<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;DEMDQ3Y7fyp7ImA9WhBVGE0.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573</id><updated>2013-04-24T08:27:52.807-04:00</updated><category term="linux" /><category term="mirrors" /><category term="epo" /><category term="intern" /><category term="enable" /><category term="virusnames" /><category term="signatures" /><category term="press release" /><category term="vrt" /><category term="documentation" /><category term="news" /><category term="immunet" /><category term="malware" /><category term="postfix" /><category term="scholarship" /><category term="faq" /><category term="updates" /><category term="sendmail" /><category term="osx" /><category term="Sourcefire" /><category term="milter" /><category term="test" /><category term="antivirus" /><category term="xpaj" /><category term="polymorphic" /><category term="unix" /><category term="virus" /><category term="server" /><category term="windows" /><category term="Release Candidate" /><category term="team" /><category term="guides" /><category term="clamav" /><category term="Ubuntu" /><category term="statistics" /><category term="solaris" /><category term="patch release" /><category term="snort" /><title>ClamAV®</title><subtitle type="html">The leading open source anti-malware software, brought to you by Sourcefire.</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://blog.clamav.net/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://blog.clamav.net/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>Joel Esler</name><uri>http://www.blogger.com/profile/03205477151965113876</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>53</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/Clamav" /><feedburner:info uri="clamav" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>Clamav</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><entry gd:etag="W/&quot;CkAEQHs_eyp7ImA9WhBVF0k.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-1478316707952236138</id><published>2013-04-23T13:21:00.000-04:00</published><updated>2013-04-23T14:11:41.543-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-23T14:11:41.543-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="patch release" /><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><title>ClamAV 0.97.8 has been released!</title><content type="html">Dear ClamAV users,&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
"ClamAV 0.97.8 addresses several reported potential security bugs.  Thanks to
Felix Groebert of the Google Security Team for finding and reporting these issues."&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Download: &lt;a href="http://downloads.sourceforge.net/clamav/clamav-0.97.8.tar.gz" target="_blank"&gt;http://downloads.sourceforge.net/clamav/clamav-0.97.8.tar.gz&amp;nbsp;&lt;/a&gt;&lt;br /&gt;
PGP sig: &lt;a href="http://downloads.sourceforge.net/clamav/clamav-0.97.8.tar.gz.sig"&gt;http://downloads.sourceforge.net/clamav/clamav-0.97.8.tar.gz.sig&lt;/a&gt;&lt;br /&gt;
ChangeLog: &lt;a href="https://github.com/vrtadmin/clamav-devel/blob/0.97/ChangeLog"&gt;https://github.com/vrtadmin/clamav-devel/blob/0.97/ChangeLog&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
The ClamAV team (&lt;a href="http://www.clamav.net/lang/en/about/team/"&gt;http://www.clamav.net/lang/en/about/team/&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=x7F8K_pMpus:tXzQ-uMiIuk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=x7F8K_pMpus:tXzQ-uMiIuk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=x7F8K_pMpus:tXzQ-uMiIuk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=x7F8K_pMpus:tXzQ-uMiIuk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/x7F8K_pMpus" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/1478316707952236138/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2013/04/clamav-0978-has-been-released.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/1478316707952236138?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/1478316707952236138?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/x7F8K_pMpus/clamav-0978-has-been-released.html" title="ClamAV 0.97.8 has been released!" /><author><name>Joel Esler</name><uri>http://www.blogger.com/profile/03205477151965113876</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.clamav.net/2013/04/clamav-0978-has-been-released.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEUNQHc9fip7ImA9WhBVEE4.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-23472805713901776</id><published>2013-04-15T10:31:00.000-04:00</published><updated>2013-04-15T10:31:31.966-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-15T10:31:31.966-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="mirrors" /><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><title>You want to become a ClamAV mirror?</title><content type="html">One of the questions I receive in my inbox quite frequently is:&lt;br /&gt;
&lt;br /&gt;
"Does ClamAV need any more mirrors for virus definitions?"&lt;br /&gt;
&lt;br /&gt;
The quick answer is "Yes!" &amp;nbsp;We'll always take more mirrors that we can get, as we increase output of virus definitions and such, we need more infrastructure to be able to handle the load.&lt;br /&gt;
&lt;br /&gt;
If you are interested in becoming a ClamAV mirror, please follow the instructions here:&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://github.com/vrtadmin/clamav-faq/blob/master/mirrors/MirrorHowto.md"&gt;https://github.com/vrtadmin/clamav-faq/blob/master/mirrors/MirrorHowto.md&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=dbrGBD2oLWY:UGDIVAIpheU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=dbrGBD2oLWY:UGDIVAIpheU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=dbrGBD2oLWY:UGDIVAIpheU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=dbrGBD2oLWY:UGDIVAIpheU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/dbrGBD2oLWY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/23472805713901776/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2013/04/you-want-to-become-clamav-mirror.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/23472805713901776?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/23472805713901776?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/dbrGBD2oLWY/you-want-to-become-clamav-mirror.html" title="You want to become a ClamAV mirror?" /><author><name>Joel Esler</name><uri>http://www.blogger.com/profile/03205477151965113876</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.clamav.net/2013/04/you-want-to-become-clamav-mirror.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CU4GRXw-eip7ImA9WhBQE0g.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-6602604140079344078</id><published>2013-03-15T09:25:00.002-04:00</published><updated>2013-03-15T09:25:24.252-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-15T09:25:24.252-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="patch release" /><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><title>ClamAV 0.97.7 has been released!</title><content type="html">Dear ClamAV users,&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
"ClamAV 0.97.7 addresses several reported potential security bugs.  Thanks to
Felix Groebert, Mateusz Jurczyk and Gynvael Coldwind of the Google Security
Team for finding and reporting these issues."&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Download: &lt;a href="http://downloads.sourceforge.net/clamav/clamav-0.97.7.tar.gz" target="_blank"&gt;http://downloads.sourceforge.net/clamav/clamav-0.97.7.tar.gz&amp;nbsp;&lt;/a&gt;&lt;br /&gt;
PGP sig: &lt;a href="http://downloads.sourceforge.net/clamav/clamav-0.97.7.tar.gz.sig"&gt;http://downloads.sourceforge.net/clamav/clamav-0.97.7.tar.gz.sig&lt;/a&gt;&lt;br /&gt;
ChangeLog: &lt;a href="https://github.com/vrtadmin/clamav-devel/blob/0.97/ChangeLog"&gt;https://github.com/vrtadmin/clamav-devel/blob/0.97/ChangeLog&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
The ClamAV team (&lt;a href="http://www.clamav.net/lang/en/about/team/"&gt;http://www.clamav.net/lang/en/about/team/&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=2IhlTR44Hmg:uv67nyVnkT4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=2IhlTR44Hmg:uv67nyVnkT4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=2IhlTR44Hmg:uv67nyVnkT4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=2IhlTR44Hmg:uv67nyVnkT4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/2IhlTR44Hmg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/6602604140079344078/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2013/03/clamav-0977-has-been-released.html#comment-form" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/6602604140079344078?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/6602604140079344078?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/2IhlTR44Hmg/clamav-0977-has-been-released.html" title="ClamAV 0.97.7 has been released!" /><author><name>Joel Esler</name><uri>http://www.blogger.com/profile/03205477151965113876</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>2</thr:total><feedburner:origLink>http://blog.clamav.net/2013/03/clamav-0977-has-been-released.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEAGRHs9cSp7ImA9WhBRFUw.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-6662047862491102060</id><published>2013-02-26T16:05:00.000-05:00</published><updated>2013-03-05T15:52:05.569-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-05T15:52:05.569-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="mirrors" /><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><title>Resolving Issues With Freshclam</title><content type="html">Certain users are experiencing database update issues due to the failed Authenticode database push. This blog post will show how to check if you're one of those affected users and how to fix freshclam.&lt;br /&gt;
&lt;br /&gt;
Validate You're Affected&lt;br /&gt;
&lt;br /&gt;
You can validate that you're having this particular issue by a number of ways:
&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;Check the hash of your daily.cvd. You are affected if the hash matches the following:&lt;/li&gt;
&lt;ol&gt;
&lt;li&gt;MD5:&amp;nbsp;&lt;span style="font-family: Courier New, Courier, monospace;"&gt;89dedb45609e59b0244fb5202ab6fa56&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;SHA1:&amp;nbsp;&lt;span style="font-family: Courier New, Courier, monospace;"&gt;9947ec90e60499ab7c3331670d5b26b4eaac76e4&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;li&gt;Check your freshclam log file for repeated errors that look like:&lt;/li&gt;
&lt;ol&gt;
&lt;li&gt;&lt;span style="font-family: Courier New, Courier, monospace;"&gt;&lt;span style="background-color: white; color: #222222;"&gt;&lt;span style="font-size: x-small;"&gt;Ignoring mirror [Mirror's IP&amp;nbsp;address&amp;nbsp;here] (has connected too many times with an&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: white; color: #222222; font-size: 13px;"&gt;outdated version)&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;li&gt;Check the version number and the functional level of the daily.cvd by using sigtool:&lt;/li&gt;
&lt;ol&gt;
&lt;li&gt;&lt;span style="font-family: Courier New, Courier, monospace;"&gt;sigtool --info daily.cvd&lt;/span&gt; will show a version number of 16681 and a functionality level of 73&lt;/li&gt;
&lt;/ol&gt;
&lt;/ol&gt;
&lt;br /&gt;
How To Fix Freshclam&lt;br /&gt;
&lt;br /&gt;
If you are expereincing the problem, please do the following: &amp;nbsp;Stop the freshclam daemon if it's running, delete both mirrors.dat and daily.cvd, then restart the freshclam daemon. Freshclam will then download a new daily.cvd and will be up-to-date.&lt;br /&gt;
&lt;br /&gt;
We&amp;nbsp;apologize&amp;nbsp;for any&amp;nbsp;inconvenience&amp;nbsp;this has caused and thank you for using ClamAV. &amp;nbsp;If you have any further issues, please send a message to the ClamAV user's list or contact us via IRC.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=LpP6tqiabxY:_uqR47lo0SQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=LpP6tqiabxY:_uqR47lo0SQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=LpP6tqiabxY:_uqR47lo0SQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=LpP6tqiabxY:_uqR47lo0SQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/LpP6tqiabxY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/6662047862491102060/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2013/02/resolving-issues-with-freshclam.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/6662047862491102060?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/6662047862491102060?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/LpP6tqiabxY/resolving-issues-with-freshclam.html" title="Resolving Issues With Freshclam" /><author><name>Shawn Webb</name><uri>http://www.blogger.com/profile/17982634013445041029</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.clamav.net/2013/02/resolving-issues-with-freshclam.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0ANRX46eyp7ImA9WhBVFkg.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-8023485806418158661</id><published>2013-02-25T13:00:00.000-05:00</published><updated>2013-04-22T15:43:14.013-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-22T15:43:14.013-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="mirrors" /><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><title>Planned Infrastructure Maintenance - 04 Mar 2013</title><content type="html">In preparation for the ClamAV 0.98 release, we will be&amp;nbsp;performing&amp;nbsp;maintenance on the infrastructure beginning at 5:00 PM EST on 04 Mar 2013.&lt;br /&gt;
&lt;br /&gt;
We will be pushing out a new signature database that does not have a corresponding cdiff file. This means that clients will pull down a full copy of the daily.cvd database, which will cause an increase in download traffic from the mirrors.&lt;br /&gt;
&lt;br /&gt;
The maintenance is estimated to take one hour. &amp;nbsp;No impact to users, beyond the downloading of a new daily.cvd, is anticipated.&lt;br /&gt;
&lt;br /&gt;
We would like to extend our thanks to the mirror providers for their contributions, and thank you for using ClamAV.
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=5Em2vkI29VQ:xAIqXIS92ME:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=5Em2vkI29VQ:xAIqXIS92ME:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=5Em2vkI29VQ:xAIqXIS92ME:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=5Em2vkI29VQ:xAIqXIS92ME:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/5Em2vkI29VQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/8023485806418158661/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2013/02/planned-infrastructure-maintenance-04.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/8023485806418158661?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/8023485806418158661?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/5Em2vkI29VQ/planned-infrastructure-maintenance-04.html" title="Planned Infrastructure Maintenance - 04 Mar 2013" /><author><name>Shawn Webb</name><uri>http://www.blogger.com/profile/17982634013445041029</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://blog.clamav.net/2013/02/planned-infrastructure-maintenance-04.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A04GQng_fyp7ImA9WhBVFkg.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-4514704072732727300</id><published>2013-02-25T10:00:00.000-05:00</published><updated>2013-04-22T15:45:23.647-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-22T15:45:23.647-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><category scheme="http://www.blogger.com/atom/ns#" term="updates" /><title>Post-Mortem Analysis Of Virus Database Push Issues</title><content type="html">On Thursday, 14 Feb 2013, in preparation for the coming ClamAV 0.98 release, a new database was scheduled to be made available to users. We had a set of issues while performing this upgrade, and we feel that it is appropriate to let our users and mirror providers know what happened, what has done to fix the issues, and what is being done to prevent these issues from happening again.&lt;br /&gt;
&lt;br /&gt;
So first, What Happened?&lt;br /&gt;
&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;14 Feb 2013 0800 EST: Start of our scheduled work on our infrastructure.&lt;/li&gt;
&lt;li&gt;14 Feb 2013 0815 EST: A new, custom daily.cvd (our virus definition database) was published. This database was generated with ClamAV 0.98, which in turn caused freshclam to think that a new version of ClamAV was available (not yet, but there will be).&lt;/li&gt;
&lt;li&gt;14 Feb 2013 0830 EST: Published a new daily.cvd, generated with ClamAV 0.97.6, the current version of ClamAV.  This corrected the issue with incorrect notifications of a new version of ClamAV.&lt;/li&gt;
&lt;li&gt;14 Feb 2013 1100 EST: Clients report errors with updating. Investigation starts.&lt;/li&gt;
&lt;li&gt;14 Feb 2013 1130 EST: The problem was isolated. The new database wasn't copied into a critical directory on our internal Signature server. The database publishing infrastructure didn't know that a custom database had been published. The custom database was overwritten with a new database. &amp;nbsp;This resulted in some users being unable to use the .cdiff files (our incremental update files) for updating, leading to users who had downloaded the custom database to be unable to update.&lt;/li&gt;
&lt;li&gt;14 Feb 2013 1330 EST: A new database was published to resolve the issues. Issues should now be resolved for most users.&lt;/li&gt;
&lt;li&gt;19 Feb 2013 1700 EST: Issues resolved for all remaining users by modifying the set of available .cdiff files.&lt;/li&gt;
&lt;/ol&gt;
Fixes That Have Been Performed&lt;br /&gt;
&lt;br /&gt;
We've deleted all database files that would cause errors. This should fix the remainder of issues for our users. &amp;nbsp;However, any users who are still seeing errors should delete the &lt;code&gt;mirrors.dat&lt;/code&gt; file in their database directory to force a reset of mirror selection.
&lt;br /&gt;
&lt;br /&gt;
Prevention&lt;br /&gt;
&lt;br /&gt;
We've put in place a workflow that will prevent issues like this from popping up. A full change-management process is in place, with an emphasis on peer-reviewed planning, comprehensive test plans and&amp;nbsp;appropriate&amp;nbsp;personnel&amp;nbsp;assignments. &amp;nbsp;Change plans will be approved by a senior administrator, a ClamAV developer and a&amp;nbsp;representative&amp;nbsp;from the analyst team.&lt;br /&gt;
&lt;br /&gt;
For the&amp;nbsp;convenience&amp;nbsp;of our mirror providers, there is now a set maintenance window for routine changes: Monday 5pm EST through midnight EST. &amp;nbsp;As always, we will aim to notify mirror providers a&amp;nbsp;week&amp;nbsp;in advance of any change. &amp;nbsp;In the case of emergent issues, a different time or a shorter notification may be required.&lt;br /&gt;
&lt;br /&gt;
We&amp;nbsp;apologize&amp;nbsp;for any inconvenience caused by the problems outlined in this post. &amp;nbsp;We will continue to review our processes to ensure that we are providing the best experience for both our users and our mirror providers.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=2jRYAyivCs4:kLf4jnd1A84:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=2jRYAyivCs4:kLf4jnd1A84:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=2jRYAyivCs4:kLf4jnd1A84:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=2jRYAyivCs4:kLf4jnd1A84:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/2jRYAyivCs4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/4514704072732727300/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2013/02/post-mortem-analysis-of-virus-database.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/4514704072732727300?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/4514704072732727300?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/2jRYAyivCs4/post-mortem-analysis-of-virus-database.html" title="Post-Mortem Analysis Of Virus Database Push Issues" /><author><name>Shawn Webb</name><uri>http://www.blogger.com/profile/17982634013445041029</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.clamav.net/2013/02/post-mortem-analysis-of-virus-database.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkcGSH89fip7ImA9WhBVFks.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-5831044431318232222</id><published>2013-02-13T15:14:00.000-05:00</published><updated>2013-04-22T15:47:09.166-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-22T15:47:09.166-04:00</app:edited><title>Authenticode Certificate Chain Verification</title><content type="html">&lt;h2&gt;
Introduction&lt;/h2&gt;
&lt;div&gt;
Microsoft introduced digitally signing PE object files (&lt;a href="http://msdn.microsoft.com/en-us/library/ms537361.aspx" target="_blank"&gt;authenticode&lt;/a&gt;) in Windows 98. Hardware drivers eligible for the Windows Logo Program are required to contain a valid authenticode signature. Since then, Microsoft has expanded the program to executable object files (EXEs) and DLLs.&lt;br /&gt;
&lt;br /&gt;
Microsoft has its own public key infrastructure (PKI). There are four trusted root certificate authorities: two by Microsoft, Thawte, and Verisign. Microsoft's own executables for Windows are signed.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-uO6NcqTngQc/URqrUB4kLLI/AAAAAAAAGmU/_k4dEhBScBs/s1600/2013-02-12+1551+Authenticode+bit9.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="176" src="http://3.bp.blogspot.com/-uO6NcqTngQc/URqrUB4kLLI/AAAAAAAAGmU/_k4dEhBScBs/s320/2013-02-12+1551+Authenticode+bit9.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
Authenticode At Work&lt;/div&gt;
&lt;br /&gt;
&lt;h2&gt;
The Problem&lt;/h2&gt;
It's becoming more common for malware authors to sign their executables. Malware authors are known to &lt;a href="http://arstechnica.com/security/2013/02/cooks-steal-security-firms-crypto-key-use-it-to-sign-malware" target="_blank"&gt;steal existing certificates&lt;/a&gt; or &lt;a href="http://www.schneier.com/blog/archives/2008/12/forging_ssl_cer.html" target="_blank"&gt;forge certificates&lt;/a&gt;&amp;nbsp;(the certificate forging link talks about SSL certificates; though you can't use certificates used for web browsing with authenticode, the concept still applies). Stealing and forging existing certificates can trick unsuspecting users into trusting the malware.&lt;br /&gt;
&lt;h2&gt;
The Solution&lt;/h2&gt;
ClamAV 0.98 now parses and validates the authenticode certificates. ClamAV now ships a database of trusted and revoked certificates. If the PE file being scanned is flagged as a virus, ClamAV follows this logic in validating the certificate chain contained inside the PE file:&lt;br /&gt;
&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;Load the chain in full&lt;/li&gt;
&lt;li&gt;Validate each certificate in the chain:&lt;/li&gt;
&lt;ol&gt;
&lt;li&gt;If no certificate matches one of the four trusted roots, the whole chain is considered invalid and is subsequently ignored. Further chain processing is stopped.&lt;/li&gt;
&lt;li&gt;If one certificate matches a revoked entry in the database, the whole chain is considered invalid. Report PE file being scanned is a virus.&lt;/li&gt;
&lt;li&gt;If no certificates match a revoked entry in the database, the PE file is marked as clean. No virus is reported for the PE file being scanned.&lt;/li&gt;
&lt;/ol&gt;
&lt;/ol&gt;
&lt;h2&gt;
Generating A Certificate Revocation Entry&lt;/h2&gt;
&lt;/div&gt;
&lt;div&gt;
Since the authenticode chain is verified only after a file has been flagged as virus by the ClamAV engine, you have to first create a signature for the file if one doesn't already exist. If a signature exists, yet the file is reported as clean, chances are that the file is being whitelisted due to having a valid authenticode signature. You can verify that the file is being whitelisted by passing &lt;span style="font-family: Courier New, Courier, monospace;"&gt;--debug --verbose&lt;/span&gt; to &lt;span style="font-family: Courier New, Courier, monospace;"&gt;clamscan&lt;/span&gt; and looking for the word &lt;i&gt;authenicode&lt;/i&gt;&amp;nbsp;(yes, that is indeed misspelled, but that works out to our advantage). If you see that word, then the file is being whitelisted and a certificate revocation entry needs to be created.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
First, we need to dump the certificate chain so that we can find the certificate to revoke. You can tell ClamAV to dump the certificate chain to stderr by passing &lt;span style="font-family: Courier New, Courier, monospace;"&gt;--dumpcerts&lt;/span&gt; to &lt;span style="font-family: Courier New, Courier, monospace;"&gt;clamscan&lt;/span&gt;. You will then match the certificate that is dumped with the public key of the lowest certificate in the chain that Windows shows. Windows shows a few bytes before the public key actually starts. Don't worry, if that confuses you, I have screenshots:&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-jUSse1VlYes/URvREhk5SjI/AAAAAAAAGmo/Gcz28plZQ-I/s1600/Screen+Shot+2013-02-13+at+12.36.22+PM.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="137" src="http://2.bp.blogspot.com/-jUSse1VlYes/URvREhk5SjI/AAAAAAAAGmo/Gcz28plZQ-I/s320/Screen+Shot+2013-02-13+at+12.36.22+PM.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
Windows Certificate Information&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-4zIWA1y0-gQ/URvRLcX6LGI/AAAAAAAAGmw/5Dr4SjHAueY/s1600/Screen+Shot+2013-02-13+at+12.37.11+PM.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="203" src="http://2.bp.blogspot.com/-4zIWA1y0-gQ/URvRLcX6LGI/AAAAAAAAGmw/5Dr4SjHAueY/s320/Screen+Shot+2013-02-13+at+12.37.11+PM.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
Validating and Dumping Authenticode Certificate Information via ClamAV&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Certificate revocation entries go into a .crtdb file in your ClamAV database directory. Its format is as follows:&amp;nbsp;&lt;i&gt;name;trusted;subject;serial;pubkey;exponent;codesign;timesign;certsign;notbefore;comment[;minFL[;maxFL]]&lt;/i&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div&gt;
Where:&lt;/div&gt;
&lt;div&gt;
&lt;ol&gt;
&lt;li&gt;Name: a descriptive name for the certificate entry&lt;/li&gt;
&lt;li&gt;Trusted: a bit field (0 or 1) whether this entry is trusted or revoked&lt;/li&gt;
&lt;li&gt;Subject: the subject reported by ClamAV&lt;/li&gt;
&lt;li&gt;Serial: the serial reported by ClamAV&lt;/li&gt;
&lt;li&gt;Pubkey: the public key reported by ClamAV&lt;/li&gt;
&lt;li&gt;Exponent: The exponent of the certificate. Set this to 010001.&lt;/li&gt;
&lt;li&gt;Codesign: A bit field (0 or 1) whether this certificate can sign code&lt;/li&gt;
&lt;li&gt;Timesign: A bit field (0 or 1) whether this certificate can generate a timestamp signature&lt;/li&gt;
&lt;li&gt;Certsign: A bit field (0 or 1) whether this certificate can sign other certificates&lt;/li&gt;
&lt;li&gt;Notbefore: The notbefore field of the certificate. Defaults to 0 if empty.&lt;/li&gt;
&lt;li&gt;Comment: any comments about this entry&lt;/li&gt;
&lt;li&gt;MinFL: The minimum ClamAV feature level needed for this entry. Required only if MaxFL is set.&lt;/li&gt;
&lt;li&gt;MaxFL: The maximum ClamAV feature level supported by this entry&lt;/li&gt;
&lt;/ol&gt;
&lt;div&gt;
Let's return back to the example. We now have enough information to create the certificate revocation entry. It would look like:&amp;nbsp;&lt;/div&gt;
&lt;/div&gt;

&lt;div&gt;
&lt;i&gt;Descriptive name here;0;fe72355be4b6893d8e5b628d1a9ae8863d202b6f;a58d94ce010afa9865e732870971428768c92d64;ba0532ff862861cfaf8c22601fe479e3697b6ab94ff01c3254d105018c93bdb47f4c3fc1fb1d20172c46a727fb589f310cf6b081517ee472d145dfd4939c7d4652aad06c3ee6722f15703e88bbd8bc4d56fe7030b21f105fa9817b625103273caf46072628207e81bc13ac6ba18cdd3e93b97c9761730eb14ce36464cc997075;010001;1;0;0;0;&lt;/i&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
After adding that revocation entry to our certs database, ClamAV now flags the sample as a virus:&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-Ynr4sVyF9Bk/URvUMhrkVqI/AAAAAAAAGm4/8AfYdgoR0mU/s1600/Screen+Shot+2013-02-13+at+12.57.51+PM.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="203" src="http://1.bp.blogspot.com/-Ynr4sVyF9Bk/URvUMhrkVqI/AAAAAAAAGm4/8AfYdgoR0mU/s320/Screen+Shot+2013-02-13+at+12.57.51+PM.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;span style="font-family: Courier New, Courier, monospace;"&gt;clamscan&lt;/span&gt; Reporting Virus&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=4TYye-pOCWA:Xq9QaSO4LPM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=4TYye-pOCWA:Xq9QaSO4LPM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=4TYye-pOCWA:Xq9QaSO4LPM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=4TYye-pOCWA:Xq9QaSO4LPM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/4TYye-pOCWA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/5831044431318232222/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2013/02/authenticode-certificate-chain.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/5831044431318232222?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/5831044431318232222?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/4TYye-pOCWA/authenticode-certificate-chain.html" title="Authenticode Certificate Chain Verification" /><author><name>Shawn Webb</name><uri>http://www.blogger.com/profile/17982634013445041029</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-uO6NcqTngQc/URqrUB4kLLI/AAAAAAAAGmU/_k4dEhBScBs/s72-c/2013-02-12+1551+Authenticode+bit9.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://blog.clamav.net/2013/02/authenticode-certificate-chain.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0MGQ3kzfip7ImA9WhNXEUw.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-1372983189068825695</id><published>2012-11-27T16:54:00.000-05:00</published><updated>2012-11-28T11:17:02.786-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-11-28T11:17:02.786-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><title>Contribute signatures to ClamAV</title><content type="html">Back in February, Joel Esler who is our&amp;nbsp;Open Source Community Manager,&amp;nbsp;&lt;a href="http://blog.snort.org/2012/02/community-submissions-to-vrt-ruleset.html"&gt;explained&lt;/a&gt;&amp;nbsp;how you could contribute rules to Snort.&amp;nbsp;We just wanted to let you know that the VRT is seeking and accepting your contribution on the ClamAV side as well.&lt;br /&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
One of the best features of ClamAV is the&amp;nbsp;openness&amp;nbsp;of the signatures database. There are very few anti-malware products out there that will allow you see exactly how a signature is constructed and let you use your &amp;nbsp;own custom signatures. We strive to provide the best protection we can to our users through the official signature releases we provide several times a day. However, the nature of our field makes it that you will at some point (if you haven't already) come&amp;nbsp;across&amp;nbsp;malware for which there are no official signatures to detect it.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
That's where your contribution is sought and would be highly appreciated. If you come across malware that isn't detected with the official ClamAV signatures and you have your own signature to detect it, please provide it to us! It will go through our regular QA cycle and we will provide you with personal feedback. Your signature will be&amp;nbsp;tweaked&amp;nbsp;if necessary and tested against our clean files in order to prevent false positives once released. We will also give you credit for the signature your contributed unless you choose to remain&amp;nbsp;anonymous.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
You have a few ways of contributing signatures:&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
- Go to http://www.clamav.net/lang/en/sendvirus/submit-malware/&amp;nbsp;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-mWH6Yc2VuFA/ULUyPMhzQ4I/AAAAAAAADRw/6I7Kf3MxqXs/s1600/Screen+Shot+2012-11-27+at+4.33.08+PM.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/-mWH6Yc2VuFA/ULUyPMhzQ4I/AAAAAAAADRw/6I7Kf3MxqXs/s320/Screen+Shot+2012-11-27+at+4.33.08+PM.png" width="309" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
In the description field, provide your signature along with supporting evidence. Attach your sample and submit.&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
- Submit your password protected zip (a typical password is 'infected') along with your research and signature via email to vrt[at]sourcefire.com&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;
We prefer "body-based" signatures as opposed to "checksum-based" signatures. Hex (body) signatures are based on a fragment of a malware sample's body converted into a hexadecimal string which can be extended using various wildcards. More on&amp;nbsp;how to write ClamAV signatures&amp;nbsp;&lt;a href="http://www.clamav.net/doc/webinars/Webinar-Alain-2009-03-04.pdf"&gt;here&lt;/a&gt; and &lt;a href="http://www.clamav.net/doc/latest/signatures.pdf"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Of course we are always accepting false positive submissions &lt;a href="http://www.clamav.net/lang/en/sendvirus/submit-fp/"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=gktduiY-ZEI:aqn8Dxx59JY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=gktduiY-ZEI:aqn8Dxx59JY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=gktduiY-ZEI:aqn8Dxx59JY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=gktduiY-ZEI:aqn8Dxx59JY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/gktduiY-ZEI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/1372983189068825695/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2012/11/contribute-signatures-to-clamav.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/1372983189068825695?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/1372983189068825695?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/gktduiY-ZEI/contribute-signatures-to-clamav.html" title="Contribute signatures to ClamAV" /><author><name>Alain Zidouemba</name><uri>http://www.blogger.com/profile/02483121662356945808</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-mWH6Yc2VuFA/ULUyPMhzQ4I/AAAAAAAADRw/6I7Kf3MxqXs/s72-c/Screen+Shot+2012-11-27+at+4.33.08+PM.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://blog.clamav.net/2012/11/contribute-signatures-to-clamav.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkIDQHo-eyp7ImA9WhJaGE4.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-30587074149336876</id><published>2012-10-09T23:09:00.003-04:00</published><updated>2012-10-09T23:09:31.453-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-10-09T23:09:31.453-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><title>Open Source Antivirus: ClamAV by Dejan Lukan</title><content type="html">For someone just getting started with ClamAV, I noticed this easy to read and understand blog post &lt;a href="http://resources.infosecinstitute.com/open-source-antivirus-clamav/" target="_blank"&gt;here&lt;/a&gt;. &amp;nbsp;If you know someone who is just getting started with ClamAV, or you yourself came to this blog looking to get started. &amp;nbsp;Check that blog post out!&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=-aL4n3IoQ8Q:YuntvrFRqIY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=-aL4n3IoQ8Q:YuntvrFRqIY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=-aL4n3IoQ8Q:YuntvrFRqIY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=-aL4n3IoQ8Q:YuntvrFRqIY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/-aL4n3IoQ8Q" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/30587074149336876/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2012/10/open-source-antivirus-clamav-by-dejan.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/30587074149336876?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/30587074149336876?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/-aL4n3IoQ8Q/open-source-antivirus-clamav-by-dejan.html" title="Open Source Antivirus: ClamAV by Dejan Lukan" /><author><name>Joel Esler</name><uri>http://www.blogger.com/profile/03205477151965113876</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.clamav.net/2012/10/open-source-antivirus-clamav-by-dejan.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkEER3k9eip7ImA9WhJbFks.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-3689258618724537573</id><published>2012-09-25T17:37:00.005-04:00</published><updated>2012-09-26T09:03:26.762-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-09-26T09:03:26.762-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="faq" /><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><title>ClamAV Wiki Documents</title><content type="html">We've had much interest in the documents that were contained within our Wiki before we took it down here at ClamAV. &amp;nbsp;We've managed to salvage the useful pieces of the Wiki and publish them on our github site. &amp;nbsp;Check it out here:&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://github.com/vrtadmin/clamav-faq"&gt;https://github.com/vrtadmin/clamav-faq&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=5IzHl0XlIBM:2GwYZbYMltU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=5IzHl0XlIBM:2GwYZbYMltU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=5IzHl0XlIBM:2GwYZbYMltU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=5IzHl0XlIBM:2GwYZbYMltU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/5IzHl0XlIBM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/3689258618724537573/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2012/09/clamav-faq-documents.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/3689258618724537573?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/3689258618724537573?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/5IzHl0XlIBM/clamav-faq-documents.html" title="ClamAV Wiki Documents" /><author><name>Joel Esler</name><uri>http://www.blogger.com/profile/03205477151965113876</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://blog.clamav.net/2012/09/clamav-faq-documents.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUcEQXg_fyp7ImA9WhJbEE0.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-1692062890477592727</id><published>2012-09-18T18:23:00.000-04:00</published><updated>2012-09-18T18:23:20.647-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-09-18T18:23:20.647-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="statistics" /><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><title>ClamAV Stats, we need more of them, we need your help</title><content type="html">We've been working pretty hard behind the scenes over here on ClamAV, its backend infrastructure, and moving the codebase as well as its detection up the ladder.&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;In order for us to get some accurate statistics about what you all are seeing out there, in the field, we need as many people as possible to "opt-in" to some statistics gathering features that we have built into the code base.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;If you've ever browsed around ClamAV.net, I'm sure you've probably bumped into this page:&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.clamav.net/lang/en/download/cvd/malware-stats/"&gt;http://www.clamav.net/lang/en/download/cvd/malware-stats/&lt;/a&gt; at some point. &amp;nbsp;These are statistics that are provided by you all, the users of ClamAV, collected and correlated on our backend systems here. &amp;nbsp;It allows us to see trends across signatures and allows us to check in on what you are seeing in the actual real world.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;We need more people to opt-in to this feature. &amp;nbsp;We are looking at growing the detection rate and feature set of ClamAV's detection functionality, and this type of data will allow us to see where we need to pinpoint resources.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;If you can participate in the program, please go here:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.clamav.net/lang/en/faq/faq-cctts/stats-howto/"&gt;http://www.clamav.net/lang/en/faq/faq-cctts/stats-howto/&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;Follow the instructions above and you should be good to go! &amp;nbsp;Thanks!&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=n1pP_-q8Jgc:VB1bDkC2xXo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=n1pP_-q8Jgc:VB1bDkC2xXo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=n1pP_-q8Jgc:VB1bDkC2xXo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=n1pP_-q8Jgc:VB1bDkC2xXo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/n1pP_-q8Jgc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/1692062890477592727/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2012/09/clamav-stats-we-need-more-of-them-we.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/1692062890477592727?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/1692062890477592727?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/n1pP_-q8Jgc/clamav-stats-we-need-more-of-them-we.html" title="ClamAV Stats, we need more of them, we need your help" /><author><name>Joel Esler</name><uri>https://plus.google.com/106448761108546578724</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh6.googleusercontent.com/-75CehHVGXxA/AAAAAAAAAAI/AAAAAAAAAoU/M0az1QplMMM/s512-c/photo.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.clamav.net/2012/09/clamav-stats-we-need-more-of-them-we.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C08HSHY4fip7ImA9WhJbEE0.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-4000888398256357481</id><published>2012-09-18T16:57:00.002-04:00</published><updated>2012-09-18T16:57:19.836-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-09-18T16:57:19.836-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="patch release" /><category scheme="http://www.blogger.com/atom/ns#" term="windows" /><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><title>Windows versions of ClamAV 0.97.6 posted!</title><content type="html">All:&lt;br /&gt;
&lt;br /&gt;
If you are a Windows user of ClamAV, you'll be happy to know that we have released the Windows builds for ClamAV 0.97.6 to our Sourceforge site here:&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://sourceforge.net/projects/clamav/files/clamav/win32/0.97.6/"&gt;http://sourceforge.net/projects/clamav/files/clamav/win32/0.97.6/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Please feel free to download, use, and provide feedback via the ClamAV-Users list here:&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://lists.clamav.net/mailman/listinfo/clamav-users"&gt;http://lists.clamav.net/mailman/listinfo/clamav-users&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Thanks!&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
Joel Esler&lt;br /&gt;
Senior Research Engineer, VRT&lt;br /&gt;
OpenSource Community Manager&lt;br /&gt;
Sourcefire&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=MBYV10wE8gs:bm5CYTMMxmA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=MBYV10wE8gs:bm5CYTMMxmA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=MBYV10wE8gs:bm5CYTMMxmA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=MBYV10wE8gs:bm5CYTMMxmA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/MBYV10wE8gs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/4000888398256357481/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2012/09/windows-versions-of-clamav-0976-posted.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/4000888398256357481?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/4000888398256357481?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/MBYV10wE8gs/windows-versions-of-clamav-0976-posted.html" title="Windows versions of ClamAV 0.97.6 posted!" /><author><name>Joel Esler</name><uri>https://plus.google.com/106448761108546578724</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh6.googleusercontent.com/-75CehHVGXxA/AAAAAAAAAAI/AAAAAAAAAoU/M0az1QplMMM/s512-c/photo.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.clamav.net/2012/09/windows-versions-of-clamav-0976-posted.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkIMQXg7cCp7ImA9WhJUGUw.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-2942856304603522688</id><published>2012-09-17T15:36:00.000-04:00</published><updated>2012-09-17T15:36:20.608-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-09-17T15:36:20.608-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="patch release" /><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><title>ClamAV 0.97.6 has been released.</title><content type="html">&lt;span style="font-family: Helvetica;"&gt;Dear ClamAV users,&lt;/span&gt;&lt;br /&gt;
&lt;br style="font-family: Helvetica;" /&gt; &lt;span style="font-family: Helvetica;"&gt;ClamAV 0.97.6 includes minor bug fixes and detection improvements.&lt;/span&gt;&lt;br /&gt;
&lt;br style="font-family: Helvetica;" /&gt; &lt;span style="font-family: Helvetica;"&gt;Download:&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;&lt;a href="http://downloads.sourceforge.net/clamav/clamav-0.97.6.tar.gz"&gt;http://downloads.sourceforge.net/clamav/clamav-0.97.6.tar.gz&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Helvetica;"&gt;PGP sig:&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;&lt;a href="http://downloads.sourceforge.net/clamav/clamav-0.97.6.tar.gz.sig"&gt;http://downloads.sourceforge.net/clamav/clamav-0.97.6.tar.gz.sig&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Helvetica;"&gt;ChangeLog:&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;&lt;a href="https://github.com/vrtadmin/clamav-devel/blob/0.97/ChangeLog"&gt;https://github.com/vrtadmin/clamav-devel/blob/0.97/ChangeLog&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div style="font-family: Helvetica;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="font-family: Helvetica;"&gt;--&lt;/div&gt;&lt;div style="font-family: Helvetica;"&gt;The ClamAV team (&lt;a href="http://www.clamav.net/lang/en/about/team/"&gt;http://www.clamav.net/lang/en/about/team/&lt;/a&gt;)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=CNeEoTBGv6k:WZKvg963wss:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=CNeEoTBGv6k:WZKvg963wss:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=CNeEoTBGv6k:WZKvg963wss:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=CNeEoTBGv6k:WZKvg963wss:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/CNeEoTBGv6k" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/2942856304603522688/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2012/09/clamav-0976-has-been-released.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/2942856304603522688?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/2942856304603522688?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/CNeEoTBGv6k/clamav-0976-has-been-released.html" title="ClamAV 0.97.6 has been released." /><author><name>Joel Esler</name><uri>https://plus.google.com/106448761108546578724</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh6.googleusercontent.com/-75CehHVGXxA/AAAAAAAAAAI/AAAAAAAAAoU/M0az1QplMMM/s512-c/photo.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.clamav.net/2012/09/clamav-0976-has-been-released.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C08ER3cyeSp7ImA9WhJSE08.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-4239923057572534389</id><published>2012-07-03T09:23:00.000-04:00</published><updated>2012-07-03T09:23:26.991-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-07-03T09:23:26.991-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="documentation" /><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><title>ClamAV's Wiki</title><content type="html">The ClamAv Wiki is currently down. &amp;nbsp;It hadn't been updated for some time (several years!) and it was time to covert it into something more useable.&lt;br /&gt;
&lt;br /&gt;
We are currently converting the relevant documentation that was in the Wiki into something more useful and it will be forthcoming.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=1tYQrHcgJNE:sC2GGs3K_Ds:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=1tYQrHcgJNE:sC2GGs3K_Ds:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=1tYQrHcgJNE:sC2GGs3K_Ds:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=1tYQrHcgJNE:sC2GGs3K_Ds:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/1tYQrHcgJNE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/4239923057572534389/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2012/07/clamavs-wiki.html#comment-form" title="6 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/4239923057572534389?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/4239923057572534389?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/1tYQrHcgJNE/clamavs-wiki.html" title="ClamAV's Wiki" /><author><name>Joel Esler</name><uri>https://plus.google.com/106448761108546578724</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh6.googleusercontent.com/-75CehHVGXxA/AAAAAAAAAAI/AAAAAAAAAoU/M0az1QplMMM/s512-c/photo.jpg" /></author><thr:total>6</thr:total><feedburner:origLink>http://blog.clamav.net/2012/07/clamavs-wiki.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0QGRHs5cSp7ImA9WhJTE0Q.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-5297733813094195964</id><published>2012-06-22T14:55:00.000-04:00</published><updated>2012-06-22T14:55:25.529-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-06-22T14:55:25.529-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="vrt" /><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><category scheme="http://www.blogger.com/atom/ns#" term="team" /><title>Introducing the new ClamAV team</title><content type="html">Earlier this week we announced a new chapter for ClamAV with the departure of Tomasz Kojm, Alberto Wu, Luca Gibelli and Edwin Török. While we are sad to see them go, we are grateful for the contributions they have made and are committed to carrying on the project with the community in mind.&lt;br /&gt;
&lt;br /&gt;
As Tomasz mentioned in his own email, ClamAV just had its 10th birthday. Over the years we've been able to integrate ClamAV into our own product suite and it is now used by millions of mail filters, operating systems and millions of file scans per day. It's big, and we want it to be even bigger, with open source commitment at its core.&lt;br /&gt;
&lt;br /&gt;
So, now that we've begun this new chapter, I’d like to introduce you to some new members of the ClamAV team.  These folks might be new to ClamAV, but they have been with the Sourcefire Vulnerability Research Team (VRT) for quite some time, and all have worked on other open source projects. Without further ado, they are:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Matthew Olney&lt;/b&gt; is the project development lead for ClamAV and lead architect for the Razorback framework.  Pulling from his experience as a network and security engineer, he’s also a detection specialist for Snort and a frequent contributor of signatures to the ClamAV engine itself.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Ryan Pentney&lt;/b&gt; is the lead bytecode engine developer for ClamAV; a perfect complement to his role as lead developer for file format detection for the Razorback framework.  He also is a contributor to both the Snort and ClamAV engines.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Tom Judge&lt;/b&gt; has a strong background in systems and security operations. He is a FreeBSD committer, a lead developer for the Razorback framework and a long-time user of ClamAV.  On the ClamAV development team, he concentrates on FireAMP integration, virtual machine interfacing and freshclam development.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;David Raynor&lt;/b&gt; is the core engine developer for ClamAV.  He was a developer of a major scalable security system for the United States Department of Homeland Security before coming to Sourcefire.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Nigel Houghton&lt;/b&gt; has been with Sourcefire as the lead of the Department of Intelligence Excellence for almost 10 years.  Nigel has vast knowledge of programming, operating systems, administration, and security.  His team is responsible for the ClamAV supporting infrastructure as well as releasing signature updates.&lt;br /&gt;
&lt;br /&gt;
As I mentioned, all of the above are members of the VRT, led by Matt Watchinski, who has overseen the ClamAV project since Sourcefire acquired it in 2007.  We remain committed to continuing the open source nature of the project, pushing the growth of the project even farther.  &lt;br /&gt;
&lt;br /&gt;
As always, you can reach us on the ClamAV Mailing lists found here: &lt;a href="http://www.clamav.net/lang/en/ml/"&gt;http://www.clamav.net/lang/en/ml/&lt;/a&gt;.  We look forward to hearing your ideas and feedback.  Thanks for using ClamAV and we look forward to working with you.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Joel Esler&lt;br /&gt;
Open Source Community Manager&lt;br /&gt;
Senior Research Engineer, VRT&lt;br /&gt;
Sourcefire&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=696757z7Hq0:UOPoJ8G6g30:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=696757z7Hq0:UOPoJ8G6g30:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=696757z7Hq0:UOPoJ8G6g30:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=696757z7Hq0:UOPoJ8G6g30:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/696757z7Hq0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/5297733813094195964/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2012/06/introducing-new-clamav-team.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/5297733813094195964?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/5297733813094195964?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/696757z7Hq0/introducing-new-clamav-team.html" title="Introducing the new ClamAV team" /><author><name>Joel Esler</name><uri>https://plus.google.com/106448761108546578724</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh6.googleusercontent.com/-75CehHVGXxA/AAAAAAAAAAI/AAAAAAAAAoU/M0az1QplMMM/s512-c/photo.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.clamav.net/2012/06/introducing-new-clamav-team.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkYCQ30_fyp7ImA9WhJTEUw.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-905546765177783688</id><published>2012-06-19T11:02:00.001-04:00</published><updated>2012-06-19T11:02:42.347-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-06-19T11:02:42.347-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><title>A New Chapter for ClamAV</title><content type="html">Earlier today, Tomasz Kojm sent an email to the ClamAV mailing list on behalf of himself and three of his teammates - Alberto Wu, Luca Gibelli, Edwin Török. As he wrote in his email, since they joined us via acquisition in 2007, we’ve been able to work together on some great projects. And now, as we celebrate the 10-year anniversary of ClamAV, the team has decided to move onto new development projects outside of Sourcefire. From his email:
&lt;br /&gt;
&lt;blockquote class="tr_bq"&gt;
“...it is time for us to make a change. ClamAV is now mature software and we are confident that Sourcefire will successfully continue its development, move it forward and maintain the integrity of its infrastructure.”
&lt;/blockquote&gt;
And mature it has. Today the solution has more than 2 million active installations and scans hundreds of millions of files every day. I am incredibly proud of the leadership of Tomasz and the tenacity of his team in all of these development projects. While I am remiss to see them go, I am excited and looking forward to what they come up with next.
&lt;br /&gt;
&lt;br /&gt;
Now, what does this mean for you, our ClamAV users and community? The good news is that I will continue to oversee the development project, as I have done since our acquisition of the company in 2007. &amp;nbsp;&lt;a href="mailto:jesler@sourcefire.com"&gt;Joel Esler&lt;/a&gt;, our Open Source community manager, will still be your main point of contact. I do want you to be aware of a few changes to come:
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="background-color: white;"&gt;ClamAV source package signing.  The signing key will no longer be tkojm@clamav.net.  It will be research@sourcefire.com.  This is the main VRT GPG key, and has been signed by tkojm@clamav.net.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="background-color: white;"&gt;New faces&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="background-color: white;"&gt;Matt Olney&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="background-color: white;"&gt;David Raynor&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="background-color: white;"&gt;Tom Judge&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="background-color: white;"&gt;Nigel Houghton&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;li&gt;&lt;span style="background-color: white;"&gt;0.97.5 New Release&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
If you need to reach us for any reason, email &lt;a href="mailto:vrt@sourcefire.com"&gt;vrt@sourcefire.com&lt;/a&gt;. In the meantime, please join me in expressing thanks to Tomasz, Alberto, Luca and Edwin for all of their contributions to the ClamAV project.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=p-RwHk8Aq9c:yJELHn7p1s8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=p-RwHk8Aq9c:yJELHn7p1s8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=p-RwHk8Aq9c:yJELHn7p1s8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=p-RwHk8Aq9c:yJELHn7p1s8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/p-RwHk8Aq9c" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/905546765177783688/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2012/06/new-chapter-for-clamav.html#comment-form" title="4 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/905546765177783688?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/905546765177783688?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/p-RwHk8Aq9c/new-chapter-for-clamav.html" title="A New Chapter for ClamAV" /><author><name>Matthew Watchinski</name><uri>http://www.blogger.com/profile/11852187130907898252</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>4</thr:total><feedburner:origLink>http://blog.clamav.net/2012/06/new-chapter-for-clamav.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0ACRn89cSp7ImA9WhVaF0s.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-5538768326730518802</id><published>2012-06-15T10:16:00.000-04:00</published><updated>2012-06-15T10:16:07.169-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-06-15T10:16:07.169-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="patch release" /><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><title>ClamAV 0.97.5 has been released!</title><content type="html">Just released is version 0.97.5 of&amp;nbsp;ClamAV. &amp;nbsp;Below is the changelog:&lt;br /&gt;
&lt;br /&gt;
&lt;pre&gt;Fri Jun 1 13:15:50 EST 2012 (dar)
---------------------------------
 * libclamav: Scan output at end of truncated tar (bb#4625) 

Wed May 30 17:27:00 EST 2012 (dar)
----------------------------------
 * libclamav: Fix handling of tar file with malformed header
         (bb#4627)

Fri May 25 13:05:40 EST 2012 (dar)
----------------------------------
 * libclamav: Scan chm with invalid handling (bb#4626)

Thu May 10 15:45:56 CEST 2012 (tk)
----------------------------------
 * freshclam: give custom dbs higher priority during update

Tue May  8 15:31:51 CEST 2012 (acab)
------------------------------------
 * libclamav: detect read races and abort the scan with an error
       (bb#4669)

Tue Apr 10 17:04:20 CEST 2012 (tk)
----------------------------------
 * libclamav/pe.c: drop old header check (bb#4699)&lt;/pre&gt;
&lt;pre&gt;
&lt;/pre&gt;
We are currently experiencing some problems updating our freshmeat account, however, in the meantime ClamAV, as always, is available from &lt;a href="http://www.clamav.net/"&gt;http://www.clamav.net&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=yLJH3KhxAG4:Ncl2x1E2f50:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=yLJH3KhxAG4:Ncl2x1E2f50:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=yLJH3KhxAG4:Ncl2x1E2f50:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=yLJH3KhxAG4:Ncl2x1E2f50:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/yLJH3KhxAG4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/5538768326730518802/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2012/06/clamav-0975-has-been-released.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/5538768326730518802?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/5538768326730518802?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/yLJH3KhxAG4/clamav-0975-has-been-released.html" title="ClamAV 0.97.5 has been released!" /><author><name>Joel Esler</name><uri>https://plus.google.com/106448761108546578724</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh6.googleusercontent.com/-75CehHVGXxA/AAAAAAAAAAI/AAAAAAAAAoU/M0az1QplMMM/s512-c/photo.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.clamav.net/2012/06/clamav-0975-has-been-released.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ck4BRXg9fyp7ImA9WhVbFUs.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-3023057051937649144</id><published>2012-06-01T10:29:00.000-04:00</published><updated>2012-06-01T10:29:14.667-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-06-01T10:29:14.667-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="vrt" /><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><category scheme="http://www.blogger.com/atom/ns#" term="test" /><title>ClamAV vs. ContentIQ Test series</title><content type="html">I wanted to call attention to a series of blog posts that Alain is writing over on the VRT blog about the ContentIQ test and ClamAV's results with that test. &amp;nbsp;Enjoy:&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://vrt-blog.snort.org/2012/02/clamav-vs-content-iq-test-part-1.html"&gt;http://vrt-blog.snort.org/2012/02/clamav-vs-content-iq-test-part-1.html&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://vrt-blog.snort.org/2012/03/clamav-vs-content-iq-test-part-2.html"&gt;http://vrt-blog.snort.org/2012/03/clamav-vs-content-iq-test-part-2.html&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://vrt-blog.snort.org/2012/04/clamav-vs-content-iq-test-part-3.html"&gt;http://vrt-blog.snort.org/2012/04/clamav-vs-content-iq-test-part-3.html&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=ytZJZMQL5js:SH1outy8JqE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=ytZJZMQL5js:SH1outy8JqE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=ytZJZMQL5js:SH1outy8JqE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=ytZJZMQL5js:SH1outy8JqE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/ytZJZMQL5js" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/3023057051937649144/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2012/06/clamav-vs-contentiq-test-series.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/3023057051937649144?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/3023057051937649144?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/ytZJZMQL5js/clamav-vs-contentiq-test-series.html" title="ClamAV vs. ContentIQ Test series" /><author><name>Joel Esler</name><uri>https://plus.google.com/106448761108546578724</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh6.googleusercontent.com/-75CehHVGXxA/AAAAAAAAAAI/AAAAAAAAAoU/M0az1QplMMM/s512-c/photo.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.clamav.net/2012/06/clamav-vs-contentiq-test-series.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0ENQXw-fSp7ImA9WhVbE00.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-2090452527930686977</id><published>2012-05-28T08:56:00.002-04:00</published><updated>2012-05-29T12:41:30.255-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-29T12:41:30.255-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><category scheme="http://www.blogger.com/atom/ns#" term="Ubuntu" /><title>Building a Computer Disaster Recovery Toolkit</title><content type="html">In this article over at CNET, one of the things they discuss is using An Ubuntu Live CD, included with ClamAV to help repair infected computers. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://cnet.com.au/building-a-computer-disaster-recovery-toolkit-339338606.htm"&gt;Article here&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=0eWotB3ERrg:ycledJEmpnI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=0eWotB3ERrg:ycledJEmpnI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=0eWotB3ERrg:ycledJEmpnI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=0eWotB3ERrg:ycledJEmpnI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/0eWotB3ERrg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/2090452527930686977/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2012/05/building-computer-disaster-recovery.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/2090452527930686977?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/2090452527930686977?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/0eWotB3ERrg/building-computer-disaster-recovery.html" title="Building a Computer Disaster Recovery Toolkit" /><author><name>Joel Esler</name><uri>https://plus.google.com/106448761108546578724</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh6.googleusercontent.com/-75CehHVGXxA/AAAAAAAAAAI/AAAAAAAAAoU/M0az1QplMMM/s512-c/photo.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.clamav.net/2012/05/building-computer-disaster-recovery.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A04AQn04cSp7ImA9WhVUGU0.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-7868481611500959451</id><published>2012-05-24T21:38:00.001-04:00</published><updated>2012-05-24T21:39:03.339-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-24T21:39:03.339-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="windows" /><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><title>ClamAV as a service on Windows with Kerio Connect / Mailserver</title><content type="html">A quick blog post about installing ClamWin with Kerio Connect. &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://blog.campodoro.org/?p=269"&gt;http://blog.campodoro.org/?p=269&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=C5HwiP-knEw:iETcwjat3N8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=C5HwiP-knEw:iETcwjat3N8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=C5HwiP-knEw:iETcwjat3N8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=C5HwiP-knEw:iETcwjat3N8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/C5HwiP-knEw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/7868481611500959451/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2012/05/clamav-as-service-on-windows-with-kerio.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/7868481611500959451?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/7868481611500959451?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/C5HwiP-knEw/clamav-as-service-on-windows-with-kerio.html" title="ClamAV as a service on Windows with Kerio Connect / Mailserver" /><author><name>Joel Esler</name><uri>https://plus.google.com/106448761108546578724</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh6.googleusercontent.com/-75CehHVGXxA/AAAAAAAAAAI/AAAAAAAAAoU/M0az1QplMMM/s512-c/photo.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.clamav.net/2012/05/clamav-as-service-on-windows-with-kerio.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEICSXg6fyp7ImA9WhVQGUQ.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-6010338653445591197</id><published>2012-04-09T14:36:00.000-04:00</published><updated>2012-04-09T14:36:08.617-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-04-09T14:36:08.617-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="vrt" /><category scheme="http://www.blogger.com/atom/ns#" term="intern" /><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><title>ClamAV needs an Intern</title><content type="html">The VRT is looking for an Intern to assist with the ClamAV and Razorback projects.  If you are a C coder, we'd like to hear from you.&lt;br /&gt;
&lt;br /&gt;
We are looking for resumes sent to research [at] sourcefire.com. &amp;nbsp;Please let us know that you are interested in the Intern position with the VRT, and that you saw the blog post here on the ClamAV blog!&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=SC7ZZr1XVBI:jOwinEwP-tc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=SC7ZZr1XVBI:jOwinEwP-tc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=SC7ZZr1XVBI:jOwinEwP-tc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=SC7ZZr1XVBI:jOwinEwP-tc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/SC7ZZr1XVBI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/6010338653445591197/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2012/04/clamav-needs-intern.html#comment-form" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/6010338653445591197?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/6010338653445591197?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/SC7ZZr1XVBI/clamav-needs-intern.html" title="ClamAV needs an Intern" /><author><name>Joel Esler</name><uri>https://plus.google.com/106448761108546578724</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh6.googleusercontent.com/-75CehHVGXxA/AAAAAAAAAAI/AAAAAAAAAoU/M0az1QplMMM/s512-c/photo.jpg" /></author><thr:total>2</thr:total><feedburner:origLink>http://blog.clamav.net/2012/04/clamav-needs-intern.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0ICRXw9eSp7ImA9WhVRE0k.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-5619406457039798294</id><published>2012-03-21T10:52:00.003-04:00</published><updated>2012-03-21T10:52:44.261-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-03-21T10:52:44.261-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><category scheme="http://www.blogger.com/atom/ns#" term="osx" /><title>On-access scanning for OS X</title><content type="html">&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;The ClamAuth kernel extension enables ClamAV to provide on-access scanning&amp;nbsp;for Mac OS X 10.5 and later.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;The current version works in a passive mode&amp;nbsp;only - ClamAV will log the detection but won't block access to the infected&amp;nbsp;file. However, it's possible to perform special actions (eg. quarantine&amp;nbsp;files) with the VirusEvent directive of clamd.&lt;br /&gt;&lt;br /&gt;Usage&lt;br /&gt;-----&lt;br /&gt;&lt;br /&gt;1. Run ClamAuth_load to load the kernel extension (you can edit the&amp;nbsp;script to change or add more paths that will be monitored).&lt;br /&gt;2. Add "ClamAuth yes" to your clamd.conf (ClamAV 0.97.4) or&amp;nbsp;"ScanOnAccess yes" (ClamAV-devel)&lt;br /&gt;3. Start clamd with root privileges ('sudo /usr/local/sbin/clamd')&lt;br /&gt;&lt;br /&gt;If clamd properly connects to the driver, you should see a line like this&amp;nbsp;in the log file:&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;blockquote class="tr_bq"&gt;
&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;ClamAuth: Driver version: 0.3, protocol version: 2&lt;/span&gt;&lt;/blockquote&gt;
&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;ClamAV is now monitoring the paths specified in ClamAuth_load.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;If you have any questions or feedback about this module please send it to the ClamAV mailing list here:&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;a href="http://www.clamav.net/lang/en/ml/"&gt;http://www.clamav.net/lang/en/ml/&lt;/a&gt;&lt;/span&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=6twuPLs51OA:nfufY_8Vuw0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=6twuPLs51OA:nfufY_8Vuw0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=6twuPLs51OA:nfufY_8Vuw0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=6twuPLs51OA:nfufY_8Vuw0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/6twuPLs51OA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/5619406457039798294/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2012/03/on-access-scanning-for-os-x.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/5619406457039798294?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/5619406457039798294?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/6twuPLs51OA/on-access-scanning-for-os-x.html" title="On-access scanning for OS X" /><author><name>Joel Esler</name><uri>https://plus.google.com/106448761108546578724</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh6.googleusercontent.com/-75CehHVGXxA/AAAAAAAAAAI/AAAAAAAAAoU/M0az1QplMMM/s512-c/photo.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.clamav.net/2012/03/on-access-scanning-for-os-x.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0EEQHk7fyp7ImA9WhVREUs.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-7113584888255676181</id><published>2012-03-19T10:00:00.000-04:00</published><updated>2012-03-19T10:00:01.707-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-03-19T10:00:01.707-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="patch release" /><category scheme="http://www.blogger.com/atom/ns#" term="antivirus" /><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><title>ClamAV 0.97.4 has been released!</title><content type="html">ClamAV 0.97.4 includes minor bugfixes, detection improvements and&lt;br /&gt;
initial support for on-access scanning under Mac OS X (see&lt;br /&gt;
contrib/ClamAuth).&lt;br /&gt;
&lt;br /&gt;
This update is recommended for all users.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;pre style="white-space: pre-wrap; word-wrap: break-word;"&gt;Wed Feb 29 18:35:45 CET 2012 (acab)
-----------------------------------
 * libclamav/bytecode.c: reset to BYTECODE_AUTO mode at db reload so that
    we don't fail to re-enable or re-disable it again
    (bb#3789)

Tue Jan 17 11:15:57 CET 2012 (acab)
-----------------------------------
 * misc: performance improvement for HP-UX PA-RISC - patch from 
  Michael Pelletier &amp;lt;michael.v.pelletier*raytheon.com&amp;gt; (bb#3926)

Fri Nov  4 00:52:21 CET 2011 (acab)
-----------------------------------
 * libclamav/pe.c: parse vinfo where varfileinfo occours before stringfileinfo
     (bb#3062)

Fri Mar  2 19:48:36 CET 2012 (tk)
---------------------------------
 * clamd: add support for on-access scanning on OS X with ClamAuth (beta)

Wed Feb 29 17:02:18 EET 2012 (edwin)
------------------------------------
 * libclamav/bytecode_api*: Fix Sparc crash (bb #4324)

Tue Feb  7 23:23:48 CET 2012 (tk)
---------------------------------
 * libclamav: fix bytecode whitelisting

Wed Jan 25 18:56:44 CET 2012 (tk)
---------------------------------
 * libclamav: fix macro detection in OLE2BlockMacros (bb#4269)

Thu Dec  1 15:07:49 CET 2011 (tk)
---------------------------------
 * libclamav/readdb.c: allow comments in all db files (bb#3930)

Fri Nov 18 15:23:50 CET 2011 (tk)
---------------------------------
 * libclamav/scanners.c: use lsigs when scanning vba data (bb#3922)

Fri Nov 18 15:48:59 EET 2011 (edwin)
-----------------------------------
 * libclamav/matcher-hash.c: Fix SIGBUS on PA-RISC (big-endian) architectures (bb #3894).&lt;/pre&gt;
&lt;br /&gt;
&lt;br /&gt;
Download :&amp;nbsp;&lt;a href="http://downloads.sourceforge.net/clamav/clamav-0.97.4.tar.gz"&gt;http://downloads.sourceforge.net/clamav/clamav-0.97.4.tar.gz&lt;/a&gt;&lt;br /&gt;
PGP sig &amp;nbsp;:&amp;nbsp;&lt;a href="http://downloads.sourceforge.net/clamav/clamav-0.97.4.tar.gz.sig"&gt;http://downloads.sourceforge.net/clamav/clamav-0.97.4.tar.gz.sig&lt;/a&gt;&lt;br /&gt;
Bugfixes :&amp;nbsp;&lt;a href="http://www.clamav.net/release-info/bugs/0.97.4"&gt;http://www.clamav.net/release-info/bugs/0.97.4&lt;/a&gt;&lt;br /&gt;
ChangeLog:&amp;nbsp;&lt;a href="http://www.clamav.net/release-info/changelog/0.97.4"&gt;http://www.clamav.net/release-info/changelog/0.97.4&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=KfleM_8CcUI:RzHv2tkuzB4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=KfleM_8CcUI:RzHv2tkuzB4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=KfleM_8CcUI:RzHv2tkuzB4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=KfleM_8CcUI:RzHv2tkuzB4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/KfleM_8CcUI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/7113584888255676181/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2012/03/clamav-0974-has-been-released.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/7113584888255676181?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/7113584888255676181?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/KfleM_8CcUI/clamav-0974-has-been-released.html" title="ClamAV 0.97.4 has been released!" /><author><name>Joel Esler</name><uri>https://plus.google.com/106448761108546578724</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh6.googleusercontent.com/-75CehHVGXxA/AAAAAAAAAAI/AAAAAAAAAoU/M0az1QplMMM/s512-c/photo.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.clamav.net/2012/03/clamav-0974-has-been-released.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0IMSX0zfSp7ImA9WhVRE0k.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-4310435873549851866</id><published>2012-02-28T12:37:00.000-05:00</published><updated>2012-03-21T10:53:08.385-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-03-21T10:53:08.385-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="vrt" /><title>Are you a ninja? Want to become one?</title><content type="html">Then we want to talk to you! While you can look up &lt;a href="https://sourcefire.silkroad.com/epostings/index.cfm?fuseaction=app.welcome&amp;amp;category_id=14174&amp;amp;company_id=15640&amp;amp;version=1&amp;amp;startflag=1&amp;amp;parent=VRT%20%28Vulnerability%20Research%20Team%29&amp;amp;levelid1=14174"&gt;the different openings&lt;/a&gt; that the Vulnerability Research Team (VRT) has, what you won't see if why you should choose Sourcefire for your next job. This is why I love working here, in no particular order:&lt;br /&gt;
&lt;br /&gt;
1. The people. We come from different backgrounds and bring a wealth of talent and knowledge to the table. Most of us were using computers pre-Internet before we were 10 years old. Back then, our friends were just happy to have a gaming console and didn't see the point of having a computer. We are curious by nature and didn't stop learning when we got our various degrees. When you engage in conversation with the VRT, be assured that there will be someone who knows at least as much as you on any topic. The VRT is made of smart, smart! individuals and we are looking for people who are driven and can fit in the team culture.&lt;br /&gt;
&lt;br /&gt;
2.&amp;nbsp;Open-source philosophy. Whether it's ClamAV, Snort, or Razorback (and their respective signatures/rules), we believe in letting users see and understand what we do, how we do it, and why we do it. This pushes us to excel at our job and always put the customer first.&lt;br /&gt;
&lt;br /&gt;
3. Fun work environment. We are productive and have crunch times, yet we always know how to have fun. Do you know what "tea time" is? "Truffle shuffle"? "Hit box!"? Do you know what it is "to be slothed"? What does it mean when someone calls "car"? Who's the "grammar police"? Come find out :-)&lt;br /&gt;
&lt;br /&gt;
4. Hobbies. If you like biking, riding motorcycles, playing the guitar, photography, playing tennis or soccer, you will likely find an after-hours hangout buddy with similar interest in the VRT.&lt;br /&gt;
&lt;br /&gt;
5. Lunch. Delivered to you every day between 12PM and 2PM. Just choose what you like from 3 different and rotating restaurant menus and lookout for the the daily email that says that your lunch has arrived. For free. Yup, just like that (well technically it's part of your benefits).&lt;br /&gt;
&lt;br /&gt;
6. Training. Whether you want to informally learn about malware or vulnerability&amp;nbsp;research, attend a conference or a week-long training, or formally work towards a Bachelor's or Master's degree, we'll hook you up.&lt;br /&gt;
&lt;br /&gt;
7. Leadership and Innovation. &lt;a href="http://www.snort.org/"&gt;Snort&lt;/a&gt; is the de facto standard for Intrusion Detectio&lt;span style="font-family: Times, 'Times New Roman', serif;"&gt;n and Prevention. &lt;a href="http://www.clamav.net/"&gt;ClamAV&lt;/a&gt; sets&amp;nbsp;&lt;span style="background-color: white; line-height: 14px; outline-color: initial; outline-style: initial; outline-width: 0px;"&gt;the standard for open-source antivirus and anti-malware solutions. &lt;span style="color: black;"&gt;&lt;a href="http://labs.snort.org/razorback/"&gt;Razorback&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: white; line-height: 14px; outline-color: initial; outline-style: initial; outline-width: 0px;"&gt;advances complex threat detection and protection&lt;/span&gt;.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: Times, 'Times New Roman', serif;"&gt;I could really go on and on about why you should choose us. If you think you have the right skills, if you think you can grow and most importantly if you are driven, contact us with your resume at research at sourcefire dot com.&lt;/span&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=3T8mLEzOccQ:QsbfI1qvYt8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=3T8mLEzOccQ:QsbfI1qvYt8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=3T8mLEzOccQ:QsbfI1qvYt8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=3T8mLEzOccQ:QsbfI1qvYt8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/3T8mLEzOccQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/4310435873549851866/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2012/02/are-you-ninja-want-to-become-one.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/4310435873549851866?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/4310435873549851866?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/3T8mLEzOccQ/are-you-ninja-want-to-become-one.html" title="Are you a ninja? Want to become one?" /><author><name>Alain Zidouemba</name><uri>http://www.blogger.com/profile/02483121662356945808</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.clamav.net/2012/02/are-you-ninja-want-to-become-one.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0EESHYzcSp7ImA9WhVRE0k.&quot;"><id>tag:blogger.com,1999:blog-2366689974368239573.post-8730815172327517471</id><published>2012-01-25T08:19:00.000-05:00</published><updated>2012-03-21T10:53:29.889-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-03-21T10:53:29.889-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="snort" /><category scheme="http://www.blogger.com/atom/ns#" term="clamav" /><category scheme="http://www.blogger.com/atom/ns#" term="Sourcefire" /><title>Open Source Fact and Fiction: Sourcefire Stays True To Its Roots</title><content type="html">&lt;a href="http://www.networkworld.com/community/node/79655"&gt;Open Source Fact and Fiction: Sourcefire Stays True To Its Roots&lt;/a&gt;&lt;br /&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Alan Shimel writes a great article about our new product &lt;a href="http://www.sourcefire.com/security-technologies/advanced-malware-protection/fireamp"&gt;FireAMP&lt;/a&gt;, and it's roots, not only with ClamAV but many other OpenSource technologies.  It's a quick read, but really shows what we are trying to do here at Sourcefire and how OpenSource is not only the foundation of our products, but really, is baked into everything that we do here.&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=tX_883thtXE:B9KVi6m5CKU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=tX_883thtXE:B9KVi6m5CKU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?i=tX_883thtXE:B9KVi6m5CKU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Clamav?a=tX_883thtXE:B9KVi6m5CKU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Clamav?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Clamav/~4/tX_883thtXE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.clamav.net/feeds/8730815172327517471/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://blog.clamav.net/2012/01/open-source-fact-and-fiction-sourcefire.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/8730815172327517471?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2366689974368239573/posts/default/8730815172327517471?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Clamav/~3/tX_883thtXE/open-source-fact-and-fiction-sourcefire.html" title="Open Source Fact and Fiction: Sourcefire Stays True To Its Roots" /><author><name>Joel Esler</name><uri>https://plus.google.com/106448761108546578724</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh6.googleusercontent.com/-75CehHVGXxA/AAAAAAAAAAI/AAAAAAAAAoU/M0az1QplMMM/s512-c/photo.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.clamav.net/2012/01/open-source-fact-and-fiction-sourcefire.html</feedburner:origLink></entry></feed>
