Re: [clamav-users] Probably something simple but new to ClamAV

2019-06-04 Thread SCOTT PACKARD via clamav-users
clamscan -V is all they care about. > -Original Message- > From: clamav-users On Behalf Of > Rodney Stratford via clamav-users > Sent: Tuesday, June 04, 2019 8:29 AM > To: clamav-users@lists.clamav.net > Cc: Rodney Stratford > Subject: [External] [clamav-users] Probably something

Re: [clamav-users] Probably something simple but new to ClamAV

2019-06-04 Thread Graeme Fowler via clamav-users
clamconf will show you what you want (with a lot more detail if required): [graeme@whelk ~]$ clamconf -n | egrep 'version.+sigs' bytecode.cld: version 328, sigs: 94, built on Wed Jan 2 14:42:37 2019 daily.cld: version 25469, sigs: 1587497, built on Mon Jun 3 08:59:22 2019 main.cvd: version 58,

[clamav-users] Probably something simple but new to ClamAV

2019-06-04 Thread Rodney Stratford via clamav-users
I have installed ClamAV in my PCF environment. But security team is looking at how to display the virus signature level is of the AV. Is there a command or a tool that can display this? Any help is appreciated. Thanks ___ clamav-users mailing

[clamav-users] Andr.Dropper.Shedun-6840512-0 false positive ?

2019-06-04 Thread Arnaud Jacques
Hello, For me, Andr.Dropper.Shedun-6840512-0 seems a false positive : VIRUS NAME: /tmp/daily/daily.ldb:Andr.Dropper.Shedun-6840512-0 TDB: Engine:51-255,FileSize:4096-16384,Target:0 LOGICAL EXPRESSION: 0  * SUBSIG ID 0  +-> OFFSET: ANY  +-> SIGMOD: NONE  +-> DECODED SUBSIGNATURE:

[clamav-users] PUA.Andr.Trojan.Mobidash-6888313-0

2019-06-04 Thread Arnaud Jacques
Hello, PUA.Andr.Trojan.Mobidash-6888313-0 is a false positive : VIRUS NAME: /tmp/daily/daily.ldu:PUA.Andr.Adware.Domob-6888036-0 TDB: Engine:51-255,FileSize:1048576-4194304,Target:0 LOGICAL EXPRESSION: 0  * SUBSIG ID 0  +-> OFFSET: ANY  +-> SIGMOD: NONE  +-> DECODED SUBSIGNATURE: