Valhalla Legends Forums Archive | General Discussion | ClamAV: Free/opensource virus scanner

AuthorMessageTime
iago
[quote]iago@Slayer:~/downloads/viruses$ ~/clamav/bin/clamscan
/usr/local/home/iago/downloads/viruses/Your_money.com: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/Counter_strike.com: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/Document.com: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/price.scr: Worm.Bagle.AU FOUND
/usr/local/home/iago/downloads/viruses/mp3music.pif: Worm.SomeFool.I FOUND
/usr/local/home/iago/downloads/viruses/Garry.exe: Worm.Bagle.AG FOUND
/usr/local/home/iago/downloads/viruses/Dog.exe: Worm.Bagle.AG FOUND
/usr/local/home/iago/downloads/viruses/Price.exe: Worm.Bagle.AT FOUND
/usr/local/home/iago/downloads/viruses/Joke.scr: Worm.Bagle.AT FOUND
/usr/local/home/iago/downloads/viruses/MsgInfo.zip: Worm.Bagle.Gen-zippwd FOUND
/usr/local/home/iago/downloads/viruses/price.com: Worm.Bagle.AT FOUND
/usr/local/home/iago/downloads/viruses/text_document.scr: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/Your_complaint.scr: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/I_search_for_you.scr: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/Joke.exe: Worm.Bagle.AU FOUND
/usr/local/home/iago/downloads/viruses/Bill.txt.exe: Worm.SomeFool.AA-2 FOUND
/usr/local/home/iago/downloads/viruses/2-Joke.exe: Worm.Bagle.AU FOUND
/usr/local/home/iago/downloads/viruses/Message.cpl: Worm.Bagle.AC FOUND

----------- SCAN SUMMARY -----------
Known viruses: 28160
Scanned directories: 1
Scanned files: 18
Infected files: 18
Data scanned: 0.34 MB
I/O buffer size: 131072 bytes
Time: 0.776 sec (0 m 0 s)
iago@Slayer:~/downloads/viruses$[/quote]

www.clamav.net -- it passed my test.  This is a really cool project, virus scanners are so big and commercialized that a free one, if it has the right features (stuff like realtime scan and whatnot -- I haven't got a clue if it does or not), it can do well. 

Just thought people might be interested in the free alternative :)
December 8, 2004, 2:25 AM
Stealth
Neat! I wonder how it compares to other free offerings like my personal favorite Avast! or AVG?
December 8, 2004, 3:16 AM
iago
I've never heard of nor tried those.  I like that this compiled/ran on Linux :)
December 8, 2004, 3:38 AM
EpicOfTimeWasted
No, clamav doesn't have realtime scanning (I'm assuming you're talking about scanning files as they're accessed).  It's an excellent virus scanner though.  I've ran it on my (relatively low traffic) mail server for about six months now, and it hasn't missed a beat yet.  It's even caught some trojans, which even some commercial virus scanners can't always claim to do.
December 8, 2004, 4:07 AM
iago
[quote author=EpicOfTimeWasted link=topic=9822.msg91480#msg91480 date=1102478820]
No, clamav doesn't have realtime scanning
[/quote]

Somebody should write it, then.  I wonder how hard it would be to add that kind of functionality.
December 8, 2004, 4:09 AM
Newby
Giving it a run in Windows. I'll see how it fares. :)

Well, *refrains from swearing* it's a great way to lock your computer up. :(
December 8, 2004, 5:00 AM
hismajesty
<3Avast
<3Stealth
December 8, 2004, 11:27 AM
LW-Falcon
I like my McAfee Virusscan
December 8, 2004, 1:02 PM
iago
McAfee is welfare.  We got their IPS system at work for a pilot, and their software doesn't even work, so they got us to send them an error log, and they gave us an email address which doesn't work.  So we've gone for over two weeks without being able to get it to work.  This doesn't reflect well on McAfee as a whole :)
December 8, 2004, 1:31 PM
EpicOfTimeWasted
Yeah, I'm bringing up a dead thread, but clamav is worth it.  I checked my spam catch mailbox today, and found a phishing e-mail in it.  Checked the full headers for the e-mail, and saw:

[quote]X-Amavis-Alert: INFECTED, message contains virus: HTML.Phishing.Bank-91[/quote]

That's pretty damned neat when it can detect phishing attempts.
January 29, 2005, 6:33 PM
iago
[quote]
iago@Slayer:~/downloads/viruses$ ~/clamav/bin/clamscan
/usr/local/home/iago/downloads/viruses/Your_money.com: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/Counter_strike.com: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/Document.com: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/price.scr: Worm.Bagle.AU FOUND
/usr/local/home/iago/downloads/viruses/mp3music.pif: Worm.SomeFool.I FOUND
/usr/local/home/iago/downloads/viruses/Garry.exe: Worm.Bagle.AG FOUND
/usr/local/home/iago/downloads/viruses/Dog.exe: Worm.Bagle.AG FOUND
/usr/local/home/iago/downloads/viruses/Price.exe: Worm.Bagle.AT FOUND
/usr/local/home/iago/downloads/viruses/Joke.scr: Worm.Bagle.AT FOUND
/usr/local/home/iago/downloads/viruses/MsgInfo.zip: Worm.Bagle.Gen-zippwd FOUND
/usr/local/home/iago/downloads/viruses/price.com: Worm.Bagle.AT FOUND
/usr/local/home/iago/downloads/viruses/text_document.scr: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/Your_complaint.scr: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/I_search_for_you.scr: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/Joke.exe: Worm.Bagle.AU FOUND
/usr/local/home/iago/downloads/viruses/Bill.txt.exe: Worm.SomeFool.AA-2 FOUND
/usr/local/home/iago/downloads/viruses/2-Joke.exe: Worm.Bagle.AU FOUND
/usr/local/home/iago/downloads/viruses/Message.cpl: Worm.Bagle.AC FOUND
/usr/local/home/iago/downloads/viruses/Your_complaint.vbs: Worm.Bagle.Gen-vbs FOUND
/usr/local/home/iago/downloads/viruses/PlayGirls_2.exe: Worm.Maslan.B FOUND
/usr/local/home/iago/downloads/viruses/You_are_dismissed.com: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/Alive_condom.scr: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/loadadv407.exe: Trojan.Qhost.O FOUND
/usr/local/home/iago/downloads/viruses/You_will_answer_to_me.scr: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/pwd02.txt.scr: Worm.SomeFool.P FOUND
/usr/local/home/iago/downloads/viruses/part6.zip: Worm.SomeFool.P FOUND
/usr/local/home/iago/downloads/viruses/word_doc.zip: Worm.SomeFool.P FOUND
/usr/local/home/iago/downloads/viruses/letter43.txt .scr: Worm.SomeFool.P FOUND
/usr/local/home/iago/downloads/viruses/You_are_dismissed.cpl: Worm.Bagle.AC FOUND
/usr/local/home/iago/downloads/viruses/PlayGirls_2-2.exe: Worm.Maslan.B FOUND
/usr/local/home/iago/downloads/viruses/Smoke.scr: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/the_message.com: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/Information.scr: Worm.Bagle.AF FOUND
/usr/local/home/iago/downloads/viruses/text_document-2.scr: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/Toy.com: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/document.zip: Worm.SomeFool.P FOUND
/usr/local/home/iago/downloads/viruses/data_full-disclosure.zip: Worm.SomeFool.P FOUND
/usr/local/home/iago/downloads/viruses/I_search_for_you.com: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/private_01_full-disclosure.zip: Worm.SomeFool.P FOUND
/usr/local/home/iago/downloads/viruses/text_document.cpl: Worm.Bagle.AC FOUND
/usr/local/home/iago/downloads/viruses/AGen1.03.exe: Worm.Plexus.B FOUND
/usr/local/home/iago/downloads/viruses/demo.exe: Worm.Plexus.B FOUND
/usr/local/home/iago/downloads/viruses/Readme.com: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/MoreInfo.scr: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/Attach.zip: Empty file.
/usr/local/home/iago/downloads/viruses/the_message-2.com: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/Smoke.com: Worm.Bagle.Z FOUND
/usr/local/home/iago/downloads/viruses/upd02.cpl: Empty file.
/usr/local/home/iago/downloads/viruses/Information.cpl: Worm.Bagle.AF FOUND
/usr/local/home/iago/downloads/viruses/ALL D2JSP Scripts - Install.exe: Trojan.Prorat.O FOUND
/usr/local/home/iago/downloads/viruses/AutoHit.exe: Trojan.Prorat.O FOUND
/usr/local/home/iago/downloads/viruses/Autotele - Wizard Setup.exe: Trojan.Prorat.O FOUND
/usr/local/home/iago/downloads/viruses/Colour Game Spam - Wizard.exe: Trojan.Prorat.O FOUND
/usr/local/home/iago/downloads/viruses/Cracked D2JSP - Install.exe: Trojan.Prorat.O FOUND
/usr/local/home/iago/downloads/viruses/D2Mousepads Maphack v6.1 - Auto-setup.exe: Trojan.Prorat.O FOUND
/usr/local/home/iago/downloads/viruses/HC Hack.exe: Trojan.Prorat.O FOUND
/usr/local/home/iago/downloads/viruses/JHJ Anti-Detection No D2Loader - Setup.exe: Trojan.Prorat.O FOUND
/usr/local/home/iago/downloads/viruses/JHJ English - Install.exe: Trojan.Prorat.O FOUND
/usr/local/home/iago/downloads/viruses/MM.Bot - Install.exe: Trojan.Prorat.O FOUND
/usr/local/home/iago/downloads/viruses/PvP Buddy - Install.exe: Trojan.Prorat.O FOUND
/usr/local/home/iago/downloads/viruses/SpamBot - Wizard install.exe: Trojan.Prorat.O FOUND
/usr/local/home/iago/downloads/viruses/TPPK - Auto.exe: Trojan.Prorat.O FOUND
/usr/local/home/iago/downloads/viruses/WPPK - Auto.exe: Trojan.Prorat.O FOUND
/usr/local/home/iago/downloads/viruses/ZoiD's Pickit - No D2Loader Ver2.exe: Trojan.Prorat.O FOUND


----------- SCAN SUMMARY -----------
Known viruses: 28160
Scanned directories: 1
Scanned files: 62
Infected files: 62
Data scanned: 2.96 MB
I/O buffer size: 131072 bytes
Time: 0.837 sec (0 m 0 s)
[/quote]

:-)
January 29, 2005, 6:48 PM
JoeTheOdd
iago, you have a collection of viruses you just leave there? Do you have an anti-virus that makes it so they can't do any spreading or something?
January 30, 2005, 4:06 PM
LW-Falcon
*hint* look at the topic name ;)
January 30, 2005, 5:49 PM
Kp
First, that's a Linux system he's running on and those're Windows viruses, so they couldn't infect that system even if he did try to run them.  Second, it's quite safe to have a virus on disk as long as you don't run it.
January 30, 2005, 5:51 PM
iago
[quote author=Kp link=topic=9822.msg97431#msg97431 date=1107107461]
First, that's a Linux system he's running on and those're Windows viruses, so they couldn't infect that system even if he did try to run them.  Second, it's quite safe to have a virus on disk as long as you don't run it.
[/quote]

That's correct.

I save all the viruses I find in my email/otherwise for no good reason.  Although if I ever need to test a virus scanner, I can very easily.  Who needs Eicar? :)
January 30, 2005, 11:25 PM
dRAgoN
[quote author=Stealth link=topic=9822.msg91465#msg91465 date=1102475817]
Neat! I wonder how it compares to other free offerings like my personal favorite Avast! or AVG?
[/quote]
AVG is good but still miss's some things.
January 31, 2005, 12:56 AM
Intangir
ive been using clamav for months on the mail server at work
January 31, 2005, 4:19 PM
warz
[quote author=Intangir link=topic=9822.msg97615#msg97615 date=1107188386]
ive been using clamav for months on the mail server at work

[/quote]

.. and? how well do you consider it to work?
January 31, 2005, 5:16 PM
Intangir
seems good, sometimes the update servers are done and i get an error report
but mostly it works fine

(it auto downloads updates, if the servers are up)

no viruses have gotten thru our email, but then again i doubt anyone is really sending viruses to our email ;) i should probably check and see if it has logged virus mail attempts

January 31, 2005, 5:35 PM
Intangir
wow apparntly it has stopped a whole ton of viruses
looks like lately alot Worm.Zafi.D and Worm.SomeFool.P
some Worm.Bagle.Gen-zippwd and Worm.Mydoom.F

hehehe cool ;)
January 31, 2005, 5:40 PM
Intangir
hrmm today a virus slipped thru it.. McAfee caught it and says its: W32/Bagle@MM!cpl
February 2, 2005, 7:13 PM

Search