Clam AntiVirus http://www.clamav.net ClamAV, a GPL anti-virus toolkit for UNIX Fri, 02 Apr 2010 13:12:52 +0000 en hourly 1 http://wordpress.org/?v=3.0.1 Announcing ClamAV 0.96 http://www.clamav.net/lang/en/2010/04/02/announcing-clamav-0-96 http://www.clamav.net/lang/en/2010/04/02/announcing-clamav-0-96#comments Fri, 02 Apr 2010 09:40:29 +0000 webmaster http://www.clamav.net/?p=307 ClamAV 0.96 introduces new malware detection mechanisms and other
significant improvements to the scan engine. The key features are:

  • The Bytecode Interpreter: the interpreter built into LibClamAV allows
    the signature writers to create and distribute very complex detection
    routines and remotely enhance the scanner’s functionality

  • Heuristic improvements: improve the PE heuristics detection engine by
    adding support of bogus icons and fake PE header information. In a
    nutshell, ClamAV can now detect malware that tries to disguise itself
    as a harmless application by using the most common Windows program
    icons.

  • Signature Improvements: logical signature improvements to allow more
    detailed matching and referencing groups of signatures. Additionally,
    improvements to wildcard matching on word boundaries and newlines.

  • Support for new archives: 7zip, InstallShield and CPIO. LibClamAV
    can now transparently unpack and inspect their contents.

  • Support for new executable file formats: 64-bit ELF files and OS X
    Universal Binaries with Mach-O files. Additionally, the PE module
    can now decompress and inspect executables packed with UPX 3.0.

  • Support for DazukoFS in clamd

  • Performance improvements: overall performance improvements and
    memory optimizations for a better overall resource utilization
    experience.

  • Native Windows Support: ClamAV will now build natively under
    Visual Studio. This will allow 3rd Party application developers on
    Windows to easily integrate LibClamAV into their applications.

The complete list of changes is available in the ChangeLog file. For
upgrade notes and tips please see:

https://wiki.clamav.net/Main/UpgradeNotes096

]]>
http://www.clamav.net/lang/en/2010/04/02/announcing-clamav-0-96/feed 0
End of Life Announcement: ClamAV 0.94.x http://www.clamav.net/lang/en/2009/10/05/eol-clamav-094 http://www.clamav.net/lang/en/2009/10/05/eol-clamav-094#comments Mon, 05 Oct 2009 12:26:09 +0000 webmaster http://www.clamav.net/2009/10/05/end-of-life-announcement-clamav-094x/ All ClamAV releases older than 0.95 are affected by a bug in freshclam which prevents incremental updates from working with signatures longer than 980 bytes.
You can find more details on this issue on our bugzilla (see bug #1395)

This bug affects our ability to distribute complex signatures (e.g. logical signatures) with incremental updates.

So far we haven’t released any signatures which exceed this limit.
Before we do we want as many users as possible to upgrade to the latest version of ClamAV.

Starting from 15 April 2010 our CVD will contain a special signature which disables all clamd installations older than 0.95 – that is to say older than 1 year.

This move is needed to push more people to upgrade to 0.95 .
We would like to keep on supporting all old versions of our engine, but unfortunately this is no longer possible without causing a disservice to people running a recent release of ClamAV.
The traffic generated by a full CVD download, as opposed to an incremental update, cannot be sustained by our mirrors.

We plan to start releasing signatures which exceed the 980 bytes limit on May 2010.

We recommend that you always run the latest version of ClamAV to get optimal protection, reliability and performance.

Thanks for your cooperation!

]]>
http://www.clamav.net/lang/en/2009/10/05/eol-clamav-094/feed 0
Sourceforge CCA ’09: watch the video! http://www.clamav.net/lang/en/2009/06/23/sf-awards09-video-message http://www.clamav.net/lang/en/2009/06/23/sf-awards09-video-message#comments Tue, 23 Jun 2009 14:08:53 +0000 webmaster http://www.clamav.net/2009/06/23/sourceforge-cca-09-watch-the-video/ Vote for us!

Yesterday Sourceforge announced the finalists for Community Choice Awards 2009. We are glad to let you know that ClamAV was among the 10 projects that collected more nominations in the Best tool for sysadmin category!

]]>
Yesterday Sourceforge announced the finalists for Community Choice Awards 2009.
We are glad to let you know that ClamAV was among the 10 projects that collected more nominations in the Best tool for sysadmin category!
We really appreciate your support and we are happy that you find our project useful.

It’s now time to select the winner among the 10 finalists in each category.
Head over to Sourceforge website and cast your vote! Our project is listed under the Best tool for sysadmin category:

Vote for us!

We prepared a video message for all of you, to say thanks for everything you did to make this project grow: be it submit a malware sample, report a false positive, open a bug report, edit the wiki, or answer a message on our mailing-lists:

[Share it on Facebook]

Let us know if you enjoy the video :) maybe we’ll try to make more in the future.

More information on Sourceforge Community Choice Awards 2009 is available at http://sf.net/cca .

]]>
http://www.clamav.net/lang/en/2009/06/23/sf-awards09-video-message/feed 0
FISL 10 Conference in Brazil http://www.clamav.net/lang/en/2009/06/11/fisl-10-conference-in-brazil http://www.clamav.net/lang/en/2009/06/11/fisl-10-conference-in-brazil#comments Thu, 11 Jun 2009 19:46:57 +0000 webmaster http://www.clamav.net/2009/06/11/fisl-10-conference-in-brazil/ ClamAV’s own Tomasz Kojm will be giving two talks at the FISL 10 Conference, June 24th through 27th in Porto Alegre Brazil. Abstracts and times for Tomasz’ presentations are below. If you’re attending please stop by and say hi.

June 24 – 2:00pm
“ClamAV Basics, Common Usage, Tips & Tricks”

The presentation will provide a broad introduction to Clam AntiVirus, its main features and advantages. Tomasz will focus his remarks on the following aspects of ClamAV:
Software design and core components (libclamav, clamd, clamscan, clamdscan, freshclam);
Installation
Virus detection techniques
Detection of Phishing and Potentially Unwanted Applications
Clamscan, clamd & clamdscan in practice
Configuration tips and best practices
Troubleshooting

June 26 – 2:00pm
“Introduction to the ClamAV Engine and Signatures.”

The presentation, aimed toward System Administrators and advanced users, will be an introduction to ClamAV internals. Tomasz will discuss how the scan engine works and how to create various types of signatures, including phishing and logical signatures. Although the official virus databases are released on a regular basis by ClamAV Researchers, the ability to use in-house or 3rd party developed signatures makes the system highly flexible. Tomasz will also discuss the basic API and how it can be used to perform file scanning.

]]>
http://www.clamav.net/lang/en/2009/06/11/fisl-10-conference-in-brazil/feed 0
SourceForge.net 2009 Community Choice Awards nominations http://www.clamav.net/lang/en/2009/05/18/229 http://www.clamav.net/lang/en/2009/05/18/229#comments Mon, 18 May 2009 11:12:43 +0000 webmaster http://www.clamav.net/2009/05/18/229/ SourceForge.net Community Choice Awards just opened and we hope to receive your help to nominate ClamAV to one or more categories.
Once all final nominees have been decided, everyone will be able to vote for the projects of their choice in each category. We hope to be nominated in the category “Best Tool or Utility for SysAdmins”.

]]>
http://www.clamav.net/lang/en/2009/05/18/229/feed 0
DojoSec June briefings http://www.clamav.net/lang/en/2009/05/17/dojosec-june-briefings http://www.clamav.net/lang/en/2009/05/17/dojosec-june-briefings#comments Sun, 17 May 2009 15:03:47 +0000 webmaster http://www.clamav.net/2009/05/21/dojosec-june-briefings/ Alain Zidouemba will give a talk at DojoSec on the topic: What to do with the unknown.
Here are the meeting details:
Date: June 4, 2009
Time: 6:00 – 9:30 PM
Entry Fee: $1
Location: Capitol College – Avrum Gudelsky Memorial Auditorium

Register: http://www.dojosec.com/?page_id=37
Directions: http://www.capitol-college.edu/visit-campus/directions-campus

Abstract

Clam AntiVirus is an open source anti-virus toolkit for UNIX systems. The main purpose of this software lies in the integration with mail servers enabling mail attachment scanning before the end user receives a virus. Like other anti-virus software, the engine for ClamAV has pattern matching technology at it’s heart. Updates to the malware signatures are released on a regular basis by ClamAV Researchers. When no signatures are available however, or when updates are not coming fast enough the only option is to create signatures. Fortunately, ClamAV signatures are open and this enables the administrator to fill in the gap for themselves.


About Alain Zidouemba

Alain Zidouemba was born in Ouagadougou, Burkina Faso. He studied Mathématiques Supérieures and Mathématiques Spéciales at the Lycée Jacques Amyot in France and Electrical and Computer Engineering at Howard University in the US. He worked in the area of network modelling and simulation at OPNET Technologies before taking a position at PestPatrol as a Spyware researcher. He later joined Computer Associates to work on intrusion prevention and behavioral malware analysis. Alain recently became part of the Vulnerability Research Team (VRT) at Sourcefire and performs research in the areas of intrusion prevention and anti-malware.

]]>
http://www.clamav.net/lang/en/2009/05/17/dojosec-june-briefings/feed 0
ClamAV Users’ Webcast http://www.clamav.net/lang/en/2009/02/09/clamav-users-webcast http://www.clamav.net/lang/en/2009/02/09/clamav-users-webcast#comments Mon, 09 Feb 2009 10:48:12 +0000 webmaster http://www.clamav.net/2009/02/09/clamav-users%e2%80%99-webcast/ The next ClamAV® Users’ Webcast will be on Wed 4th March at 1800UTC: 10 AM PST, 1 PM EST, 6 PM GMT, 7 PM CEST. The talk, given by Alain Zidouemba of Sourcefire will be an introduction to writing ClamAV Signatures. The talk will cover about an hour. The talk will be technically advanced, and is aimed toward Systems Administrators and developers.

Abstract

ClamAV is an open source anti-virus toolkit for UNIX systems. The main purpose of this software lies in the integration with mail servers enabling mail attachment scanning before the end user receives a virus. As with other anti-virus software, the engine for ClamAV has pattern matching technology at its heart. Updates to the malware signatures are released on a regular basis by ClamAV Researchers.
However, what if no signatures are available to detect a given piece of malware, or if updates are not coming fast enough? Fortunately, ClamAV signatures are “open” and this enables the administrators to fill in the gap for themselves. This presentation covers the methods behind creating effective malware signatures for ClamAV and introduces the new malware “logical signature” format that makes it even easier to write custom detections.
The event will finish with a Q&A session of about 15 minutes.

About the Presenter

Alain Zidouemba studied Mathématiques Supérieures and Mathématiques Spéciales at the Lycée Jacques Amyot in France and Electrical and Computer Engineering at Howard University in the United States. He worked in the area of network modelling and simulation at OPNET Technologies before taking a position at PestPatrol, Inc. as a Spyware Researcher. He later joined Computer Associates to work on intrusion prevention and behavioural malware analysis. Alain is a member of the Vulnerability Research Team (VRT) at Sourcefire and performs research in the areas of intrusion prevention and anti-malware.

How to Hear The Presentation

To register for this webinar please visit https://sourcefire.webex.com/sourcefire/onstage/g.php?d=798010302&t=a.
After you have registered you will receive an email that will contain the instructions on how to listen to the webinar. For most people the procedure is to visit a URL, which will be given, enter in an password (the event password is clamav) and then either listen on the your computer’s speakers, or dial-in to listen over the telephone. The interface you get on the PC will be the same whichever audio method you choose.
The phone numbers for the U.S. and Canada are 866-469-3239 (free), 1-650-429-3300 (charged). To see the worldwide call-in numbers please visit https://sourcefire.webex.com/sourcefire/globalcallin.php?serviceType=EC&ED=111325642&tollFree=1.
To find out about the toll-free dialling restrictions: http://www.webex.com/pdf/tollfree_restrictions.pdf.
The session will be archived and available later from www.clamav.net.

]]>
http://www.clamav.net/lang/en/2009/02/09/clamav-users-webcast/feed 0
Conficker aka Downadup http://www.clamav.net/lang/en/2009/01/29/conficker-aka-downadup http://www.clamav.net/lang/en/2009/01/29/conficker-aka-downadup#comments Thu, 29 Jan 2009 06:31:58 +0000 webmaster http://www.clamav.net/2009/01/29/conficker-aka-downadup/ Some of you may have heard of a current major outbreak of a virus known as Downadup that has been reported at http://news.bbc.co.uk/1/hi/technology/7842013.stm and http://news.bbc.co.uk/1/hi/technology/7832652.stm. It has been estimated that move than 9 million PCs are infected across the world.

ClamAV detects Downadup, also known as Conficker, as Worm.Downadup. Once on a system it downloads components that ClamAV detects as members of the Trojan.Downloader- family of signatures.

The virus primarily exploits MS08-067; it can also spread through USB sticks. Since the virus is not spread by email we don’t expect to see much activity in our core user-base, which tends to use ClamAV to scan emails. We are, nevertheless, keeping an eye out for it through freshclam’s statistics gathering system – we are yet to see any obvious spike of activity from it. If we hear anything we’ll let you know.

]]>
http://www.clamav.net/lang/en/2009/01/29/conficker-aka-downadup/feed 0
500,000 Signatures and Counting http://www.clamav.net/lang/en/2009/01/27/500000-signatures-and-counting http://www.clamav.net/lang/en/2009/01/27/500000-signatures-and-counting#comments Tue, 27 Jan 2009 20:23:55 +0000 webmaster http://www.clamav.net/2009/01/27/500000-signatures-and-counting/ Today, 27th January 2009, ClamAV’s signature team investigated and identified Trojan.Agent-70954, the 500,000th entry in its database. Well done to all the team for working so hard to produce a quality database.
From time to time we are asked to keep the size of the database down by trimming old signatures; but, as the statistics-gathering program has shown, old viruses never die. SomeFool (a.k.a Netsky) is still alive and kicking 5 years after the ClamAV team spotted the first variants! Today two variants of that virus are in the top 10 most active malware amongst our users that send us statistics.

]]>
http://www.clamav.net/lang/en/2009/01/27/500000-signatures-and-counting/feed 0
ClamAV twitter feed available http://www.clamav.net/lang/en/2008/11/10/clamav-twitter-feed-available http://www.clamav.net/lang/en/2008/11/10/clamav-twitter-feed-available#comments Mon, 10 Nov 2008 18:35:11 +0000 webmaster http://www.clamav.net/2008/11/10/clamav-twitter-feed-available/ Notifications of ClamAV signature updates are now available via our
Twitter feed at http://twitter.com/clamav. The notifications include information about the number of signatures added and the total number of signatures in the ClamAV database.
We hope to include other information on that feed later so please feel free to let us know
suggestions, but remember that “twittiquette” means that we don’t wish to flood the feed with
too much information.

]]>
http://www.clamav.net/lang/en/2008/11/10/clamav-twitter-feed-available/feed 0