Re: [clamav-users] zip, rar, jar, ... how to delete all exe's and others files?

2016-04-14 Thread Steve Basford
On Thu, April 14, 2016 7:48 am, ìÉ×ÉÔÉÎ óÅÒÇÅÊ àÒØÅ×ÉÞ wrote: > Hi. > Use clamav + spamassassin + postfix. > Use /var/lib/archive.zmd and archive.rmd] > > Tried to sent exe-file in rar archive - clamd said "CLEAN" :( > Where is detailed documentation about possibilities of clamav? A few things:

Re: [clamav-users] Strange problem with custom Yara rule

2016-04-14 Thread kionez
#include // created 13/04/2016 19:33 > Please refer to the bug report at: > https://bugzilla.clamav.net/show_bug.cgi?id=11552 > for the patch to resolve the issue. Wow, thanks for the quick solution :) I've just tried the patch on my laptop and seems working fine, I do some tests and I will

Re: [clamav-users] winnow FP

2016-04-14 Thread Paul Whelan
On 13 Apr 2016 at 11:20, Alex wrote: > Hi, > > I don't understand why themastersbaker.com would be tagged? > > # sigtool --find-sigs winnow.spam.ts.untyped.966134 | sigtool --decode-sigs > VIRUS NAME: winnow.spam.ts.untyped.966134 Winnow signatures are distributed by Sanesecurity.com. They hav

Re: [clamav-users] winnow FP

2016-04-14 Thread Steve Basford
On Thu, April 14, 2016 8:22 am, Paul Whelan wrote: > On 13 Apr 2016 at 11:20, Alex wrote: > > >> Hi, >> >> >> I don't understand why themastersbaker.com would be tagged? Quick update: FP has already been removed. Cheers, Steve Web : sanesecurity.com Blog: sanesecurity.blogspot.com Twitter: @san

[clamav-users] How to start clamd in Aix - clam.0.98.1

2016-04-14 Thread kk nair
Atlast we are able to make install clam in aix6.1. We have installed 0.98.1. Freshclam is failing for us and we cant list any process running with 'clam'. Please share the steps in starting clam. Regards, Kk ___ Help us build a comprehensive ClamAV gui

Re: [clamav-users] winnow FP

2016-04-14 Thread TR Shaw
Removed when I saw the original message > On Apr 14, 2016, at 3:22 AM, Paul Whelan wrote: > > On 13 Apr 2016 at 11:20, Alex wrote: > >> Hi, >> >> I don't understand why themastersbaker.com would be tagged? >> >> # sigtool --find-sigs winnow.spam.ts.untyped.966134 | sigtool --decode-sigs >> VI

Re: [clamav-users] zip, rar, jar, ... how to delete all exe's and others files?

2016-04-14 Thread Kris Deugau
Steve Basford wrote: > 1) .rmd/.zmd databases are obsolete, they are replaced with .cdb > > More details: > https://github.com/vrtadmin/clamav-devel/blob/master/docs/signatures.pdf Does anyone have any examples of valid signatures for the .cdb sigfiles? I've tried a couple of times to port some

Re: [clamav-users] yara #match does not work with regex

2016-04-14 Thread Kevin Lin
In order to minimize the amount of regex execution in ClamAV, regex signatures are usually run until the first match is detected. This means that counting regex matches do not work in the general case. The ClamAV ldb signatures have a custom flag 'g' which specifies to the engine to find all match

[clamav-users] sigtool reports an error

2016-04-14 Thread Arnaud Jacques / SecuriteInfo.com
Hello, Using sigtool -l always reports this error : ERROR: listdb: Malformed pattern line 1 (file /tmp/clamav- c57a51d1b297cd6a8b2ca0810c9776f9.tmp/daily.cdb) ERROR: listdb: Error listing database /tmp/clamav-c57a51d1b297cd6a8b2ca0810c9776f9.tmp/daily.cdb ERROR: listdb: Can't list directory /var

Re: [clamav-users] zip, rar, jar, ... how to delete all exe's and others files?

2016-04-14 Thread Benny Pedersen
On 2016-04-14 16:15, Kris Deugau wrote: Does anyone have any examples of valid signatures for the .cdb sigfiles? http://sanesecurity.com/foxhole-databases/ "whatever"), but based on what I've tried so far that's apparently not valid. yes i have hard to get more info on cdb format files asw

Re: [clamav-users] sigtool reports an error

2016-04-14 Thread Steven Morgan
Hi Arnaud, I've opened https://bugzilla.clamav.net/show_bug.cgi?id=11553 for a fix. Thanks for your report, Steve On Thu, Apr 14, 2016 at 11:03 AM, Arnaud Jacques / SecuriteInfo.com < webmas...@securiteinfo.com> wrote: > Hello, > > Using sigtool -l always reports this error : > > ERROR: listdb: