News: 1669891864

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Twenty years on, command-line virus scanner ClamAV puts out version 1

(2022/12/01)


The ClamAV command-line virus scanner used on many Linux boxes has attained an important-looking milestone release: version 1.0.0.

It's not really the first finished version, of course. Open source version numbering is something of a work of fiction, up there with "Of course I love you" and "The check's in the post," but even so, this particular milestone has been a while in coming. [1]ClamAV , which describes itself as "the open-source standard for mail gateway-scanning software" , has finally [2]emitted an official one-point-zero version, only six months after its [3]20th birthday – and what's more, it's a long-term support release, too.

Original developer [4]Tomasz Kojm released the first version, 0.10, on May 8, 2002. As it's open source, since then, it's been ported to almost anything you're likely to find connected to the internet. It's included in the repos of most Linux distros, as well as FreeBSD, OpenBSD and NetBSD. It's also part of Apple's optional extra macOS Server package. Indeed it runs on most things, from OpenVMS to OS/2.

[5]

The project was [6]acquired by SourceFire in 2007, which itself was subsequently [7]bought by Cisco in 2013, and which still sponsors development.

[8]

[9]

After a few release candidates, the new version follows [10]version 0.105.1 which appeared in July. The [11]release notes don't contain any massive blockbuster new features, although the ability to scan inside encrypted Microsoft Excel .XLS files so long as they use the default password sounds useful.

ClamAV is a command-line virus scanner, rather than the sort of real-time antivirus protection program that most Windows users have to be familiar with. It's also important not to confuse it with the various add-on tools which wrap it in a GUI, such as [12]ClamXAV on macOS, which went commercial some years ago, although it remains try-before-you-buy.

[13]

ClamAV itself only runs when invoked, although it is a sophisticated tool which can look inside all manner of compressed file formats, performs multithreaded parallel scans, and can hook into kernel notification APIs enabling it to monitor specific folders for any changes in their contents.

[14]We need to talk about criminal hackers using Cobalt Strike, says Cisco Talos

[15]Unofficial fix emerges for Windows bug abused to infect home PCs with ransomware

[16]Apple boosts bug bounties but may not fix some bugs in past operating systems

[17]Could you not? BlackByte ransomware slinger twists the knife with data stealer

It runs perfectly well on Windows, but it's not a replacement for a proper antivirus program, which can also do things like scan programs as and when they're loaded into memory, block suspicious activities such as modifying executables, and so on. However, this does mean that you can safely run it alongside any Windows antivirus app, including the built-in one. (This is normally a no-no: don't run two resident antivirus shields at once, as they can prevent each other from working properly as well as destabilize your computer. The difference is that a simple scanner as well as a resident antivirus shield is fine.)

The Github [18]page contains versions in .DEB and .RPM format, as well as Windows 32-bit and 64-bit and a universal macOS package – and the source code, of course. Other OSes and distros will doubtless pick up the new version soon. ®

Get our [19]Tech Resources



[1] https://www.clamav.net/

[2] https://blog.clamav.net/2022/11/clamav-100-lts-released.html

[3] https://blog.clamav.net/2022/05/celebrating-20-years-of-clamav.html

[4] https://web.archive.org/web/20120206053729/http://www.emailbattles.com/2005/08/31/virus_aabejfhaib_ag/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y4iJTGa2SkDmYGMOYxNwdAAAAIo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[6] https://web.archive.org/web/20071215031743/http://www.clamav.org/2007/08/17/sourcefire-acquires-clamav/

[7] https://www.cisco.com/c/en/us/about/corporate-strategy-office/acquisitions/acquisitions-list-years.html

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y4iJTGa2SkDmYGMOYxNwdAAAAIo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y4iJTGa2SkDmYGMOYxNwdAAAAIo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://github.com/Cisco-Talos/clamav/releases/tag/clamav-0.105.1

[11] https://github.com/Cisco-Talos/clamav/releases/tag/clamav-1.0.0

[12] https://www.clamxav.com/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y4iJTGa2SkDmYGMOYxNwdAAAAIo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[14] https://www.theregister.com/2020/09/24/cobalt_strike_cisco_talos/

[15] https://www.theregister.com/2022/11/01/microsoft_motw_malware_flaw/

[16] https://www.theregister.com/2022/10/28/apple_boosts_bug_bounties_blogs/

[17] https://www.theregister.com/2022/10/24/blackbyte_ransomware_exbyte_extortion/

[18] https://github.com/Cisco-Talos/clamav/releases/

[19] https://whitepapers.theregister.com/



To program is to be.