Menu

Home

Andrea Russo

Clam sentinel is a program that detects file system changes and automatically scans the files added or modified using ClamWin. Require the installation of ClamWin. For Microsoft Windows 98/98SE/Me/2000/XP/Vista (tested) and Windows 7.


Project Members:


Discussion

  • Ubirajara Bandeira Jr

    Where can I download the source code?

     
    • Robert Scroggins

      Hello:

      Check the ClamWin FAQ link on the main web page for info regarding source
      code download. You could also do a search on the ClamWin site for "source
      code" "source code download" or something like that. If all else fails,
      get in touch with Alch/Sherpya, ClamWin developers, and ask them via the
      contact info on the main web page. If you come up with any improvements,
      be sure to let them know about it so other users can benefit.

      Thanks for being a ClamWin user!

      Regards,

      Bob Scroggins

      On Mon, Nov 27, 2017 at 5:58 AM, Ubirajara Bandeira Jr <kokbira@users.sf.net

      wrote:

      Where can I download the source code?

      Sent from sourceforge.net because you indicated interest in
      https://sourceforge.net/p/clamsentinel/wiki/Home/

      To unsubscribe from further messages, please visit
      https://sourceforge.net/auth/subscriptions/

       
      • Robert Scroggins

        Sorry.. I thought you were asking about the ClamWin source code. You can
        read about the Clam Sentinel source code by looking at the Code item in the
        main menu. You had better hurry because Source Forge is soon making a
        change--buy the end of November, I think.

        Regards,

        Robert Scroggins

        On Mon, Nov 27, 2017 at 9:47 AM, Robert Scroggins sentinelguy@users.sf.net
        wrote:

        Hello:

        Check the ClamWin FAQ link on the main web page for info regarding source
        code download. You could also do a search on the ClamWin site for "source
        code" "source code download" or something like that. If all else fails,
        get in touch with Alch/Sherpya, ClamWin developers, and ask them via the
        contact info on the main web page. If you come up with any improvements,
        be sure to let them know about it so other users can benefit.

        Thanks for being a ClamWin user!

        Regards,

        Bob Scroggins

        On Mon, Nov 27, 2017 at 5:58 AM, Ubirajara Bandeira Jr <
        kokbira@users.sf.net

        wrote:
        Where can I download the source code?

        Sent from sourceforge.net because you indicated interest in
        https://sourceforge.net/p/clamsentinel/wiki/Home/

        To unsubscribe from further messages, please visit
        https://sourceforge.net/auth/subscriptions/


        Sent from sourceforge.net because you indicated interest in
        https://sourceforge.net/p/clamsentinel/wiki/Home/

        To unsubscribe from further messages, please visit
        https://sourceforge.net/auth/subscriptions/

         
        • Ubirajara Bandeira Jr

          No, I am talking about ClamSentinel, not ClamWin.

          ClamSentinel is so interesting because it makes ClamWin do a proactive
          protection, but it would be improved to do more things and merged with
          ClamWin to become a complete solution.

          I would like to see the ClamSentinel code to see if I can contribute in
          some way.

          2017-11-28 12:59 GMT-03:00 Robert Scroggins sentinelguy@users.sf.net:

          Sorry.. I thought you were asking about the ClamWin source code. You can
          read about the Clam Sentinel source code by looking at the Code item in the
          main menu. You had better hurry because Source Forge is soon making a
          change--buy the end of November, I think.

          Regards,

          Robert Scroggins

          On Mon, Nov 27, 2017 at 9:47 AM, Robert Scroggins sentinelguy@users.sf.net
          wrote:

          Hello:

          Check the ClamWin FAQ link on the main web page for info regarding source
          code download. You could also do a search on the ClamWin site for "source
          code" "source code download" or something like that. If all else fails,
          get in touch with Alch/Sherpya, ClamWin developers, and ask them via the
          contact info on the main web page. If you come up with any improvements,
          be sure to let them know about it so other users can benefit.

          Thanks for being a ClamWin user!

          Regards,

          Bob Scroggins

          On Mon, Nov 27, 2017 at 5:58 AM, Ubirajara Bandeira Jr <
          kokbira@users.sf.net

          wrote:
          Where can I download the source code?

          Sent from sourceforge.net because you indicated interest in
          https://sourceforge.net/p/clamsentinel/wiki/Home/

          To unsubscribe from further messages, please visit
          https://sourceforge.net/auth/subscriptions/


          Sent from sourceforge.net because you indicated interest in
          https://sourceforge.net/p/clamsentinel/wiki/Home/

          To unsubscribe from further messages, please visit
          https://sourceforge.net/auth/subscriptions/


          Sent from sourceforge.net because you indicated interest in
          https://sourceforge.net/p/clamsentinel/wiki/Home/

          To unsubscribe from further messages, please visit
          https://sourceforge.net/auth/subscriptions/

           
          • Robert Scroggins

            Hello:

            If you will give me another email address, I will send you a 7-zip file of
            the Clam Sentinel code.

            Regards,

            Robert Scroggins

            On Tue, Dec 12, 2017 at 8:55 AM, Ubirajara Bandeira Jr <kokbira@users.sf.net

            wrote:

            No, I am talking about ClamSentinel, not ClamWin.

            ClamSentinel is so interesting because it makes ClamWin do a proactive
            protection, but it would be improved to do more things and merged with
            ClamWin to become a complete solution.

            I would like to see the ClamSentinel code to see if I can contribute in
            some way.

            2017-11-28 12:59 GMT-03:00 Robert Scroggins sentinelguy@users.sf.net:

            Sorry.. I thought you were asking about the ClamWin source code. You can
            read about the Clam Sentinel source code by looking at the Code item in the
            main menu. You had better hurry because Source Forge is soon making a
            change--buy the end of November, I think.

            Regards,

            Robert Scroggins

            On Mon, Nov 27, 2017 at 9:47 AM, Robert Scroggins sentinelguy@users.sf.net
            wrote:

            Hello:

            Check the ClamWin FAQ link on the main web page for info regarding source
            code download. You could also do a search on the ClamWin site for "source
            code" "source code download" or something like that. If all else fails,
            get in touch with Alch/Sherpya, ClamWin developers, and ask them via the
            contact info on the main web page. If you come up with any improvements,
            be sure to let them know about it so other users can benefit.

            Thanks for being a ClamWin user!

            Regards,

            Bob Scroggins

            On Mon, Nov 27, 2017 at 5:58 AM, Ubirajara Bandeira Jr <
            kokbira@users.sf.net

            wrote:
            Where can I download the source code?

            Sent from sourceforge.net because you indicated interest in
            https://sourceforge.net/p/clamsentinel/wiki/Home/

            To unsubscribe from further messages, please visit
            https://sourceforge.net/auth/subscriptions/


            Sent from sourceforge.net because you indicated interest in
            https://sourceforge.net/p/clamsentinel/wiki/Home/

            To unsubscribe from further messages, please visit
            https://sourceforge.net/auth/subscriptions/


            Sent from sourceforge.net because you indicated interest in
            https://sourceforge.net/p/clamsentinel/wiki/Home/

            To unsubscribe from further messages, please visit
            https://sourceforge.net/auth/subscriptions/


            Sent from sourceforge.net because you indicated interest in
            https://sourceforge.net/p/clamsentinel/wiki/Home/

            To unsubscribe from further messages, please visit
            https://sourceforge.net/auth/subscriptions/

             
            • Ubirajara Bandeira Jr

              kokbira@gmail.com

              2017-12-12 14:35 GMT-03:00 Robert Scroggins sentinelguy@users.sf.net:

              Hello:

              If you will give me another email address, I will send you a 7-zip file of
              the Clam Sentinel code.

              Regards,

              Robert Scroggins

              On Tue, Dec 12, 2017 at 8:55 AM, Ubirajara Bandeira Jr <
              kokbira@users.sf.net

              wrote:

              No, I am talking about ClamSentinel, not ClamWin.

              ClamSentinel is so interesting because it makes ClamWin do a proactive
              protection, but it would be improved to do more things and merged with
              ClamWin to become a complete solution.

              I would like to see the ClamSentinel code to see if I can contribute in
              some way.

              2017-11-28 12:59 GMT-03:00 Robert Scroggins sentinelguy@users.sf.net:

              Sorry.. I thought you were asking about the ClamWin source code. You can
              read about the Clam Sentinel source code by looking at the Code item in the
              main menu. You had better hurry because Source Forge is soon making a
              change--buy the end of November, I think.

              Regards,

              Robert Scroggins

              On Mon, Nov 27, 2017 at 9:47 AM, Robert Scroggins sentinelguy@users.sf.net
              wrote:

              Hello:

              Check the ClamWin FAQ link on the main web page for info regarding source
              code download. You could also do a search on the ClamWin site for "source
              code" "source code download" or something like that. If all else fails,
              get in touch with Alch/Sherpya, ClamWin developers, and ask them via the
              contact info on the main web page. If you come up with any improvements,
              be sure to let them know about it so other users can benefit.

              Thanks for being a ClamWin user!

              Regards,

              Bob Scroggins

              On Mon, Nov 27, 2017 at 5:58 AM, Ubirajara Bandeira Jr <
              kokbira@users.sf.net

              wrote:
              Where can I download the source code?

              Sent from sourceforge.net because you indicated interest in
              https://sourceforge.net/p/clamsentinel/wiki/Home/

              To unsubscribe from further messages, please visit
              https://sourceforge.net/auth/subscriptions/


              Sent from sourceforge.net because you indicated interest in
              https://sourceforge.net/p/clamsentinel/wiki/Home/

              To unsubscribe from further messages, please visit
              https://sourceforge.net/auth/subscriptions/


              Sent from sourceforge.net because you indicated interest in
              https://sourceforge.net/p/clamsentinel/wiki/Home/

              To unsubscribe from further messages, please visit
              https://sourceforge.net/auth/subscriptions/


              Sent from sourceforge.net because you indicated interest in
              https://sourceforge.net/p/clamsentinel/wiki/Home/

              To unsubscribe from further messages, please visit
              https://sourceforge.net/auth/subscriptions/


              Sent from sourceforge.net because you indicated interest in
              https://sourceforge.net/p/clamsentinel/wiki/Home/

              To unsubscribe from further messages, please visit
              https://sourceforge.net/auth/subscriptions/

               
              • Robert Scroggins

                Hello:

                I have tried to sent you the files I have several times--as a 7zip file, a
                tarball file, and a Gzip file, but both Gmail and Yahoo Mail treat them as
                malicious and do not deliver them. Do you have a file repository somewhere
                on the web that I can sent them to so that you can get them from there?

                Regards,

                Robert Scroggins

                On Wed, Jan 17, 2018 at 10:17 AM, Ubirajara Bandeira Jr kokbira@users.sf.net wrote:

                kokbira@gmail.com

                2017-12-12 14:35 GMT-03:00 Robert Scroggins sentinelguy@users.sf.net:

                Hello:

                If you will give me another email address, I will send you a 7-zip file of
                the Clam Sentinel code.

                Regards,

                Robert Scroggins

                On Tue, Dec 12, 2017 at 8:55 AM, Ubirajara Bandeira Jr <
                kokbira@users.sf.net

                wrote:

                No, I am talking about ClamSentinel, not ClamWin.

                ClamSentinel is so interesting because it makes ClamWin do a proactive
                protection, but it would be improved to do more things and merged with
                ClamWin to become a complete solution.

                I would like to see the ClamSentinel code to see if I can contribute in
                some way.

                2017-11-28 12:59 GMT-03:00 Robert Scroggins sentinelguy@users.sf.net:

                Sorry.. I thought you were asking about the ClamWin source code. You can
                read about the Clam Sentinel source code by looking at the Code item in the
                main menu. You had better hurry because Source Forge is soon making a
                change--buy the end of November, I think.

                Regards,

                Robert Scroggins

                On Mon, Nov 27, 2017 at 9:47 AM, Robert Scroggins sentinelguy@users.sf.net
                wrote:

                Hello:

                Check the ClamWin FAQ link on the main web page for info regarding source
                code download. You could also do a search on the ClamWin site for "source
                code" "source code download" or something like that. If all else fails,
                get in touch with Alch/Sherpya, ClamWin developers, and ask them via the
                contact info on the main web page. If you come up with any improvements,
                be sure to let them know about it so other users can benefit.

                Thanks for being a ClamWin user!

                Regards,

                Bob Scroggins

                On Mon, Nov 27, 2017 at 5:58 AM, Ubirajara Bandeira Jr <
                kokbira@users.sf.net

                wrote:
                Where can I download the source code?

                Sent from sourceforge.net because you indicated interest in
                https://sourceforge.net/p/clamsentinel/wiki/Home/

                To unsubscribe from further messages, please visit
                https://sourceforge.net/auth/subscriptions/


                Sent from sourceforge.net because you indicated interest in
                https://sourceforge.net/p/clamsentinel/wiki/Home/

                To unsubscribe from further messages, please visit
                https://sourceforge.net/auth/subscriptions/


                Sent from sourceforge.net because you indicated interest in
                https://sourceforge.net/p/clamsentinel/wiki/Home/

                To unsubscribe from further messages, please visit
                https://sourceforge.net/auth/subscriptions/


                Sent from sourceforge.net because you indicated interest in
                https://sourceforge.net/p/clamsentinel/wiki/Home/

                To unsubscribe from further messages, please visit
                https://sourceforge.net/auth/subscriptions/


                Sent from sourceforge.net because you indicated interest in
                https://sourceforge.net/p/clamsentinel/wiki/Home/

                To unsubscribe from further messages, please visit
                https://sourceforge.net/auth/subscriptions/


                Sent from sourceforge.net because you indicated interest in
                https://sourceforge.net/p/clamsentinel/wiki/Home/

                To unsubscribe from further messages, please visit
                https://sourceforge.net/auth/subscriptions/

                 
  • Eduardo Oliveira

    Hello Ubirajara,

    I get the ClamSentinel source code through CVS:

    1. Download SmartCVS at http://www.syntevo.com/smartcvs/
    2. Extract the file and open the executable "smartcvs.exe" at the "bin" directory.
    3. Choose the first option (Check out project from repository) and click on "OK" button.
    4. Into "Repository" page, click on "Manage" button.
    5. Click into "Add" button.
    6. The info necessary to connect is available at https://sourceforge.net/p/clamsentinel/code/ . CVS repositories from SourceForge is now read-only. It means you cannot checkout (commit) changes to the code. The author of the repo needs to convert it to Git to allow commits. Select the following options to connect to CVS repo:
      1. Access server: pserver
      2. Username: anonymous
      3. Server Name: clamsentinel.cvs.sourceforge.net
      4. Repository Path: /cvsroot/clamsentinel
      5. Server Port: Default
    7. Click into Next.
    8. When return to the previous window, click on Next again.
    9. Into "Modules" window, select the "ClamSentinel" path on the list and click "Next".
    10. Into "Target Directory" window, select a local path where you want to download the source code.
    11. Into "Checkout Options" and "Project Settings", use the defaults. Just click on "Next" twice.
    12. Click into "Finish" button to download the source code for your computer.
     
    • Robert Scroggins

      Hello:

      Very good!

      The real-time (resident) module is the most important one. I do not think
      it needs any change right now. The heuristics module needs some change
      (add detection of PE file sections that have entropy of 95% or greater, add
      heuristic detection of certain JavaScript files or certain JavaScript code
      in html files). The heuristic scoring method needs to be improved. The
      memory scan needs to be discarded--users can do a memory scan with ClamWin
      if they want to, and the ClamWin scan is faster. The 120 default file
      extensions for a ClamWin scan are too many--it needs to be changed to
      accept the extensions that the user has already set up in ClamWin. These
      are some of the suggestions I have.

      Please let me know if I can help you further.

      Regards,

      Bob Scroggins

      On Wed, Jan 24, 2018 at 6:44 PM, Eduardo Oliveira <jaysponsored@users.sf.net

      wrote:

      Hello Ubirajara,

      I get the ClamSentinel source code through CVS:

      1. Download SmartCVS at http://www.syntevo.com/smartcvs/
      2. Extract the file and open the executable "smartcvs.exe" at the
        "bin" directory.
      3. Choose the first option (Check out project from repository) and
        click on "OK" button.
      4. Into "Repository" page, click on "Manage" button.
      5. Click into "Add" button.
      6. The info necessary to connect is available at
        https://sourceforge.net/p/clamsentinel/code/
        https://sourceforge.net/p/clamsentinel/code/
        https://sourceforge.net/p/clamsentinel/code/
        https://sourceforge.net/p/clamsentinel/code/ . CVS repositories from
        SourceForge is now read-only. It means you cannot checkout (commit) changes
        to the code. The author of the repo needs to convert it to Git to allow
        commits. Select the following options to connect to CVS repo:
        1. Access server: pserver
        2. Username: anonymous
        3. Server Name: clamsentinel.cvs.sourceforge.net
        4. Repository Path: /cvsroot/clamsentinel
        5. Server Port: Default
      7. Click into Next.
      8. When return to the previous window, click on Next again.
      9. Into "Modules" window, select the "ClamSentinel" path on the list
        and click "Next".
      10. Into "Target Directory" window, select a local path where you want
        to download the source code.
      11. Into "Checkout Options" and "Project Settings", use the defaults.
        Just click on "Next" twice.
      12. Click into "Finish" button to download the source code for your
        computer.

      Sent from sourceforge.net because you indicated interest in
      https://sourceforge.net/p/clamsentinel/wiki/Home/

      To unsubscribe from further messages, please visit
      https://sourceforge.net/auth/subscriptions/

       
  • Mark Miller

    Mark Miller - 2019-05-19

    This software is just what I was looking for - open source/privacy respecting/real time.

    A few questions:

    1) I have selected "Detect suspicious files only".
    I have gotten on several occassions numerous notices about this:
    "Modified Folder
    Folder: C:\Users[me]\AppData\Local\Microsoft\Windows\UPPS\ File: UPPS.bin
    [Time of day]"

    I haven't been able to find out what this file is or why it is suspicious.
    How do I verify it?
    The popup warning on the lower right will say "Verify" or something like that, but there is no link to the file and I don't know what to do if I could find it.

    I've also had multiple warnings also for:

    "File with invalid PE format.
    Please verify this suspicious file:
    Folder: C:\Windows\CbsTemp\30739476_2946417796\Windows10.0-KB4494441-x64.cab\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.503_none_7e4a68b076309782\ File: gdiplus.dll"

    "Please verify this suspicious file:..."
    How?

    Also how do I get the popup to not come out rapidly 15 times in a row?
    I didn't see any "OK" or similar button to let it know that the message was received.


    2) I've selected "Notify of new versions".
    I get that message daily.

    Does that mean it's a daily Database update of ClamWin, or a new build?

    Thank you.

     
    • Robert Scroggins

      Hello Mark:

      Thanks for using Clam Sentinel; however, you are about 5 years too late!
      The project was discontinued in 2014. Developer Andrea Russo of Italy
      abandoned it. I worked with him on the Clam Sentinel heuristics, and I
      have been checking the web site now and then.

      Clam Sentinel has its own heuristic detections to generically detect
      Windows malware, and it also uses ClamWin and its signature database to
      detect specific malware. The heuristics are for malware that existed from
      2012 to 2014, and malware has changed a lot since then, so the heuristics
      can not detect most of today's malware. I believe that ClamWin is about to
      be discontinued by the developer. Furthermore, the ClamWin signatures are
      not sufficient to provide good protection for Windows users--Clam Av gets
      about 1,000 signatures each day, but more than 300,000 new malware variants
      are released each day.

      You need something better than ClamWin/Sentinel. I recommend the following
      free antivirus programs: Microsoft's Windows Defender (Security Essentials
      is the version for Windows 7 and older operating systems) or Fortinet's
      Forticlient. Most other "free" AVs will attempt to make money from their
      users in some manner unless you pay for them. If you want to pay for an
      AV, I recommend Bitdefender or Kaspersky. I use Forticlient personally.

      As for your questions, I will try to answer them here.

      If you get a message from Clam Sentinel about a modified file, it could be
      for many different reasons. Check the quarantine folder to see if it was
      quarantined. If it was not quarantined (Verify message), don't worry about
      it. If it was quarantined, the text file accompanying the quarantined file
      will tell you the folder where it was originally located. The Sentinel
      quarantine folder is the same as the ClamWin quarantine folder. It is
      located at C:\ProgramData.clamwin\quarantine. You can check files out at
      the Virus Total web site. If Clam AV is the only AV on Virus Total
      detecting a file as infected, it is a false positive.You can whitelist
      (exclude) a file in ClamWin if it is only detected by Clam AV on Virus
      Total. You should whitelist a false positive detected file in Clam
      Sentinel also, but stop Sentinel until you whitelist the file and restore
      it.

      The Verify messages are for files that are not quarantined--just warned
      about. You are supposed to check the files on Virus Total as mentioned
      above, but they are seldom infected, so don't worry about them.

      I don't know of any way to stop the 15 times in a row verify messages other
      than to disable Clam Sentinel heuristics. This will make Clam Sentinel use
      only the ClamWin virus signatures--there will be no heuristic scan.

      There will be no new versions of Clam Sentinel, so you can de-select that
      notice.

      Thanks for giving ClamWin/Clam Sentinel a try. Windows Defender or
      Forticlient and the built-in Windows firewall will provide all the
      protection you will need as a personal computer user. If you are a
      business user, you have lots of choices. Keep Malwarebytes Free for an
      occasional scan as well.

      Regards,

      Bob Scroggins (GuitarBob)

      On Sun, May 19, 2019 at 1:28 PM Mark Miller rigidgrubby@users.sourceforge.net wrote:

      This software is just what I was looking for - open source/privacy
      respecting/real time.

      A few questions:

      1) I have selected "Detect suspicious files only".
      I have gotten on several occassions numerous notices about this:
      "Modified Folder
      Folder: C:\Users[me]\AppData\Local\Microsoft\Windows\UPPS\ File: UPPS.bin
      [Time of day]"

      I haven't been able to find out what this file is or why it is suspicious.
      How do I verify it?
      The popup warning on the lower right will say "Verify" or something like
      that, but there is no link to the file and I don't know what to do if I
      could find it.

      I've also had multiple warnings also for:

      "File with invalid PE format.
      Please verify this suspicious file:
      Folder:
      C:\Windows\CbsTemp\30739476_2946417796\Windows10.0-KB4494441-x64.cab\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.17763.503_none_7e4a68b076309782\ File: gdiplus.dll"

      "Please verify this suspicious file:..."
      How?

      Also how do I get the popup to not come out rapidly 15 times in a row?
      I didn't see any "OK" or similar button to let it know that the message
      was received.


      2) I've selected "Notify of new versions".
      I get that message daily.

      Does that mean it's a daily Database update of ClamWin, or a new build?

      Thank you.

      Sent from sourceforge.net because you indicated interest in
      https://sourceforge.net/p/clamsentinel/wiki/Home/

      To unsubscribe from further messages, please visit
      https://sourceforge.net/auth/subscriptions/

       

Log in to post a comment.