http://oss.netfarm.it/clamav/
-Original Message-
From: supp...@declude.com [mailto:supp...@declude.com] On Behalf Of Gary
Steiner
Sent: Wednesday, November 24, 2010 12:32 PM
To: declude.virus@declude.com
Subject: [Declude.Virus] ClamAv / ClamWin with Declude
What version or port of
What version or port of ClamAV are you using with Declude? I've been
reading on the SmarterTools forums about the problems with ClamWin, and was
wondering if the majority are using this port or a different one?
SmarterTools has been referring people to this link:
http://www.h-online.com/open/ne
lf Of Matt
Sent: Thursday, April 29, 2010 6:05 PM
To: declude.virus@declude.com
Subject: Re: [Declude.Virus] ClamAV
Michael,
I created a step-by-step guide a little over a year ago for the proper
installation. It's pretty simple to do. I can't say however if the steps
have changed i
Michael Cummins
*From:* supp...@declude.com [mailto:supp...@declude.com] *On Behalf Of
*Andy Schmidt
*Sent:* Thursday, April 29, 2010 3:14 PM
*To:* declude.virus@declude.com
*Subject:* RE: [Declude.Virus] ClamAV
There really is no need for ClamAid, because the recent builds
(including oss.netfarm.i
t
General and Non-Emergency support ticket:
https://www.skywaves.com/content/secure/support_ticket.htm
From: "Michael Cummins"
Sent: Thursday, April 29, 2010 3:02 PM
To: declude.virus@declude.com
Subject: RE: [Declude.Virus] ClamAV
In case
a trail here in the archives in
case it helps someone else. :)
- Michael Cummins
From: supp...@declude.com [mailto:supp...@declude.com] On Behalf Of Andy
Schmidt
Sent: Thursday, April 29, 2010 3:14 PM
To: declude.virus@declude.com
Subject: RE: [Declude.Virus] ClamAV
There real
Virus.cfg, ClamAid
probably makes things unnecessary complicated...
From: supp...@declude.com [mailto:supp...@declude.com] On Behalf Of Michael
Cummins
Sent: Thursday, April 29, 2010 2:50 PM
To: declude.virus@declude.com
Subject: RE: [Declude.Virus] ClamAV
In case this is helpful for someone
In case this is helpful for someone else that isn't so great at rolling
their own Clams from the source code:
First, I installed ClamAID using the default options. (SmarterMail /
Declude install for me)
http://www.armresearch.com/tools/arm/clamAID.jsp
This installs Clam 0.92, wraps it
- to integrate the ClamLib and
eliminate any command line needs).
Best Regards,
Andy
-Original Message-
From: supp...@declude.com [mailto:supp...@declude.com] On Behalf Of Cert
Sent: Wednesday, April 28, 2010 7:26 PM
To: declude.virus@declude.com
Subject: Re: [Declude.Virus] ClamAV
Hello!
Hello!
The "sherpya" Clam port at oss.netfarm.it is very easy to build and use,
and there are only about 10 lines of code in 2 or 3 modules where you
need to add a "VirusName->" prefix before the actual name of the virus
so Declude can pick it up in the report file. I just mod the code and
re
Generally, ClamD catches most viruses that AVG misses (during those times
when it actually runs), and McAfee catches the occasional virus that ClamD
misses. ClamD downloads updates automatically (using the FreshClam).
I found the http://oss.netfarm.it/clamav build very useful. I don't recall
an
"Native Windows Support: ClamAV will now build natively under Visual Studio.
This will allow 3rd Party application developers on Windows to easily
integrate LibClamAV into their applications."
http://www.clamav.net/lang/en/2010/04/02/announcing-clamav-0-96/
Also:
"ClamAV for Windows Released"
eware" to
reformat the Report file before feeding it to Declude. If you don't
care
about names, then this isn't necessary.
Best Regards,
Andy
-Original Message-
From: supp...@declude.com [mailto:supp...@declude.com] On Behalf Of
David
Dodell
Sent: Monday, June 08, 2009 12:
to
reformat the Report file before feeding it to Declude. If you don't care
about names, then this isn't necessary.
Best Regards,
Andy
-Original Message-
From: supp...@declude.com [mailto:supp...@declude.com] On Behalf Of David
Dodell
Sent: Monday, June 08, 2009 12:26 AM
To:
I'm using an older version of ClamAV that needs to be updated as a
backup scanner.Unfortunately, it is no longer being developed.
Has anyone tried the ClamID from ArmResearch or any other version of
ClamAV that is current that works with Declude?
David
---
This E-mail came from the De
had
> success with http://www.clamwin.com/ ?
>
>
>
>
> Original Message
> > From: "Scott Fisher"
> > Sent: Monday, December 29, 2008 7:39 AM
> > To: declude.virus@declude.com
> > Subject: RE: [Declude.Virus] ClamAv
> From: "Scott Fisher"
> Sent: Monday, December 29, 2008 7:39 AM
> To: declude.virus@declude.com
> Subject: RE: [Declude.Virus] ClamAv with Declude
>
> I use the runclamscan program to call clamav. Here's my virus.cfg lines
>
> SCANFILE1 c:\clamav\runcla
odell
Sent: Sunday, December 28, 2008 11:29 AM
To: declude.virus@declude.com
Subject: [Declude.Virus] ClamAv with Declude
On Dec 28, 2008, at 8:36 AM, Hirthe, Alexander wrote:
> http://www.mail-archive.com/declude.virus@declude.com/msg14082.html
Ok, thanks for the excellent beginning ... I
On Dec 28, 2008, at 10:28 AM, David Dodell wrote:
(2) In my virus.cfg I have
scanfile c:\imail\declude\clamav\clamdscan.exe --quiet -l report.txt
viruscode 1
report FOUND
(3) In my logs it reports
Could Not Parse String FOUND in report.txt
Error 2 in virus scanner 1
Scanned: Error in Virus
On Dec 28, 2008, at 8:36 AM, Hirthe, Alexander wrote:
http://www.mail-archive.com/declude.virus@declude.com/msg14082.html
Ok, thanks for the excellent beginning ... I'm using the Clamav-win32
from sosdg.org
Freshclam installed all the latest files just fine
Got it all installed ... but s
ksma" <[EMAIL PROTECTED]>
> Sent: Thursday, June 05, 2008 1:45 PM
> To: Declude.Virus@declude.com
> Subject: [Declude.Virus] ClamAV
>
> Hi,
>
> Been using the old F-prot v3 as a second scanner but I disabled it today. As
> the new F-prot 6 scanner is not allowed
an uses
the Daemon if it's available.
Btw: I tried it right now, "ClamDscan C:\temp" and "ClamScan C:\temp"
ClamDscan takes 0.375 seconds, ClamScan 10.359.
Alex
Von: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Im Auftrag von Bonno Bloksma
Gesendet: Donnerstag, 5.
Hi,
Been using the old F-prot v3 as a second scanner but I disabled it today. As
the new F-prot 6 scanner is not allowed with Declude, well sort of but I don't
want to pay that mucht ;-) I wanted to use ClamAV asn an extra scanner.
In the past it was a bit dificult I seem to remember but Is
would be the error, look for thirdparty\runclamscan in your ClamDir,
this is the easy way to run ClamD.
Alex
> -Ursprüngliche Nachricht-
> Von: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Im Auftrag von
> Brian T
> Gesendet: Freitag, 28. März 2008 18:38
> An: declude.vir
I recently switch my antivirs over to ClamAV and now my virus log is showing
the following errors:
03/28/2008 12:56:17.781 q22fc01b601b4.smd Virus scanner 1 reports exit
code of 40
03/28/2008 12:56:19.984 q22fc01b601b4.smd Could not find report file
C:\IMail\spool\proc\work\D22fc01b60
t; <[EMAIL PROTECTED]>
To: "declude.virus@declude.com"
Sent: 7/14/07 3:42 AM
Subject: [Declude.Virus] ClamAV and Declude problem
Hi All,
We've been testing ClamAV with Declude AVA on our new mail server (running
2006.2). We only have a few mailboxes on this server because we
Hi All,
We've been testing ClamAV with Declude AVA on our new mail server (running
2006.2). We only have a few mailboxes on this server because we're still
testing it. Today, I ran into a problem where the D: drive ran out of space
(100GB). It turns out the d:\temp folder was very large (90
John Shacklett" <[EMAIL PROTECTED]>
> Sent: Tuesday, June 26, 2007 8:25 AM
> To: Declude.Virus@declude.com
> Subject: [Declude.Virus] ClamAV with a strong aroma
>
> Is anyone using ClamWin 0.90.2.1 with Declude AV? I was, using the following
> line from the virus.cfg:
>
>
e.com
> Subject: [Declude.Virus] ClamAV with a strong aroma
>
> Is anyone using ClamWin 0.90.2.1 with Declude AV? I was, using the
> following
> line from the virus.cfg:
>
> SCANFILE4 C:\Progra~1\ClamWin\bin\clamscan.exe --verbose
> --database=C:\Docume~1\AllUse~1\.clamwin\db
> --
Is anyone using ClamWin 0.90.2.1 with Declude AV? I was, using the following
line from the virus.cfg:
SCANFILE4 C:\Progra~1\ClamWin\bin\clamscan.exe --verbose
--database=C:\Docume~1\AllUse~1\.clamwin\db
--tempdir=C:\PROGRA~1\IPSWITCH\IMAIL\Declude\Scanners\ClamAV --no-summary -l
report.txt
All o
; <[EMAIL PROTECTED]>
> Sent: Wednesday, April 25, 2007 8:33 PM
> To: declude.virus@declude.com
> Subject: RE: [Declude.Virus] ClamAV lstat() failed. ERROR
>
> Gary,
>
> I'm not sure I understand your point.
>
> What you define in Virus.cfg, e.g.:
>
&g
PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Gary
Steiner
Sent: Wednesday, April 25, 2007 6:39 PM
To: declude.virus@declude.com
Subject: [Declude.Virus] ClamAV lstat() failed. ERROR
In pursuing the problem of the new worm with a password-protected RAR file,
I found a problem with ClamAV.
I
Overflow Queue Monitoring, SURBL/URI integration, MRTG
Integration, and Log Parsers.
- Original Message -
From: "Gary Steiner" <[EMAIL PROTECTED]>
To:
Sent: Wednesday, April 25, 2007 6:39 PM
Subject: [Declude.Virus] ClamAV lstat() failed. ERROR
In pursuing the problem of t
In pursuing the problem of the new worm with a password-protected RAR file, I
found a problem with ClamAV.
I'm running the SOSDG ClamAV Windows port version 0.90.2-2 (along with runclamd
and runclamscan).
Declude uses the following string:
C:\clamav-devel\bin\clamdscan.exe --quiet -l report.txt
o: declude.virus@declude.comSubject: RE: [Declude.Virus] ClamAV 0.90.1-2 problemsA new version (0.90.1-3) was posted on the SOSDG web site.
Bri Bruns told me that the --mbox parameter no longer works, so you should
remove it from the line in your virus.cfg file before installing 0.90.1-3.
Gary
[EMAIL PROTECTED]>
> Sent: Tuesday, March 13, 2007 3:13 PM
> To: declude.virus@declude.com
> Subject: RE: [Declude.Virus] ClamAV 0.90.1-2 problems
>
> The following was just posted to clamav-announce:
>
>
>
> Original Message
> > From: "B
The following was just posted to clamav-announce:
Original Message
> From: "Bri Bruns" <[EMAIL PROTECTED]>
> Sent: Tuesday, March 13, 2007 2:43 PM
> To: [EMAIL PROTECTED]
> Subject: [clamav-announce] Problems with ClamAV/SOSDG For WIndows 0.90.1-1
> and -2
>
> Okay, been gett
rsion corrects some build problems and incorrect
linkage to cygclamav1.dll by clamd."
Gary
Original Message
> From: "Mark Reimer" <[EMAIL PROTECTED]>
> Sent: Tuesday, March 13, 2007 11:21 AM
> To: declude.virus@declude.com
> Subject: RE: [D
-6887
-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Nick
Hayer
Sent: Tuesday, March 13, 2007 8:01 AM
To: declude.virus@declude.com
Subject: Re: [Declude.Virus] ClamAV 0.90.1-2 problems
Exit code of 2 means ClamAV had an error - Is clamd running? will
Exit code of 2 means ClamAV had an error - Is clamd running? will
clamdscan.exe work? eg no parameters?
-Nick
Gary Steiner wrote:
Ever since I upgraded to ClamAV 0.90.1-2 (the SOSDG windows port), I've been
unable to get it to work. The Declude log files show an error like this:
03/12/2007
Ever since I upgraded to ClamAV 0.90.1-2 (the SOSDG windows port), I've been
unable to get it to work. The Declude log files show an error like this:
03/12/2007 19:17:29.359 62376245 Vulnerability flags = 861
03/12/2007 19:17:29.359 62376245 MIME file: [text/html][7bit; Length=429
Checksum=3809
FYI - List of AV Vulns that were listed in the SANS Vulnerability Alert that
affect most of us one way or another.
Also, there was a McAfee vulnerability but it was for thier linux based version.
06.50.31 CVE: CVE-2006-5874
Platform: Cross Platform
Title: Clam Anti-Virus MIME Attachments Denia
> -Original Message-
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On
> Behalf Of george kulman
> Sent: Friday, September 29, 2006 6:06 PM
> To: declude.virus@declude.com
> Subject: RE: [Declude.Virus] ClamAV Exit codes
>
>
> Strange. It sounds like a reso
0:58 AM
> To: declude.virus@declude.com
> Subject: RE: [Declude.Virus] ClamAV Exit codes
>
> Thank you
>
> The strange thing is that the error doesn't appeared constantly at a
> certain
> point. At 06:50PM there was the first dozen result codes 2. Then the next
> one
de.com
> Subject: RE: [Declude.Virus] ClamAV Exit codes
>
>
> Markus,
>
> Here are the Return Codes from the ClamAV Documentation.
>
> George
>
> >From http://www.clamav.net/doc/0.88.4/man/clamdscan.1
>
> .SH "RETURN CODES"
> .LP
> 0
n Behalf Of Markus
> Gufler
> Sent: Friday, September 29, 2006 5:59 AM
> To: declude.virus@declude.com
> Subject: [Declude.Virus] ClamAV Exit codes
>
> Does anyone know what exit codes ClamAV has and what they mean?
>
> >From 2006-09-27 06:50PM on I can see a huge number of
>
> Failure I do believe, probably ClamD is not running?
Correct. Thank you.
Markus
---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".The archives can be found
at http://www.mail-archive
Failure I do believe, probably ClamD is not running?
-Nick
Markus Gufler wrote:
Does anyone know what exit codes ClamAV has and what they mean?
>From 2006-09-27 06:50PM on I can see a huge number of
"Virus scanner 2 reports exit code of 2"
...in the virus-logfile.
Markus
---
This E-mail
Does anyone know what exit codes ClamAV has and what they mean?
>From 2006-09-27 06:50PM on I can see a huge number of
"Virus scanner 2 reports exit code of 2"
...in the virus-logfile.
Markus
---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [
eclude.com
> Betreff: [Declude.Virus] CLAMAV - 88.3-1 - 7/11/2006 Release
>
> I noticed a new build from the SOSDG group has been released (88.3-1).
> http://www.sosdg.org/clamav-win32/index.php
>
> Anyone running it yet?
>
> Darrell
> -
9:18 PM
> To: Declude.Virus@declude.com
> Subject: [Declude.Virus] CLAMAV - 88.3-1 - 7/11/2006 Release
>
>
> I noticed a new build from the SOSDG group has been released (88.3-1).
> http://www.sosdg.org/clamav-win32/index.php
>
>
I noticed a new build from the SOSDG group has been released (88.3-1).
http://www.sosdg.org/clamav-win32/index.php
Anyone running it yet?
Darrell
Check out http://www.invariantsystems.com for utilities for Declude And
Imail
I have noticed now with 4x that if ClamAv is the first scanner it fails
- it cannot find the file to scan. However it it is moved to the 2
'hole' or 3 'hole' - identical config otherwise - it works like a charm.
Does any one else see this anomolie?
-Nick
---
This E-mail came from the Declud
Only if he is running an older version of Declude, which does not include
the built-in AVG scanner, which runs as scanner 0.
Bill
- Original Message -
From: "Goran Jovanovic" <[EMAIL PROTECTED]>
To:
Sent: Friday, July 14, 2006 12:13 PM
Subject: RE: [Declude.Virus] Cla
AVG is my first one (it's everybody's first one, it's built in).
Original Message
> From: "Goran Jovanovic" <[EMAIL PROTECTED]>
> Sent: Friday, July 14, 2006 3:26 PM
> To: declude.virus@declude.com
> Subject: RE: [Declude.Virus] Cla
, VIRUSCODE2, REPORT2 to 3. That might help
Goran Jovanovic
Omega Network Solutions
-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Gary
Steiner
Sent: Friday, July 14, 2006 1:16 PM
To: declude.virus@declude.com
Subject: [Declude.Virus] ClamAV error
I recently
I recently installed ClamAv as my third scanner after AVG and F-Prot. For some
reason it indicates an error related to the attachment when it detects a virus
(Attachment=[Unknown: Err]). Here is an example from the Declude virus log
file:
07/13/2006 19:32:18.843 366626185 Vulnerability flags
& Computer Services
519-741-1222
> -Original Message-
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED] On Behalf Of Harry Vanderzand
> Sent: Thursday, March 09, 2006 3:22 PM
> To: Declude.Virus@declude.com
> Subject: RE: [Declude.Virus] ClamAV leaving locked fil
Vanderzand
inTown Internet & Computer Services
519-741-1222
> -Original Message-
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED] On Behalf Of Harry Vanderzand
> Sent: Wednesday, March 08, 2006 1:35 PM
> To: Declude.Virus@declude.com
> Subject: RE: [Declude.Vi
day, March 08, 2006 1:27 PM
> To: Declude.Virus@declude.com
> Subject: [Declude.Virus] ClamAV leaving locked files?
>
> I have a problem with ClamAV apparently leaving locked pdf
> files behind. I get these messages the the virus log:
>
> 03/08/2006 11:50:34.721 262309704382
dnesday, March 08, 2006 12:26 PM
Subject: [Declude.Virus] ClamAV leaving locked files?
I have a problem with ClamAV apparently leaving locked pdf files behind. I
get these messages the the virus log:
03/08/2006 11:50:34.721 262309704382 WARNING: Couldn't remove .vir
directory
e:\SmarterMa
I have a problem with ClamAV apparently leaving locked pdf files behind. I
get these messages the the virus log:
03/08/2006 11:50:34.721 262309704382 WARNING: Couldn't remove .vir directory
e:\SmarterMail\Spool\proc\work\262309704382.vir\: EXTRA FILES THERE. [145]
Error String: [The directory is n
Andrew:
After the post I did the same and it is working great. I have done
as Scott has stated.
I review all the messages and none of our Declude filters are being
triggered anymore. All the phishing attempts used to get caught by our
filters.. with ClamAV and the phish.ndb all are bein
at it only took about 15
minutes to get it working with a scheduled task to update itself.
- Original Message -
From:
Colbeck,
Andrew
To: Declude.Virus@declude.com
Sent: Wednesday, March 01, 2006 2:46
PM
Subject: RE: [Declude.Virus] ClamAV &
sanesecurity definitio
t: Re: [Declude.Virus] ClamAV &
sanesecurity definitions
I running clamav as one of my scanners. The
SaneSecurity is an additional defintion database named phish.ndb.
I put the phish.ndb into my
c:\clamav-devel\share\clamav folder and it does all of the rest.
- Origina
@declude.com
Sent: Wednesday, March 01, 2006 2:15
PM
Subject: RE: [Declude.Virus] ClamAV &
sanesecurity definitions
Scott,
Are you running ClamAV with the SaneSecurity antiphishing
signatures as an external spam test in Declude Pro, or as an antivirus engine
in Declude Virus
, March 01, 2006 12:06 PMTo:
Declude.Virus@declude.comSubject: [Declude.Virus] ClamAV &
sanesecurity definitions
As a followup on last week's discussions on
the SaneSecurity phish definitions for ClamAv.
ClamAv (without SaneSecurity) caught 273 phish
for me in Februar
As a followup on last week's discussions on
the SaneSecurity phish definitions for ClamAv.
ClamAv (without SaneSecurity) caught 273 phish for
me in February (all 28 days).
SaneSecurity definitions caught 178 phish for me in
the last 8 days of February.
McAfee caught 118 and none after I ins
Is anyone using one of the various Windows ports for ClamAV under W2K3? If so,
which one is best?
Thanks,
Gary Steiner
---
[This E-mail was scanned for viruses by Declude EVA www.declude.com]
---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to
: Friday, February 17, 2006 10:34 PM
Subject: Re: [Declude.Virus] ClamAV Footer ...
Who is Sandy, and how can I get in touch with her?
Matt wrote:
Andrew,
There is no native capability to do this dynamically. Adding a footer is
also a difficult task since it must be integrated properly and
sel
Who is Sandy, and how can I get in touch with her?
Matt wrote:
Andrew,
There is no native capability to do this dynamically. Adding a footer
is also a difficult task since it must be integrated properly and
selectively into multiple MIME segments, and without breaking certain
types of messa
Andrew,
There is no native capability to do this dynamically. Adding a footer
is also a difficult task since it must be integrated properly and
selectively into multiple MIME segments, and without breaking certain
types of messages that rely on strict formating (such as calendaring).
Sandy
Hello all ... I am trying to do the following: On each message scanned
by Declude and ClamAV, I would like to add a footer, specifying that the
message has been scanned and found to be free of any virus, which
version of ClamAV scanned it, which virus database was used, and what
the date of th
Hi
..
I thought this could
be of interest to the group- if you are using ClamAV -0.86.1. Saw this in
a security newsletter.
Regards,_
Kami
*
Widely Deployed Software
*
(1) HIGH: ClamAV Multiple Buffer
Overflows
Affected: ClamAV version 0.86.1
FYI - For those who have not seen this and are running ClamAV.
05.26.8 CVE: CAN-2005-1923
Platform: Cross Platform
Title: ClamAV Cabinet File Parsing Remote Denial of Service
Description: ClamAV is a virus scanning utility. ClamAV is affected by a
remote denial of service issue. ClamAV versions
d for me.
- Original Message -
From: "Hirthe, Alexander" <[EMAIL PROTECTED]>
To:
Sent: Thursday, February 17, 2005 11:34 AM
Subject: [Declude.Virus] ClamAV?
Hello,
I'm getting errors with Zip Files larger than about 10 MB.
In the virus.log:
02/17/2005
D]>
To:
Sent: Thursday, February 17, 2005 11:34 AM
Subject: [Declude.Virus] ClamAV?
> Hello,
>
> I'm getting errors with Zip Files larger than about 10 MB.
>
> In the virus.log:
> 02/17/2005 17:12:03 Qbede796f012201de MIME file: 123.zipxxx [base64;
> Length=13024694
Hello,
I'm getting errors with Zip Files larger than about 10 MB.
In the virus.log:
02/17/2005 17:12:03 Qbede796f012201de MIME file: 123.zipxxx [base64;
Length=13024694 Checksum=1676135806]
02/17/2005 17:12:07 Qbede796f012201de Scanner 3: Virus= Attachment= [6] O
02/17/2005 17:12:07 Qbede796f0122
Manually perform the scan, and look @ the report.txt file.
- Original Message -
From: "Hirthe, Alexander" <[EMAIL PROTECTED]>
To:
Sent: Thursday, February 17, 2005 12:34 PM
Subject: [Declude.Virus] ClamAV?
Hello,
I'm getting errors with Zip Files larger tha
I just received the folloing from the Clam list - there appears to be
an issue with UDP ports and cygwin
-Nick
On 6 Dec 2004 at 9:24, Brian Bruns wrote:
From: "Brian Bruns" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Date sent: Mon, 6 Dec 200
For those that use ClamAV the latest ver appears to be Nov20 - I had
the Oct24 ver which would randomly crash - in this latest ver in the
release notes there is reference to fixing this
-Nick Hayer
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
---
This E-ma
027 - [EMAIL PROTECTED]
>>
>>
>>
>>-Original Message-
>>From: [EMAIL PROTECTED]
>>[mailto:[EMAIL PROTECTED] Behalf Of Jeff Kratka
>>Sent: Friday, November 19, 2004 4:04 PM
>>To: [EMAIL PROTE
: [Declude.Virus] ClamAv
I just started to try out Clam AV and so far it's been catching more than
F-Prot did. Is there a switch to have Declude add the virus name to the
Declude logs.My config in the virus .cfg is
SCANFILE C:\imail\declude\runclamscan.exe log=1
C:\clamav-devel\bin\clamdscan.exe --
: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] Behalf Of Jeff Kratka
Sent: Friday, November 19, 2004 4:04 PM
To: [EMAIL PROTECTED]
Subject: [Declude.Virus] ClamAv
I just started to try out Clam AV and so far it's been catching more than
F-Prot did. Is there a switch to have Declude add the virus
I just started to try out Clam AV and so far it's been catching more than
F-Prot did. Is there a switch to have Declude add the virus name to the
Declude logs.My config in the virus .cfg is
SCANFILE C:\imail\declude\runclamscan.exe log=1
C:\clamav-devel\bin\clamdscan.exe --quiet --mbox -l report.t
someone mentioned yesterday.
John
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On
Behalf Of Matt
Sent: Tuesday, November 16, 2004
10:21 AM
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus]
ClamAV scan time
Terry,
Maybe if you could clarify. You are running ClamAV in
Terry,
Maybe if you could clarify. You are running ClamAV in daemon mode, am
I correct?
My point was that as of several months ago, the non-daemon installation
was a processor hog and took a lot of time compared to F-Prot, the best
performing scanner. Things might have changed since then.
> ClamAV when not run in daemon mode is very slow in comparison to other
> virus scanners. If your server is getting pushed to it's limits, the
> first sign will likely be their vir directories piling up as a result of
> ClamAV not finishing within the specified time configured in Declude Virus
size. SO I left it to see if other changes helped -
# Close the connection if this limit is exceeded.
StreamMaxLength 3M
-Nick
From: "John Carter" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Subject: [Declude.Virus] Clam
ClamAV when not run in daemon mode is very slow in comparison to other
virus scanners. If your server is getting pushed to it's limits, the
first sign will likely be their vir directories piling up as a result of
ClamAV not finishing within the specified time configured in Declude Virus.
I pla
I have noticed this problem with large files, usually TIFFs.
No solutions though...
-- Original Message --
From: "John Carter" <[EMAIL PROTECTED]>
Reply-To: [EMAIL PROTECTED]
Date: Mon, 15 Nov 2004 16:44:35 -0600
>Has anyone using ClamAV had problems with
Has anyone using ClamAV had problems with it taking longer than 60 seconds
to run? After installing it last week and working out a few problems, it
has done well. Today I noticed a number of *.vir folders left on the drive.
The VIR*.log showed that ClamAV was not completing in 60 seconds. This ha
FYI:
Came in this morning to find about 30 false
positives from Clam-AV.
They were all were all on the detection of
Exploit.JPEG.Comment.1
They started about 9:45 yesterday morning and were
continuing through 8:25 this morning when I turned off Clam-AV.
I see this update was posted th
ClamAV is no longer using the old style database as of Sep 1 2004.
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declud
On a related topic, during my testing I found that while I was logged into
my server with pcANYWHERE instead of Terminal Services, I kept seeing CMD
windows pop up when AVG was scanning despite the /silent switch. I don't
ever recall seeing that before, but it's rare that I log in with
pcANYW
Thanks for the explanation. I was hoping for something miraculous that
might be of benefit, but it looks like Declude does all of this already.
On a related topic, during my testing I found that while I was logged
into my server with pcANYWHERE instead of Terminal Services, I kept
seeing CMD
> Terry, if you could explain the demime thing, that would be appreciated.
I'm sorry - I've been tied up all day working on name server issues.
The application I referenced earlier was an xmail mail server.
Declude is not available for it so I wrote my own program that is
called by xmail for mess
PROTECTED]] On Behalf Of Terry Fritts
Sent: Thursday, April 01, 2004 6:54 AM
To: Charles Frolick
Subject: Re[2]: [Declude.Virus] clamav
BTW, run clamd.exe and clamdscan.exe and notice a difference in speed
Charles,
Did you start clamd and then leave the server logged on?
Terry
goLink.net
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Terry Fritts
Sent: Thursday, April 01, 2004 6:54 AM
To: Charles Frolick
Subject: Re[2]: [Declude.Virus] clamav
> BTW, run clamd.exe and clamdscan.exe and notice a difference in speed
Charles,
> BTW, run clamd.exe and clamdscan.exe and notice a difference in
> speed
Charles,
Did you start clamd and then leave the server logged on?
Terry
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
---
This E-mail came from the Declude.Virus mailing list. To
u
1 - 100 of 114 matches
Mail list logo