fficial ClamAV signature team. Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] Some Virus not detected by Clamav

2009-10-15 Thread Tom Shaw
is currently being blocked, as Sanesecurity.Malware.12699 Steve, The samples I have of that one are being detected by ClamAV standard sigs as Trojan.Peed-477. Wonder why you and some others didn't detect it with standard sigs? Could this be a problem? Do you have samples that were u

Re: [Clamav-users] Some Virus not detected by Clamav

2009-10-15 Thread Tom Shaw
ayloads That one is also typed as winnow.malware.7515/6.UNOFFICIAL Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] Some Virus not detected by Clamav

2009-10-15 Thread Tom Shaw
At 3:14 PM +0300 10/15/09, Jari Fredriksson wrote: Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="=_20nrA2UWvqBocwzbhDgZQrQ22plLxr" Content-Disposition: inline 15.10.2009 14:55, Tom Shaw kirjoitti: The samples I have o

Re: [Clamav-users] Some Virus not detected by Clamav

2009-10-15 Thread Tom Shaw
s they changed their attack vector. Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] Some Virus not detected by Clamav

2009-10-15 Thread Tom Shaw
innow.malware.7515.UNOFFICIAL was removed due to detection on recent official sig updates. Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] Some Virus not detected by Clamav

2009-10-15 Thread Tom Shaw
it is possible that is does not recognise this http://www.iki.fi/jarif/malware/FILE_UPS_c380a16.zip That's an UPS fraud, W32/Bredolab.D.gen!Eldorado by F-Prot. winnow.malware.7520/1.UNOFFICIAL Tom ___ Help us build a comprehensive

Re: [Clamav-users] Some Virus not detected by Clamav

2009-10-16 Thread Tom Shaw
ins used to deliver malware payloads and invoke xsite injections as well as hand crafted signatures to detect links to malware. It also contains other signatures to augment winnow_malware.hdb to detect malware loaded on your system. Tom ___ H

Re: [Clamav-users] Some Virus not detected by Clamav

2009-10-16 Thread Tom Shaw
Tom Shaw wrote: Just to clarify winnow_malware.hdb is designed to detect malware payloads. Thus, it is effective in an email system only when the payload is attached (such as a dropper, etc). It is also very effective when used in file system/download checking scenarios. Thanks to Dennis

Re: [Clamav-users] Some Virus not detected by Clamav

2009-10-16 Thread Tom Shaw
Tom Shaw wrote: If you submit a file to virus-samp...@oitc.com I'll process it for winnow_malware.hdb and at the same time send it to the ClamAV malware signature team and virustotal to check if others can detect. If you submit a url to malware to virus-samp...@oitc.com I'lldo

Re: [Clamav-users] Some Virus not detected by Clamav

2009-10-16 Thread Tom Shaw
At 8:14 AM -0700 10/16/09, Dennis Peterson wrote: Tom Shaw wrote: Tom Shaw wrote: If you submit a file to virus-samp...@oitc.com I'll process it for winnow_malware.hdb and at the same time send it to the ClamAV malware signature team and virustotal to check if others can detect. I

Re: [Clamav-users] Some Virus not detected by Clamav

2009-10-16 Thread Tom Shaw
At 5:21 PM +0200 10/16/09, Jose-Marcio Martins da Cruz wrote: Tom Shaw wrote: As long as you don't obfuscate the url my scripts will isolate the url or the attached malware and process. Nice ! Can I send one URL per line ? I have 20 undetected virus. Yes it strips out all urls just

Re: [Clamav-users] APER

2009-10-22 Thread Tom Shaw
gnatures hosted at Sane Security). John Steve (sane security) was in the process of implementing at least a subset. I have to ask however. You mentioned it contains phish urls as well. I have not been able to find that. However, we track phish urls/domains in winnow_phish_com

[Clamav-users] where is 0.93 src?

2009-10-28 Thread Tom Shaw
Link of website goes to SF and there there is the sig but not the gz'd source. Please help, Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

[Clamav-users] Whoops where is 0.95.3 src?

2009-10-28 Thread Tom Shaw
At 1:12 PM -0400 10/28/09, Tom Shaw wrote: Link of website goes to SF and there there is the sig but not the gz'd source. Please help, Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/suppo

Re: [Clamav-users] load issues due to sanesecurity signatures

2009-11-02 Thread Tom Shaw
ed then he needs to look at his entire setup - what else is running on his machine and what it contributes to the load. I doubt its a signature file causing problems per se. Just my 2 cents, Tom Tom ___ Help us build a comprehensive ClamAV guide:

Re: [Clamav-users] load issues due to sanesecurity signatures

2009-11-03 Thread Tom Shaw
quot;? What version of OS and clamd? The more information the easier it will be for us to help. Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] [Bulk] Re: Quarantine issue with new 0.95.x clamav-milter

2009-11-09 Thread Tom Shaw
apture the nuance that Michael is wrestling with. As I understand it he wants his mailserver to accept the message and quarantine it for analysis and not for later delivery and NOT deliver it to the recipient. It seems to me perfectly acceptable to return a 5xx a

Re: [Clamav-users] SubmitDetectionStats Error

2009-11-20 Thread Tom Shaw
been 7 days and still no status report posted to the stats page! This can't be all that hard. Just my 2 cents. Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] SubmitDetectionStats Error

2009-11-21 Thread Tom Shaw
roject during my free time ;-) if you need and I am sure that others on this list will offer support as well.. Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

[Clamav-users] Detection Reporting

2009-11-25 Thread Tom Shaw
I have been looking at performing a single freshclam update and then distributing that update internally but I cannot find how to report detections from all the internal systems. Anyone have an idea on what I am missing? Tom ___ Help us build a

Re: [Clamav-users] Clamd & Clamav yield different results

2009-11-29 Thread Tom Shaw
You don't need linux to become more "unixfied" OSX is BSD unix under the hood after all. Tom PS Don't forget to set your bash profile to search /usr/local/bin as part of your search path in Terminal or else you will have to prepend /us

Re: [Clamav-users] Clamd & Clamav yield different results

2009-11-29 Thread Tom Shaw
hough on that system the case issues will be corrected. Anyway - it works fine on a Mac. Actually, Dennis, it comes preinstalled on Mini Server it just located in /usr/bin and its version 0.95.2 Tom ___ Help us build a comprehensive Cl

Re: [Clamav-users] ClamAV Memory Usage

2009-12-01 Thread Tom Shaw
es. Have your turned on safebrowsing in your config file? Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] How does Clam stand up to Commercial A/V?

2009-12-03 Thread Tom Shaw
At 3:50 PM +0300 12/3/09, Anatoly Pugachev wrote: Someone with linkedin account, could be interested in commenting the following discussion http://www.linkedin.com/groupAnswers?viewQuestionAndAnswers=&discussionID=10222162&gid=107486 Anatoly Whats the group'

Re: [Clamav-users] How does Clam stand up to Commercial A/V?

2009-12-03 Thread Tom Shaw
Thanks! I am "awaiting approval" At 4:18 PM +0300 12/3/09, Anatoly Pugachev wrote: Tom, I'm sorry, it's "IT Core Infrastructure" group, mentioned discusstion topic is "Wanted to get a feel of what people are using for an Enterprise Anti-virus solution in an

Re: [Clamav-users] How does Clam stand up to Commercial A/V?

2009-12-03 Thread Tom Shaw
much CPU and memory usage. For example, these third party signatures detected the recent zeus outbreaks (not to mention the google jobs, IRS and others) in one case before any other AV vendor and usually the same time as 2-3. Just my 2cents, Tom ___

Re: [Clamav-users] Phishing detection on downloaded pages

2009-12-11 Thread Tom Shaw
tory say, on my server, that it will not detect bad html files or bad php files? This true for graphics as well? What files are matched to signatures of type 1 trough 7? Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.

Re: [Clamav-users] Phishing detection on downloaded pages

2009-12-11 Thread Tom Shaw
At 9:31 PM +0200 12/11/09, Török Edwin wrote: On 2009-12-11 21:14, Tom Shaw wrote: At 3:53 PM +0200 12/10/09, Török Edwin wrote: >> On 2009-12-10 15:41, Sundara Kaku wrote: The heuristic phishing detector only works on emails correctly, not websites by design, hence there is no po

Re: [Clamav-users] ExcludePath, defining absolute path

2009-12-16 Thread Tom Shaw
one of the directories is called 'Volumes' which contains directories and links to other volumes which I scan separately. Is it possible to exclude an absolute path using the configure variable ExcludePath? A. A. Why don't you just do something l

[Clamav-users] TargetType

2010-02-13 Thread Tom Shaw
How does one determine what TargetType ClamAV will assign to a file or attachment? I have been all through the docs and wiki and can find no specifics. Any and all help is appreciated. Tom ___ Help us build a comprehensive ClamAV guide: visit http

Re: [Clamav-users] TargetType

2010-02-16 Thread Tom Shaw
s an rtf considered an OLE or ascii orwhat, and what does a zeus bin file get categorized as? Answers for these and many other questions like these, I have searched the docs to find out with no joy. Tom ___ Help us build a comprehensive C

Re: [Clamav-users] TargetType

2010-02-16 Thread Tom Shaw
On 02/16/2010 09:15 PM, Tom Shaw wrote: At 4:15 PM + 2/16/10, Steve Basford wrote: > Attached document? I did not see an attachment. Can you send a link? Is this the TargetType you are after... 2.3.4 Extended signature format The extended signature format allows

Re: [Clamav-users] TargetType

2010-02-16 Thread Tom Shaw
Thanks, Alain. This helps. Let me noodle on the information. Is there a definition of the .fmt file or will I have to look through the code? Thanks, again, Tom At 3:01 PM -0500 2/16/10, Alain Zidouemba wrote: Tom: Is this the answer you were looking for? -- Alain S. Zidouemba Research

Re: [Clamav-users] clamav syslog and cron

2010-03-09 Thread Tom Shaw
. Should I approach this in a different way like using clamscan instead? It does not look like clamscan can write to syslog but I could be wrong. Tim Why don't you just get rid of --fdpass and run the cron job as root? Tom -- Tom Shaw - Chief Engineer, OITC , http://www.oitc.com/ local wx:

[Clamav-users] quick question on freshclam

2010-03-09 Thread Tom Shaw
I can easily put a shell script between launchd and freshclam to solve this (in fact I have) but it would be much cleaner if I could tell freshclam to return 0 for both "good" events, eg updated and no need to update." Anyone got an idea on

[Clamav-users] Bad link on site to 0.96RC1

2010-03-10 Thread Tom Shaw
The link on http://www.clamav.net/ to 0.96.rc1 actually downloads 0.95.3. It should be http://sourceforge.net/projects/clamav/files/clamav/0.96rc1/clamav-0.96rc1.tar.gz/download Tom ___ Help us build a comprehensive ClamAV guide: visit http

Re: [Clamav-users] Bad link on site to 0.96RC1

2010-03-10 Thread Tom Shaw
At 12:39 AM +0100 3/11/10, Luca Gibelli wrote: Hello Tom, The link on http://www.clamav.net/ to 0.96.rc1 actually downloads 0.95.3. both links on www.clamav.net and www.clamav.net/download/sources work correctly for me. Thanks Luca. It must have been fixed because my first download was

[Clamav-users] FYI

2010-03-11 Thread Tom Shaw
Link to 0.95.3 on http://www.clamav.net/download/sources/ actually goes to 0.96rc1 Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

Re: [Clamav-users] ***** SPAM ***** ***** SPAM ***** Re: 0.96rc1 LibClamAV Warning: JIT not compiled in

2010-03-12 Thread Tom Shaw
that rev of gcc that will see this error. I had similar problem on OSX. I added this configure option: --enable-llvm and JIT compiles Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

[Clamav-users] Missed detection

2010-03-18 Thread Tom Shaw
dat-4mmrTv 23848f3f080237b7e2d2313496f4c00f:3680:./malware/style25.dat-4mmrTv Any ideas? I have a couple more like this in my DB. Tom ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

[Clamav-users] byte code compiler configure issues

2010-04-30 Thread Tom Shaw
ect (ifacegen) won't be configured automatically checking build system type... i386-apple-darwin9.8.0 checking host system type... i386-apple-darwin9.8.0 checking target system type... i386-apple-darwin9.8.0 Any ideas? Tom ___ Help us build a co

Re: [Clamav-users] byte code compiler configure issues

2010-05-01 Thread Tom Shaw
At 8:52 AM +0300 5/1/10, Török Edwin wrote: On 05/01/2010 01:17 AM, Tom Shaw wrote: I have the following configure problem: $ cd obj && ../llvm/configure --enable-optimized --enable-targets=host-only --disable-bindings --prefix=/usr/local/clamav configure: WARNING: Unknown

Re: [Clamav-users] byte code compiler configure issues

2010-05-01 Thread Tom Shaw
At 2:40 PM +0300 5/1/10, Török Edwin wrote: On 05/01/2010 02:20 PM, Tom Shaw wrote: llvm[3]: Compiling ClamBCOptimizers.cpp for Release build /Users/tshaw/Sites/clamav/clamav-bytecode-compiler/clamav-bytecode-compiler/llvm/lib/Target/ClamBC/ClamBCModule.cpp: In member function 'virtual

Re: [Clamav-users] byte code compiler configure issues

2010-05-01 Thread Tom Shaw
orted only once /Users/tshaw/Sites/clamav/clamav-bytecode-compiler/llvm/lib/Target/ClamBC/version.c:4: error: for each function it appears in.) make[3]: *** [/Users/tshaw/Sites/clamav/clamav-bytecode-compiler/obj/lib/Target/ClamBC/Release/version.o] Error 1 make[2]: *** [ClamBC/.makeall] Error 2 mak

Re: [Clamav-users] byte code compiler configure issues

2010-05-02 Thread Tom Shaw
At 10:45 AM +0300 5/2/10, Török Edwin wrote: On 05/02/2010 12:49 AM, Tom Shaw wrote: At 10:52 PM +0300 5/1/10, Török Edwin wrote: Please run 'make VERBOSE=1', and paste the output. llvm[3]: Compiling version.c for Release build Thanks, please 'git pull' and try build

Re: [Clamav-users] byte code compiler configure issues

2010-05-02 Thread Tom Shaw
At 4:46 PM +0300 5/2/10, Török Edwin wrote: On 05/02/2010 04:44 PM, Tom Shaw wrote: At 10:45 AM +0300 5/2/10, Török Edwin wrote: On 05/02/2010 12:49 AM, Tom Shaw wrote: At 10:52 PM +0300 5/1/10, Török Edwin wrote: Please run 'make VERBOSE=1', and paste the output.

Re: [Clamav-users] byte code compiler configure issues

2010-05-02 Thread Tom Shaw
At 6:07 PM +0300 5/2/10, Török Edwin wrote: On 05/02/2010 05:33 PM, Tom Shaw wrote: At 4:46 PM +0300 5/2/10, Török Edwin wrote: On 05/02/2010 04:44 PM, Tom Shaw wrote: At 10:45 AM +0300 5/2/10, Török Edwin wrote: On 05/02/2010 12:49 AM, Tom Shaw wrote: At 10:52 PM +0300 5/1/10

Re: [Clamav-users] byte code compiler configure issues

2010-05-02 Thread Tom Shaw
error: re2c command failed with exit code 1 (use -v to see invocation) Compiler exited with code 1! Going to now look for an example to insure its working correctly. Thanks again. Tom PS What the heck is the .data() function? ___ Help us build a comprehe

Re: [Clamav-users] byte code compiler configure issues

2010-05-02 Thread Tom Shaw
At 12:27 PM -0700 5/2/10, Dennis Peterson wrote: On 5/2/10 8:14 AM, Tom Shaw wrote: Trying now let you know in about 10 10.5.8 right now. 10.6 after we get this working Tom I was able to compile .96 in Snow Leopard with no modification. Thanks Dennis. I had no problems for ClamAV (did

Re: [Clamav-users] byte code compiler configure issues

2010-05-03 Thread Tom Shaw
At 5:48 AM -0700 5/3/10, Jim Preston wrote: Dennis Peterson wrote: On 5/2/10 8:14 AM, Tom Shaw wrote: Trying now let you know in about 10 10.5.8 right now. 10.6 after we get this working Tom I was able to compile .96 in Snow Leopard with no modification. dp Hi Dennis, Did not know

Re: [Clamav-users] byte code compiler configure issues

2010-05-03 Thread Tom Shaw
At 6:06 AM -0700 5/3/10, Jim Preston wrote: Tom Shaw wrote: At 5:48 AM -0700 5/3/10, Jim Preston wrote: Dennis Peterson wrote: On 5/2/10 8:14 AM, Tom Shaw wrote: Trying now let you know in about 10 10.5.8 right now. 10.6 after we get this working Tom I was able to compile .96 in Snow

Re: [Clamav-users] 0.96.1 Daemon permissions on Mac OS 10.6.4?

2010-07-12 Thread Tom Shaw
ove) if not as owner _clamav. Check your config files. If you manually need to run use sudo freshclam Tom -- Tom Shaw - Chief Engineer, OITC , http://www.oitc.com/ local wx: http://www.oitc.com/weather US Phone Numbers: 321-984-3714, 321-729-6258(fax), 321-258-2475 (cell/voice mail,pager) US sky

[Clamav-users] Unknown error code ERROR

2010-09-30 Thread Tom Robinson
lp is appreciated. Thanks Tom My environment: Oct 1 09:41:27 scion freshclam[27491]: ClamAV update process started at Fri Oct 1 09:41:27 2010 Oct 1 09:41:28 scion freshclam[27491]: main.cvd is up to date (version: 52, sigs: 704727, f-level: 44, builder: sven) Oct 1 09:41:28 scion freshclam[

[Clamav-users] Problems building 0.96.3 on Solaris 9/10

2010-10-04 Thread Tom Goerger
* Hi, I'm having problems building 0.96.3 on Solaris 9 and 10. I believe I've copied in the appropriate sections of configure and make below. Can anyone tell me why this might be failing? Or, what other information I can provide that might help? Thanks, Tom >From configu

Re: [Clamav-users] Problems building 0.96.3 on Solaris 9/10

2010-10-04 Thread Tom Goerger
We're using gcc to compile. No parameters on configure. The same setup was used to compile 0.95.2 just fine, without any problems, but it's bailing here without giving me a reason that I can decipher, at least. On Mon, Oct 4, 2010 at 2:19 PM, René Berber wrote: > On 10/4/2010

Re: [Clamav-users] Problems building 0.96.3 on Solaris 9/10

2010-10-05 Thread Tom Goerger
ainly the first failure I encountered in the config.log, and I'm seeing it a couple of times. On Mon, Oct 4, 2010 at 2:31 PM, René Berber wrote: > On 10/4/2010 2:24 PM, Tom Goerger wrote: > > > We're using gcc to compile. No parameters on configure. The same setup > was > >

Re: [Clamav-users] Problems building 0.96.3 on Solaris 9/10

2010-10-05 Thread Tom Goerger
x27;m seeing in STDOUT, if it helps: checking whether we are cross compiling... configure: error: in `/src/objss9/clamav-0.96.3/libclamav/c++': configure: error: cannot run C++ compiled programs. On Tue, Oct 5, 2010 at 3:26 PM, René Berber wrote: > On 10/5/2010 3:06 PM, Tom Goerger wrote: >

Re: [Clamav-users] Problems building 0.96.3 on Solaris 9/10

2010-10-05 Thread Tom Goerger
lamav-0.96.3/libclamav/c++': configure:3453: error: cannot run C++ compiled programs. If you meant to cross compile, use `--host'. So, must be some library that's missing. On Tue, Oct 5, 2010 at 4:57 PM, René Berber wrote: > On 10/5/2010 4:11 PM, Tom Goerger wrote: > &g

Re: [Clamav-users] Unknown error code ERROR

2010-10-11 Thread Tom Robinson
v.net/bugzilla/show_bug.cgi?id=2296 Regards, Tom On 01/10/10 10:18, Tom Robinson wrote: > Hi > > I saw a recent thread about something similar (LibClamAV Error: > cli_dbgets: Line too long for provided buffer?) > > I'm having a similar issue with only some PDF files not

[clamav-users] Problems compiling 0.97.2 on Solaris 9

2011-08-19 Thread Tom Goerger
ea why this might be going on? Any information I can provide that might help? Thanks, -- Tom Goerger University of Minnesota - Internet Services ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml

  1   2   3   >