[clamav-users] clamav update from tar.gz

2012-08-27 Thread infelectromed . mtz
Hi people: I have install clamav 0.96.5 from my ubuntu 10.04 repository but I want to upgrade to 0.97.5, I download the tar.gz file to my /home/user folder and do this: 1. Unpack the file 2. Cd to clamav directory 3. Run ./configure 4. Run make Now I want to uninstall the old clamav but I

[clamav-users] XF.Sic.E False positive

2012-08-27 Thread polloxx
Just a quick note to inform you that the FP for XF.Sic.E I submited to http://www.clamav.net/lang/en/sendvirus/submit-fp/ on Aug 13 is still in the database. ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net

Re: [clamav-users] XF.Sic.E False positive

2012-08-27 Thread Alain Zidouemba
In the RF822 message that you sent in, found: An Excel Formula Macro Virus (XF.Classic)) Hydrocodone/APAP 10-650 For Your Computer (C) The Narkotic Network 1998 **Simple Payload** **Set Our Values and Paths**5 **Add New Workbook, Infect It, Save It As Book1.xls** **Infect Workbook**. Why do you

Re: [clamav-users] clamav update from tar.gz

2012-08-27 Thread Bryan Burke
Now I want to uninstall the old clamav but I no idea of what packs, I have install: clamav, clamav-base, clamav-daemon, clamav-freshclam, libclamav6 and libtommath. I would keep one or more of this packs for eg libclamav6, to install the new version o I have to uninstall all of them? You

Re: [clamav-users] XF.Sic.E False positive

2012-08-27 Thread polloxx
Because a VirusTotal scan results in only Clamav (1/42) marking it as infected. On Mon, Aug 27, 2012 at 4:29 PM, Alain Zidouemba azidoue...@sourcefire.com wrote: In the RF822 message that you sent in, found: An Excel Formula Macro Virus (XF.Classic)) Hydrocodone/APAP 10-650 For Your Computer

Re: [clamav-users] Corrupt ClamAV virus DB files

2012-08-27 Thread Steve Brazill
This issue was resolved once I analyzed the 'behavior' of the download method, and the person performing the 'testing' and 'debugging' of the process (me)... The nightly download script, performs a WGET from db.local.clamav.net which I assumed would update (only if there were a newer version of