[Clamav-users] Plesk

2004-06-10 Thread Matt
Plesk:
http://www.sw-soft.com/en/products/plesk/

Does not support an antivirus scanner.  Is there an easy way to use ClamAV
with it?  Anyone using Plesk?

Matt



---
This SF.Net email is sponsored by the new InstallShield X.
>From Windows to Linux, servers to mobile, InstallShield X is the
one installation-authoring solution that does it all. Learn more and
evaluate today! http://www.installshield.com/Dev2Dev/0504
___
Clamav-users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/clamav-users


RE: [Clamav-users] Ethics Question

2004-06-10 Thread Mitch \(WebCob\)
I'd say so. You aren't talking about doing this after the fact, but as the
message is received and detected as viral - right? They'd have to have hung
up immediately and even then, it's unlikely the modem handshake would be
complete yet on the next call ;-)

> On Thu, 10 Jun 2004, Nigel Horne wrote:
> > And just hope that the next person to dial in to the ISP who gets that
> > IP address from DHCP is the same person...
>
> If it's done immediately, then the chance of alerting the wrong machine is
> pretty small, isn't it?
>
> Jeffrey Moskot
> System Administrator
> [EMAIL PROTECTED]
>



---
This SF.Net email is sponsored by the new InstallShield X.
>From Windows to Linux, servers to mobile, InstallShield X is the
one installation-authoring solution that does it all. Learn more and
evaluate today! http://www.installshield.com/Dev2Dev/0504
___
Clamav-users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/clamav-users


Re: [Clamav-users] Ethics Question

2004-06-10 Thread Bit Fuzzy
Damian Menscher wrote:
On Wed, 9 Jun 2004, Tris Forster wrote:
 

With a ridiculous number of Somefools arriving at our server daily I was
trying to think of a proactive way do deal with them.
One possible solution I came up with was sending winpopups to the
offending IP informing them that they are infected (there's a pretty
good chance they'll get through as the infected machine is most likely
not firewalled).
While the aim of doing this may be completely honourable,  sending
winpopups to a non-firewalled  machine stinks of spamming and thus I am
in two minds about putting it into practice
   

We recently had our mailserver being repeatedly hit with virus traffic,
which logs showed was coming mostly from a single IP.  I contacted their
ISP, and they really didn't care.  So I sent a few popups to them,
spaced several hours apart (so as not to be a nuisance) and the machine
stopped its virus traffic in about 2 days.
Automating this would be nice, but I didn't ever bother.  Hard to
imagine it breaking anything, though.  And as long as it's sent in
response to an attack (they punched you first!) and doesn't advertise
anything, I don't think anyone could complain.
Damian Menscher
 

There's really no good way to handle this
We've been sending emails for 2 solid months to Road Runner giving 
everything but the kitchen sink, and they yet are to do anything. (you'd 
think they'd at least contact their user(s) and inform them that their 
systems are infected)  While we have though about creating a pop up on 
the offending machine, we opted not to due to potential legal issues (It 
considered a hack and thus could be illegal)

At this point we are looking at 2 options.
1) Block offending IP's as they occur. -- Effective, but could be 
aggravating to potential customers
2) Warn the ISP in question, that if something isn't done soon, you're 
going to post their non-action along with email transcripts to the news 
media, whom have taken the position in the past that ISP's should be 
taking measures to keep the Internet (users) safe. -- Could be effective 
as well as in-effective.

:(   There's no easy way around this issue, so I guess what I'm trying 
to say, if a solution works for you go for it

---
This SF.Net email is sponsored by the new InstallShield X.
From Windows to Linux, servers to mobile, InstallShield X is the
one installation-authoring solution that does it all. Learn more and
evaluate today! http://www.installshield.com/Dev2Dev/0504
___
Clamav-users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/clamav-users


Re: [Clamav-users] does vbs.pub recognized by clamav?

2004-06-10 Thread Fajar A. Nugraha
Liew Toh Seng wrote:
hi,
can i know currently the Virus Database is updated and maintained 
by  who ? 
http://www.clamav.net/team.html#pagestart
is there any mirror site for the Virus database so that when the  
current server is down, i can change the update scripts to download 
the  latest virus pattern files from others updated sites ?
database.clamav.net consists of multiple servers.
Usually no need to switch manually.
List of mirrors on http://www.clamav.net/mirrors.html
Regards,
Fajar
--
Don't use GIF. Use PNG instead
http://www.gnu.org/philosophy/gif.html

---
This SF.Net email is sponsored by the new InstallShield X.
From Windows to Linux, servers to mobile, InstallShield X is the
one installation-authoring solution that does it all. Learn more and
evaluate today! http://www.installshield.com/Dev2Dev/0504
___
Clamav-users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/clamav-users


Re: [Clamav-users] Ethics Question

2004-06-10 Thread Damian Menscher
On Wed, 9 Jun 2004, Tris Forster wrote:

> With a ridiculous number of Somefools arriving at our server daily I was
> trying to think of a proactive way do deal with them.
>
> One possible solution I came up with was sending winpopups to the
> offending IP informing them that they are infected (there's a pretty
> good chance they'll get through as the infected machine is most likely
> not firewalled).
>
> While the aim of doing this may be completely honourable,  sending
> winpopups to a non-firewalled  machine stinks of spamming and thus I am
> in two minds about putting it into practice

We recently had our mailserver being repeatedly hit with virus traffic,
which logs showed was coming mostly from a single IP.  I contacted their
ISP, and they really didn't care.  So I sent a few popups to them,
spaced several hours apart (so as not to be a nuisance) and the machine
stopped its virus traffic in about 2 days.

Automating this would be nice, but I didn't ever bother.  Hard to
imagine it breaking anything, though.  And as long as it's sent in
response to an attack (they punched you first!) and doesn't advertise
anything, I don't think anyone could complain.

Damian Menscher
-- 
-=#| Physics Grad Student & SysAdmin @ U Illinois Urbana-Champaign |#=-
-=#| 488 LLP, 1110 W. Green St, Urbana, IL 61801 Ofc:(217)333-0038 |#=-
-=#| 4602 Beckman, VMIL/MS, Imaging Technology Group:(217)244-3074 |#=-
-=#| <[EMAIL PROTECTED]> www.uiuc.edu/~menscher/ Fax:(217)333-9819 |#=-
-=#| The above opinions are not necessarily those of my employers. |#=-


---
This SF.Net email is sponsored by the new InstallShield X.
>From Windows to Linux, servers to mobile, InstallShield X is the
one installation-authoring solution that does it all. Learn more and
evaluate today! http://www.installshield.com/Dev2Dev/0504
___
Clamav-users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/clamav-users


Re: [Clamav-users] Install on shared web host?

2004-06-10 Thread Todd Lyons
Gary Weinfurther wanted us to know:

>>This might be worth putting in the README.  Many times newbies need a
>>little bit of handholding for this type of stuff.
>Great idea, Todd.  It would have saved me a lot of effort, and it was so 
>easy once I was told how to do it.

However, Gary, I will say this.  Fighting through all the different
things that you tried and then finding the answer after all that effort
*REALLY* makes you learn it.  :-)  Congrats on getting it just the way
you want.
-- 
Regards...  Todd
They that can give up essential liberty to obtain a little temporary 
safety deserve neither liberty nor safety.   --Benjamin Franklin
Linux kernel 2.6.3-4mdkenterprise   2 users,  load average: 0.01, 0.06, 0.04


---
This SF.Net email is sponsored by the new InstallShield X.
>From Windows to Linux, servers to mobile, InstallShield X is the
one installation-authoring solution that does it all. Learn more and
evaluate today! http://www.installshield.com/Dev2Dev/0504
___
Clamav-users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/clamav-users


Re: [Clamav-users] can not get clamav installaed on Debian Woody on a PPC machine

2004-06-10 Thread Stephen Gran
On Thu, Jun 10, 2004 at 03:03:40PM -0400, Alexander Rau (private) said:
> hi, 
> 
> trying to install clamav on a ppc running debian woody and I am
> running into problems.
> 
> Configure gives me the following error: "Please install zlib and
> zlib-devel packages."

apt-get install zlib1g-dev

> I also tried apt-get and installed clamav but there is no clamd deamon
> present after install.

apt-get install clamav-daemon

HTH,
-- 
 --
|  Stephen Gran  | Nobody ever forgets where he buried the |
|  [EMAIL PROTECTED] | hatchet.   -- Kin Hubbard   |
|  http://www.lobefin.net/~steve | |
 --


pgpLu4RaaaG1O.pgp
Description: PGP signature


Re: [Clamav-users] Ethics Question

2004-06-10 Thread jef moskot
On Thu, 10 Jun 2004, Nigel Horne wrote:
> And just hope that the next person to dial in to the ISP who gets that
> IP address from DHCP is the same person...

If it's done immediately, then the chance of alerting the wrong machine is
pretty small, isn't it?

Jeffrey Moskot
System Administrator
[EMAIL PROTECTED]


---
This SF.Net email is sponsored by the new InstallShield X.
>From Windows to Linux, servers to mobile, InstallShield X is the
one installation-authoring solution that does it all. Learn more and
evaluate today! http://www.installshield.com/Dev2Dev/0504
___
Clamav-users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/clamav-users


Re: [Clamav-users] does vbs.pub recognized by clamav?

2004-06-10 Thread kengheng
http://www.clamav.net/mirrors.html

- Original Message - 
From: "Liew Toh Seng" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Thursday, June 10, 2004 10:33 PM
Subject: Re: [Clamav-users] does vbs.pub recognized by clamav?


> hi,
> can i know currently the Virus Database is updated and maintained by  
> who ? is there any mirror site for the Virus database so that when the  
> current server is down, i can change the update scripts to download the  
> latest virus pattern files from others updated sites ?
>  
> ---
> Best Regards
> Liew Toh Seng
> Icq No: >> 36835809 <<
> MSN: >> [EMAIL PROTECTED] <<
> * .--.
> * |o_o |
> * |:_/ |
> * //
> * (| | )
> * /'\_ _/` The Internet Solution Company
> * \___)=(___   My Directory Sdn Bhd
> On Jun 10, 2004, at 4:37 PM, [EMAIL PROTECTED] wrote:
> 
> > Hi all,
> >   Does clamav already update to detect vbs.pub worm?
> >
> > http://news.netcraft.com/archives/2004/06/08/ 
> > symantec_new_virus_deletes_all_files.html
> >
> > http://www.sarc.com/avcenter/venc/data/vbs.pub.html
> >
> >
> > ---
> > This SF.Net email is sponsored by: GNOME Foundation
> > Hackers Unite!  GUADEC: The world's #1 Open Source Desktop Event.
> > GNOME Users and Developers European Conference, 28-30th June in Norway
> > http://2004/guadec.org
> > ___
> > Clamav-users mailing list
> > [EMAIL PROTECTED]
> > https://lists.sourceforge.net/lists/listinfo/clamav-users
> 
> 
> 
> ---
> This SF.Net email is sponsored by the new InstallShield X.
> From Windows to Linux, servers to mobile, InstallShield X is the
> one installation-authoring solution that does it all. Learn more and
> evaluate today! http://www.installshield.com/Dev2Dev/0504
> ___
> Clamav-users mailing list
> [EMAIL PROTECTED]
> https://lists.sourceforge.net/lists/listinfo/clamav-users
> 


---
This SF.Net email is sponsored by the new InstallShield X.
>From Windows to Linux, servers to mobile, InstallShield X is the
one installation-authoring solution that does it all. Learn more and
evaluate today! http://www.installshield.com/Dev2Dev/0504
___
Clamav-users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/clamav-users


Re: [Clamav-users] does vbs.pub recognized by clamav?

2004-06-10 Thread Liew Toh Seng
hi,
	can i know currently the Virus Database is updated and maintained by  
who ? is there any mirror site for the Virus database so that when the  
current server is down, i can change the update scripts to download the  
latest virus pattern files from others updated sites ?
 
---
Best Regards
Liew Toh Seng
Icq No: >> 36835809 <<
MSN: >> [EMAIL PROTECTED] <<
* .--.
* |o_o |
* |:_/ |
* //
* (| | )
* /'\_ _/` The Internet Solution Company
* \___)=(___   My Directory Sdn Bhd
On Jun 10, 2004, at 4:37 PM, [EMAIL PROTECTED] wrote:

Hi all,
  Does clamav already update to detect vbs.pub worm?
http://news.netcraft.com/archives/2004/06/08/ 
symantec_new_virus_deletes_all_files.html

http://www.sarc.com/avcenter/venc/data/vbs.pub.html
---
This SF.Net email is sponsored by: GNOME Foundation
Hackers Unite!  GUADEC: The world's #1 Open Source Desktop Event.
GNOME Users and Developers European Conference, 28-30th June in Norway
http://2004/guadec.org
___
Clamav-users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/clamav-users

---
This SF.Net email is sponsored by the new InstallShield X.
From Windows to Linux, servers to mobile, InstallShield X is the
one installation-authoring solution that does it all. Learn more and
evaluate today! http://www.installshield.com/Dev2Dev/0504
___
Clamav-users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/clamav-users


[Clamav-users] Any idea??? Clamav & MailScanner are not rejecting viruses!

2004-06-10 Thread Alfredo Rivera
Hi guys,

I've installed clamav 0.72 and MailScanner on a RedHat 7.3. However, I still 
can receive viruses by e-mail (I've tested from testvirus.org).

Here are some facts:

- Clamav seems to be working, if I download an infected file to any directory 
on my server and scan with clamscan, it is detected
- Mailscanner & spamassassin seem to be working since the number of spam 
messages now is very small. When I type "top" I can see from time to time 
MailScanner running.

Two questions, what would be the name of the clamav service that I should see 
when typing "top"? How do I start it?

Thank you very much for any help that you guys can give me. I'm going crazy 
trying to properly configure this!!

Alfredo
 intelNet WebMail



---
This SF.Net email is sponsored by the new InstallShield X.
>From Windows to Linux, servers to mobile, InstallShield X is the
one installation-authoring solution that does it all. Learn more and
evaluate today! http://www.installshield.com/Dev2Dev/0504
___
Clamav-users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/clamav-users


RE: [Clamav-users] Sober.G failing to be detected after 349 update

2004-06-10 Thread Diego d'Ambra
> -Original Message-
> From: [EMAIL PROTECTED] [mailto:clamav-users-
> [EMAIL PROTECTED] On Behalf Of John Alexander
> Sent: 10. juni 2004 08:43
> To: [EMAIL PROTECTED]
> Subject: [Clamav-users] Sober.G failing to be detected after 349
update
> 
> After the last update, Sober.G isn't being detected anymore.
Everything
> is still ok - this could be good, maybe Sober.G has stopped! Or
> something has broke
> 
> Has anyone else seen this occuring?
> 

It seems like Sober-G has stopped spreading.

Since midnight my statistic shows "only" 566 copies (I live in UTC
+0200) - used to be around 100K per day.

I can confirm that ClamAV still contains signature matching Sober-G.

Best regards,
Diego d'Ambra


smime.p7s
Description: S/MIME cryptographic signature


[Clamav-users] clam 0.72 + linux + ntfs + ole2 = segfault :(

2004-06-10 Thread Mehmet Ekiz
Hi,
I am using clamav binaries from Crashhat for Fedora Core 1. And have an 
NTFS filesystem mounted through http://linux-ntfs.sourceforge.net/.

After upgrading 0.72, there is two problems with OLE2 files:
1. clamscan and clamd both segfaults when trying to scan OLE2 files 
located on ntfs partition.
2. When the file is on ext3 partition, there is a debug error but no 
segfault.

I know that is a bit confusing. Sorry for that. Hope the debug output helps.
Regards,
Mehmet
output of clamscan --debug excel.xls (excel.xls is a template file from 
excel 2000)
when excel.xls on NTFS partition:

LibClamAV debug: Loading databases from /var/lib/clamav
LibClamAV debug: Loading /var/lib/clamav/daily.cvd
LibClamAV debug: /var/lib/clamav/daily.cvd: CVD file detected
LibClamAV debug: in cli_cvdload()
LibClamAV debug: MD5(.tar.gz) = fb69bcf0328d74a6b879f1fdab0c747d
LibClamAV debug: Decoded signature: fb69bcf0328d74a6b879f1fdab0c747d
LibClamAV debug: Digital signature is correct.
LibClamAV debug: in cli_untgz()
LibClamAV debug: Unpacking /tmp/clamav-01c2ff6333f2950f/COPYING
LibClamAV debug: Unpacking /tmp/clamav-01c2ff6333f2950f/viruses.db2
LibClamAV debug: Loading databases from /tmp/clamav-01c2ff6333f2950f
LibClamAV debug: Loading /tmp/clamav-01c2ff6333f2950f/viruses.db2
LibClamAV debug: Initializing trie.
LibClamAV debug: Loading /var/lib/clamav/main.cvd
LibClamAV debug: /var/lib/clamav/main.cvd: CVD file detected
LibClamAV debug: in cli_cvdload()
LibClamAV debug: MD5(.tar.gz) = 2afa38b2ececc44e99e396f97e94adef
LibClamAV debug: Decoded signature: 2afa38b2ececc44e99e396f97e94adef
LibClamAV debug: Digital signature is correct.
LibClamAV debug: in cli_untgz()
LibClamAV debug: Unpacking /tmp/clamav-83ce78ccd8ca0bb2/COPYING
LibClamAV debug: Unpacking /tmp/clamav-83ce78ccd8ca0bb2/viruses.db
LibClamAV debug: Loading databases from /tmp/clamav-83ce78ccd8ca0bb2
LibClamAV debug: Loading /tmp/clamav-83ce78ccd8ca0bb2/viruses.db
LibClamAV debug: Recognized OLE2 container file
LibClamAV debug: in cli_scanole2()
LibClamAV debug: in cli_ole2_extract()
LibClamAV debug: mmap'ed file
Segmentation Fault
when excel.xls on ext3:
LibClamAV debug: Loading databases from /var/lib/clamav
LibClamAV debug: Loading /var/lib/clamav/daily.cvd
LibClamAV debug: /var/lib/clamav/daily.cvd: CVD file detected
LibClamAV debug: in cli_cvdload()
LibClamAV debug: MD5(.tar.gz) = fb69bcf0328d74a6b879f1fdab0c747d
LibClamAV debug: Decoded signature: fb69bcf0328d74a6b879f1fdab0c747d
LibClamAV debug: Digital signature is correct.
LibClamAV debug: in cli_untgz()
LibClamAV debug: Unpacking /tmp/clamav-8bfc7cb0582a2574/COPYING
LibClamAV debug: Unpacking /tmp/clamav-8bfc7cb0582a2574/viruses.db2
LibClamAV debug: Loading databases from /tmp/clamav-8bfc7cb0582a2574
LibClamAV debug: Loading /tmp/clamav-8bfc7cb0582a2574/viruses.db2
LibClamAV debug: Initializing trie.
LibClamAV debug: Loading /var/lib/clamav/main.cvd
LibClamAV debug: /var/lib/clamav/main.cvd: CVD file detected
LibClamAV debug: in cli_cvdload()
LibClamAV debug: MD5(.tar.gz) = 2afa38b2ececc44e99e396f97e94adef
LibClamAV debug: Decoded signature: 2afa38b2ececc44e99e396f97e94adef
LibClamAV debug: Digital signature is correct.
LibClamAV debug: in cli_untgz()
LibClamAV debug: Unpacking /tmp/clamav-470acdf5af80ad3c/COPYING
LibClamAV debug: Unpacking /tmp/clamav-470acdf5af80ad3c/viruses.db
LibClamAV debug: Loading databases from /tmp/clamav-470acdf5af80ad3c
LibClamAV debug: Loading /tmp/clamav-470acdf5af80ad3c/viruses.db
LibClamAV debug: Recognized OLE2 container file
LibClamAV debug: in cli_scanole2()
LibClamAV debug: in cli_ole2_extract()
LibClamAV debug: mmap'ed file
LibClamAV debug:
Magic:  0xLibClamAV debug: d0LibClamAV debug: 
cfLibClamAV debug: 11LibClamAV debug: e0LibClamAV debug: a1LibClamAV 
debug: b1LibClamAV debug: 1aLibClamAV debug: e1LibClamAV debug:
LibClamAV debug: CLSID: {LibClamAV debug: 0 LibClamAV 
debug: 0 LibClamAV debug: 0 LibClamAV debug: 0 LibClamAV debug: 0 
LibClamAV debug: 0 LibClamAV debug: 0 LibClamAV debug: 0 LibClamAV 
debug: 0 LibClamAV debug: 0 LibClamAV debug: 0 LibClamAV debug: 0 
LibClamAV debug: 0 LibClamAV debug: 0 LibClamAV debug: 0 LibClamAV 
debug: 0 LibClamAV debug: }
LibClamAV debug: Minor version: 0x3e
LibClamAV debug: DLL version:   0x3
LibClamAV debug: Byte Order:-2
LibClamAV debug: Big Block Size:9
LibClamAV debug: Small Block Size:  6
LibClamAV debug: BAT count: 1
LibClamAV debug: Prop start:1
LibClamAV debug: SBAT cutoff:   4096
LibClamAV debug: SBat start:2
LibClamAV debug: SBat block count:  1
LibClamAV debug: XBat start:-2
LibClamAV debug: XBat block count:  0

LibClamAV debug: Root EntryLibClamAV debug:  
[root]LibClamAV debug:  rLibClamAV debug:  3136 0
LibClamAV debug: _1_CompObjLibClamAV debug:  
[file]LibClamAV debug:  bLibClamAV debug:  106 
LibClamAV debug:   

RE: [Clamav-users] Ethics Question

2004-06-10 Thread Samuel Benzaquen

> > I think the only way I could think is reporting the IP to some DNSBLs.
> > That way you can stop receiving their mails and you leave the cleansing
> > problem to their ISP.
>
> And just hope that the next person to dial in to the ISP who gets
> that IP address
> from DHCP is the same person...
>

Before we used ClamAV to block outgoing messages (and firewall to prevent
port 25 outgoing from clients to the Internet), we got complete class C
networks blocked very often because just one IP was sending virus.
As those networks are dial-up, it is very likely to happen what you say, but
eventually they will have their whole network blocked and they will have to
do something about it.

If you don't clean your house, your neighbors will complain about the
infestation and will force you to clean it.

-samuel



---
This SF.Net email is sponsored by: GNOME Foundation
Hackers Unite!  GUADEC: The world's #1 Open Source Desktop Event.
GNOME Users and Developers European Conference, 28-30th June in Norway
http://2004/guadec.org
___
Clamav-users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/clamav-users


[Clamav-users] cgpro with clamav and cgpav

2004-06-10 Thread Kristof Hardy
Hi,
Just wondering, sometimes a mail slips through with the netsky.z 
variant.. clamav detects any virus, except this one, it sometimes 
doesn't get caught.

I'm running communigate pro with the cgpav helper on red hat9, clamav is 
0.72 and freshclam runs once an hour..

Any idea why this might be? We've got a load of approx 1200msg/h. I 
sometimes enable the McAfee antivirus plugin (1000msg/h limit) for a 
limited time to see if anything gets through, so that's how I found out 
about this..

I attached the log, if I need to supply anything else, just let me 
know.. thanks..

The log conncerning the catched mail...
10:22:28.48 4 ENQUEUERRULES [7618767] rule(cgpav) conditions met
10:22:28.48 4 EXTFILTER(cgpav) out(30): 593038 FILE Queue/7618767.msg\n
10:22:28.51 4 EXTFILTER(cgpav) [7618767] header added: 
X-CAD-Virus-Scanned: by ClamAV 0.72
---> this indicates message is clean
10:22:28.51 4 ENQUEUERRULES [7618767] rule(MailScan) conditions met
10:22:28.51 4 EXTFILTER(McAfee) out(28): 3368 FILE Queue/7618767.msg\n
10:22:29.09 4 EXTFILTER(McAfee) inp(228): 3368 ERROR "Virus(es) 
found.\eBill.zip is infected with W32/[EMAIL PROTECTED]: 
1\eTrojans: 0\eJokes: 0\eTests: 0\e\eCaptured by McAfee antivirus plugin
---> this indicates message is infected
10:22:29.09 1 ENQUEUERRULES [7618767] rule(MailScan) action #0: filter 
report: Virus(es) found.\nBill.zip is infected with 
W32/[EMAIL PROTECTED]: 1\nTrojans: 0\nJokes: 0\nTests: 
0\n\nCaptured b
10:22:29.09 1 ENQUEUER-05([7618767]) Server rules failed: Error 
Code=external filter rejected the message
10:22:29.09 1 DEQUEUER [7618767] SYSTEM() failed
10:22:29.09 4 DEQUEUER [7618767] placed into empty 'immediate' queue
10:22:29.09 4 DEQUEUER-31 [7618767] processing
10:22:29.09 4 QUEUE([7618767]) closed, nOpen=14
10:22:29.09 2 QUEUE([7618767]) deleted


---
This SF.Net email is sponsored by: GNOME Foundation
Hackers Unite!  GUADEC: The world's #1 Open Source Desktop Event.
GNOME Users and Developers European Conference, 28-30th June in Norway
http://2004/guadec.org
___
Clamav-users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/clamav-users


[Clamav-users] does vbs.pub recognized by clamav?

2004-06-10 Thread kengheng
Hi all,
  Does clamav already update to detect vbs.pub worm?

http://news.netcraft.com/archives/2004/06/08/symantec_new_virus_deletes_all_files.html

http://www.sarc.com/avcenter/venc/data/vbs.pub.html


---
This SF.Net email is sponsored by: GNOME Foundation
Hackers Unite!  GUADEC: The world's #1 Open Source Desktop Event.
GNOME Users and Developers European Conference, 28-30th June in Norway
http://2004/guadec.org
___
Clamav-users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/clamav-users


Re: [Clamav-users] Ethics Question

2004-06-10 Thread Nigel Horne
> I think the only way I could think is reporting the IP to some DNSBLs.
> That way you can stop receiving their mails and you leave the cleansing
> problem to their ISP.

And just hope that the next person to dial in to the ISP who gets that IP address
from DHCP is the same person...

-Nigle

-- 
Nigel Horne. Arranger, Composer, Typesetter.
NJH Music, Barnsley, UK.  ICQ#20252325
[EMAIL PROTECTED] http://www.bandsman.co.uk


---
This SF.Net email is sponsored by: GNOME Foundation
Hackers Unite!  GUADEC: The world's #1 Open Source Desktop Event.
GNOME Users and Developers European Conference, 28-30th June in Norway
http://2004/guadec.org
___
Clamav-users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/clamav-users