Clam AntiVirus ClamAV, a GPL anti-virus toolkit for UNIX 2009-10-05T12:33:47Z WordPress http://www.clamav.net/feed/atom/ webmaster <![CDATA[End of Life Announcement: ClamAV 0.94.x]]> http://www.clamav.net/2009/10/05/end-of-life-announcement-clamav-094x/ 2009-10-05T12:33:47Z 2009-10-05T12:26:09Z All ClamAV releases older than 0.95 are affected by a bug in freshclam which prevents incremental updates from working with signatures longer than 980 bytes.
You can find more details on this issue on our bugzilla (see bug #1395)

This bug affects our ability to distribute complex signatures (e.g. logical signatures) with incremental updates.

So far we haven’t released any signatures which exceed this limit.
Before we do we want as many users as possible to upgrade to the latest version of ClamAV.

Starting from 15 April 2010 our CVD will contain a special signature which disables all clamd installations older than 0.95 – that is to say older than 1 year.

This move is needed to push more people to upgrade to 0.95 .
We would like to keep on supporting all old versions of our engine, but unfortunately this is no longer possible without causing a disservice to people running a recent release of ClamAV.
The traffic generated by a full CVD download, as opposed to an incremental update, cannot be sustained by our mirrors.

We plan to start releasing signatures which exceed the 980 bytes limit on May 2010.

We recommend that you always run the latest version of ClamAV to get optimal protection, reliability and performance.

Thanks for your cooperation!

]]>
0
webmaster <![CDATA[Sourceforge CCA ‘09: watch the video!]]> http://www.clamav.net/2009/06/23/sourceforge-cca-09-watch-the-video/ 2009-06-24T12:52:05Z 2009-06-23T14:08:53Z Vote for us!

Yesterday Sourceforge announced the finalists for Community Choice Awards 2009. We are glad to let you know that ClamAV was among the 10 projects that collected more nominations in the Best tool for sysadmin category!

]]>
Yesterday Sourceforge announced the finalists for Community Choice Awards 2009.
We are glad to let you know that ClamAV was among the 10 projects that collected more nominations in the Best tool for sysadmin category!
We really appreciate your support and we are happy that you find our project useful.

It’s now time to select the winner among the 10 finalists in each category.
Head over to Sourceforge website and cast your vote! Our project is listed under the Best tool for sysadmin category:

Vote for us!

We prepared a video message for all of you, to say thanks for everything you did to make this project grow: be it submit a malware sample, report a false positive, open a bug report, edit the wiki, or answer a message on our mailing-lists:

[Share it on Facebook]

Let us know if you enjoy the video :) maybe we’ll try to make more in the future.

More information on Sourceforge Community Choice Awards 2009 is available at http://sf.net/cca .

]]>
0
webmaster <![CDATA[FISL 10 Conference in Brazil]]> http://www.clamav.net/2009/06/11/fisl-10-conference-in-brazil/ 2009-06-11T19:46:57Z 2009-06-11T19:46:57Z ClamAV’s own Tomasz Kojm will be giving two talks at the FISL 10 Conference, June 24th through 27th in Porto Alegre Brazil. Abstracts and times for Tomasz’ presentations are below. If you’re attending please stop by and say hi.

June 24 – 2:00pm
“ClamAV Basics, Common Usage, Tips & Tricks”

The presentation will provide a broad introduction to Clam AntiVirus, its main features and advantages. Tomasz will focus his remarks on the following aspects of ClamAV:
Software design and core components (libclamav, clamd, clamscan, clamdscan, freshclam);
Installation
Virus detection techniques
Detection of Phishing and Potentially Unwanted Applications
Clamscan, clamd & clamdscan in practice
Configuration tips and best practices
Troubleshooting

June 26 – 2:00pm
“Introduction to the ClamAV Engine and Signatures.”

The presentation, aimed toward System Administrators and advanced users, will be an introduction to ClamAV internals. Tomasz will discuss how the scan engine works and how to create various types of signatures, including phishing and logical signatures. Although the official virus databases are released on a regular basis by ClamAV Researchers, the ability to use in-house or 3rd party developed signatures makes the system highly flexible. Tomasz will also discuss the basic API and how it can be used to perform file scanning.

]]>
0
webmaster <![CDATA[SourceForge.net 2009 Community Choice Awards nominations]]> http://www.clamav.net/2009/05/18/229/ 2009-05-18T11:13:30Z 2009-05-18T11:12:43Z SourceForge.net Community Choice Awards just opened and we hope to receive your help to nominate ClamAV to one or more categories.
Once all final nominees have been decided, everyone will be able to vote for the projects of their choice in each category. We hope to be nominated in the category “Best Tool or Utility for SysAdmins”.

]]>
0
webmaster <![CDATA[DojoSec June briefings]]> http://www.clamav.net/2009/05/21/dojosec-june-briefings/ 2009-05-21T15:07:35Z 2009-05-17T15:03:47Z Alain Zidouemba will give a talk at DojoSec on the topic: What to do with the unknown.
Here are the meeting details:
Date: June 4, 2009
Time: 6:00 – 9:30 PM
Entry Fee: $1
Location: Capitol College – Avrum Gudelsky Memorial Auditorium

Register: http://www.dojosec.com/?page_id=37
Directions: http://www.capitol-college.edu/visit-campus/directions-campus

Abstract

Clam AntiVirus is an open source anti-virus toolkit for UNIX systems. The main purpose of this software lies in the integration with mail servers enabling mail attachment scanning before the end user receives a virus. Like other anti-virus software, the engine for ClamAV has pattern matching technology at it’s heart. Updates to the malware signatures are released on a regular basis by ClamAV Researchers. When no signatures are available however, or when updates are not coming fast enough the only option is to create signatures. Fortunately, ClamAV signatures are open and this enables the administrator to fill in the gap for themselves.


About Alain Zidouemba

Alain Zidouemba was born in Ouagadougou, Burkina Faso. He studied Mathématiques Supérieures and Mathématiques Spéciales at the Lycée Jacques Amyot in France and Electrical and Computer Engineering at Howard University in the US. He worked in the area of network modelling and simulation at OPNET Technologies before taking a position at PestPatrol as a Spyware researcher. He later joined Computer Associates to work on intrusion prevention and behavioral malware analysis. Alain recently became part of the Vulnerability Research Team (VRT) at Sourcefire and performs research in the areas of intrusion prevention and anti-malware.

]]>
0
webmaster <![CDATA[ClamAV Users’ Webcast]]> http://www.clamav.net/2009/02/09/clamav-users%e2%80%99-webcast/ 2009-02-20T17:28:17Z 2009-02-09T10:48:12Z The next ClamAV® Users’ Webcast will be on Wed 4th March at 1800UTC: 10 AM PST, 1 PM EST, 6 PM GMT, 7 PM CEST. The talk, given by Alain Zidouemba of Sourcefire will be an introduction to writing ClamAV Signatures. The talk will cover about an hour. The talk will be technically advanced, and is aimed toward Systems Administrators and developers.

Abstract

ClamAV is an open source anti-virus toolkit for UNIX systems. The main purpose of this software lies in the integration with mail servers enabling mail attachment scanning before the end user receives a virus. As with other anti-virus software, the engine for ClamAV has pattern matching technology at its heart. Updates to the malware signatures are released on a regular basis by ClamAV Researchers.
However, what if no signatures are available to detect a given piece of malware, or if updates are not coming fast enough? Fortunately, ClamAV signatures are “open” and this enables the administrators to fill in the gap for themselves. This presentation covers the methods behind creating effective malware signatures for ClamAV and introduces the new malware “logical signature” format that makes it even easier to write custom detections.
The event will finish with a Q&A session of about 15 minutes.

About the Presenter

Alain Zidouemba studied Mathématiques Supérieures and Mathématiques Spéciales at the Lycée Jacques Amyot in France and Electrical and Computer Engineering at Howard University in the United States. He worked in the area of network modelling and simulation at OPNET Technologies before taking a position at PestPatrol, Inc. as a Spyware Researcher. He later joined Computer Associates to work on intrusion prevention and behavioural malware analysis. Alain is a member of the Vulnerability Research Team (VRT) at Sourcefire and performs research in the areas of intrusion prevention and anti-malware.

How to Hear The Presentation

To register for this webinar please visit https://sourcefire.webex.com/sourcefire/onstage/g.php?d=798010302&t=a.
After you have registered you will receive an email that will contain the instructions on how to listen to the webinar. For most people the procedure is to visit a URL, which will be given, enter in an password (the event password is clamav) and then either listen on the your computer’s speakers, or dial-in to listen over the telephone. The interface you get on the PC will be the same whichever audio method you choose.
The phone numbers for the U.S. and Canada are 866-469-3239 (free), 1-650-429-3300 (charged). To see the worldwide call-in numbers please visit https://sourcefire.webex.com/sourcefire/globalcallin.php?serviceType=EC&ED=111325642&tollFree=1.
To find out about the toll-free dialling restrictions: http://www.webex.com/pdf/tollfree_restrictions.pdf.
The session will be archived and available later from www.clamav.net.

]]>
0
webmaster <![CDATA[Conficker aka Downadup]]> http://www.clamav.net/2009/01/29/conficker-aka-downadup/ 2009-01-29T13:34:43Z 2009-01-29T06:31:58Z Some of you may have heard of a current major outbreak of a virus known as Downadup that has been reported at http://news.bbc.co.uk/1/hi/technology/7842013.stm and http://news.bbc.co.uk/1/hi/technology/7832652.stm. It has been estimated that move than 9 million PCs are infected across the world.

ClamAV detects Downadup, also known as Conficker, as Worm.Downadup. Once on a system it downloads components that ClamAV detects as members of the Trojan.Downloader- family of signatures.

The virus primarily exploits MS08-067; it can also spread through USB sticks. Since the virus is not spread by email we don’t expect to see much activity in our core user-base, which tends to use ClamAV to scan emails. We are, nevertheless, keeping an eye out for it through freshclam’s statistics gathering system – we are yet to see any obvious spike of activity from it. If we hear anything we’ll let you know.

]]>
0
webmaster <![CDATA[500,000 Signatures and Counting]]> http://www.clamav.net/2009/01/27/500000-signatures-and-counting/ 2009-01-27T20:23:55Z 2009-01-27T20:23:55Z Today, 27th January 2009, ClamAV’s signature team investigated and identified Trojan.Agent-70954, the 500,000th entry in its database. Well done to all the team for working so hard to produce a quality database.
From time to time we are asked to keep the size of the database down by trimming old signatures; but, as the statistics-gathering program has shown, old viruses never die. SomeFool (a.k.a Netsky) is still alive and kicking 5 years after the ClamAV team spotted the first variants! Today two variants of that virus are in the top 10 most active malware amongst our users that send us statistics.

]]>
0
webmaster <![CDATA[ClamAV twitter feed available]]> http://www.clamav.net/2008/11/10/clamav-twitter-feed-available/ 2008-11-10T18:35:11Z 2008-11-10T18:35:11Z Notifications of ClamAV signature updates are now available via our
Twitter feed at http://twitter.com/clamav. The notifications include information about the number of signatures added and the total number of signatures in the ClamAV database.
We hope to include other information on that feed later so please feel free to let us know
suggestions, but remember that “twittiquette” means that we don’t wish to flood the feed with
too much information.

]]>
0
webmaster <![CDATA[ClamAV 0.94.1 released]]> http://www.clamav.net/2008/11/03/clamav-0941-released/ 2008-11-17T08:55:10Z 2008-11-03T08:51:09Z There is one new feature in this release. This feature allows ClamAV users optionally to submit statistics to us about what they detect in the field. We will then use this data to determine what types of Malware/Viruses are the most detected in the field and in what geographic area they are.
It closes the following bugs from http://bugs.clamav.net:

684,777, 828, 832, 954, 1046, 1085, 1092, 1098, 1135, 1137, 1145, 1150 , 1154, 1155, 1157, 1158, 1160, 1162, 1165, 1174, 1179, 1181, 1184, 1185, 1186, 1187, 1189, 1192, 1196, 1197, 1199, 1201, 1203, 1204, 1205, 1210 , 1211, 1212, 1213, 1216, 1217, 1219, 1221

For more details, please refer to Whats New in 0.94.1.

]]>
0