Re: [clamav-users] Malwarepatrol false positive

2018-08-20 Thread Al Varnell
Submit to fp (at) malwarepatrol.net. -Al- On Mon, Aug 20, 2018 at 08:34 PM, Alex wrote: > Hi, fyi > > # sigtool --find-sigs MBL_12952716 | sigtool --decode-sigs > VIRUS NAME: MBL_12952716 > TARGET TYPE: ANY FILE > OFFSET: * > DECODED SIGNATURE: > https://drive.google.com smime.p7s Description:

[clamav-users] Malwarepatrol false positive

2018-08-20 Thread Alex
Hi, fyi # sigtool --find-sigs MBL_12952716 | sigtool --decode-sigs VIRUS NAME: MBL_12952716 TARGET TYPE: ANY FILE OFFSET: * DECODED SIGNATURE: https://drive.google.com ___ clamav-users mailing list clamav-users@lists.clamav.net http://lists.clamav.net/cg

Re: [clamav-users] Help With clamscan vs clamdscan

2018-08-20 Thread Maarten Broekman
Yep. That's fine. /tmp or /var/tmp (or /run) is usually where it goes anyway. Welcome to the ClamAV club :) On Mon, Aug 20, 2018 at 7:45 PM Michael Newman wrote: > > On Aug 20, 2018, at 23:00, *Maarten Broekman* wrote: > > > For clamdscan to work you need to enable LocalSocket at the very least

Re: [clamav-users] ClamAV signature update sync errors have gotten worse

2018-08-20 Thread Paul Kosinski
It's good to save so much (5 PB) Internet traffic. What we were seeing from our end was that there were a lot of full-size downloads of daily.cvd that were useless because they were the old version rather than the new version advertised by the DNS TXT record. Besides being annoying because of lot

Re: [clamav-users] freshclam vs sudo freshclam

2018-08-20 Thread Michael Newman
Al Varnell wrote: > It appears to me from your other thread that you are using a Homebrew > compiled installation. If that is the case, then you need to contact the > package distributor (Homebrew) about any issues with their compilation. Actually, it’s MacPorts, but, point taken. I’ve posted t

Re: [clamav-users] Help With clamscan vs clamdscan

2018-08-20 Thread Michael Newman
> On Aug 20, 2018, at 23:00, Maarten Broekman wrote: > > For clamdscan to work you need to enable LocalSocket at the very least. Thank you. I had no idea what a socket was. Now I know. I didn’t know where to put it, so I tried this: LocalSocket /var/tmp/clamd.socket It seems to have worked an

Re: [clamav-users] freshclam vs sudo freshclam

2018-08-20 Thread Al Varnell
It appears to me from your other thread that you are using a Homebrew compiled installation. If that is the case, then you need to contact the package distributor (Homebrew) about any issues with their compilation. But I really don't understand why you want to use sudo if everything is working

[clamav-users] freshclam vs sudo freshclam

2018-08-20 Thread Michael Newman
If I run freshclam as a non-privileged user, it runs fine with no warnings or error messages. Here’s the last line of the response: Database updated (6622193 signatures) from db.TH.clamav.net (IP: 104.16.188.138) But, if I run sudo freshclam it fails with numerous errors, some of which are show

Re: [clamav-users] Help With clamscan vs clamdscan

2018-08-20 Thread Maarten Broekman
For clamdscan to work you need to enable LocalSocket at the very least. On Mon, Aug 20, 2018 at 5:32 PM Michael Newman wrote: > > On Aug 20, 2018, at 23:00, Al Varnell wrote: > > > Please post the results of the following Terminal Command: > > sudo clamconf > > > MrMuscle:~ mnewman$ sudo clamc

Re: [clamav-users] Help With clamscan vs clamdscan

2018-08-20 Thread Michael Newman
> On Aug 20, 2018, at 23:00, Al Varnell wrote: > > Please post the results of the following Terminal Command: > > sudo clamconf MrMuscle:~ mnewman$ sudo clamconf Password: Checking configuration files in /opt/local/etc Config file: clamd.conf --- BlockMax disabled PreludeEn

Re: [clamav-users] ClamAV signature update sync errors have gotten worse

2018-08-20 Thread Joel Esler (jesler)
Thank you. We have to make adjustments very slowly to not disrupt anyone. Cloudflare has helped us save 2 PB in the last month, delivering updates an average of 39% faster. We are seeing excellent results. > On Aug 18, 2018, at 1:09 AM, Paul Kosinski wrote: > > Joel, > > Still lots of del

Re: [clamav-users] Help With clamscan vs clamdscan

2018-08-20 Thread Hajo Locke
Hello, Am 20.08.2018 um 13:05 schrieb Matus UHLAR - fantomas: On 20.08.18 17:55, Michael Newman wrote: clamd is running: MrMuscle:~ mnewman$ ps -A | grep -m1 clamd 31610 ?? 0:10.14 clamd When I run clamscan it works and detects a known problem. But, when I run clamdscan on the same d

Re: [clamav-users] Help With clamscan vs clamdscan

2018-08-20 Thread Matus UHLAR - fantomas
On 20.08.18 17:55, Michael Newman wrote: clamd is running: MrMuscle:~ mnewman$ ps -A | grep -m1 clamd 31610 ?? 0:10.14 clamd When I run clamscan it works and detects a known problem. But, when I run clamdscan on the same directory, it just instantly stops without scanning. What have

Re: [clamav-users] Help With clamscan vs clamdscan

2018-08-20 Thread Maarten Broekman
Check the logs and config files. Clamscan loads the databases itself before running. It does not need clamd to be running in order to work. Clamdscan attempts to use a socket to talk with clamd for the scanning of files. If there is an error, one of two things is happening: Either the permission

Re: [clamav-users] Help With clamscan vs clamdscan

2018-08-20 Thread Al Varnell
Please post the results of the following Terminal Command: sudo clamconf -Al- On Mon, Aug 20, 2018 at 03:55 AM, Michael Newman wrote: > Mac 10.13.6 > > clamd is running: > > MrMuscle:~ mnewman$ ps -A | grep -m1 clamd > 31610 ?? 0:10.14 clamd > > When I run clamscan it works and detect

[clamav-users] Help With clamscan vs clamdscan

2018-08-20 Thread Michael Newman
Mac 10.13.6 clamd is running: MrMuscle:~ mnewman$ ps -A | grep -m1 clamd 31610 ?? 0:10.14 clamd When I run clamscan it works and detects a known problem. But, when I run clamdscan on the same directory, it just instantly stops without scanning. What have I done wrong? MrMuscle:~ mnew