[Clamav-users] password protected zip file

2004-03-01 Thread kengheng
Hi, Can clamav detected those virus that is protected by a password in a zipped file?     Thanks

[Clamav-users] How to disable notification

2004-03-01 Thread Janis
Hi! I am using clamav/sendmail to scan mail for viruses. I'd like to know whether is it possible to disable sending of notification to sender of incomming mail about the virus in the e-mail. As you know - viruses are using fake addreses, so the person in from field could be not gilty at all. J

[Clamav-users] Problem or not?

2004-03-01 Thread Adrian Gurbina (main)
According to http://www.gietl.com/test-clamav/ File is valid, and was successfully uploaded. clamav scans the file ... Clamav-Output:/tmp/php3ttpQi: Worm.Bagle.A3 FOUND And found something: Worm.Bagle.A3 But localy the clamscan dont remove the virus is let it spread over the network does any1 kno

[Clamav-users] clamav 0.65 not detecting Worm.Bagle.F

2004-03-01 Thread Joey Esquibal
Sorry, might not be the correct mailing list to post but any comments are greatly appreciated. I have successfully configured MailScanner with ClamAV-0.65. Tested it with some of the known viruses like Mydoom and it was indeed detecting it. Unfortunately, the new variant of virus (Worm.Bagle) w

[Clamav-users] Clamd problem Solaris 8

2004-03-01 Thread Clamav
Hello! I have the problem that clamd sometimes crashes. I use ClamAV version 0.66 with clamav-milter version '0.66m' and sendmail 8.12.10 on Solaris 8. In the clamd.log file I found the following messages: Tue Mar 2 02:45:38 2004 -> SelfCheck: Database status OK. Tue Mar 2 02:53:48 2004 -> ERRO

[Clamav-users] HMM

2004-03-01 Thread Adrian Gurbina (main)
SO there is any possible way to make local clamscan to detect the virus that i ask about cause seem to know about it if so please give me some ideas thanks --- SF.Net is sponsored by: Speed Start Your Linux Apps Now. Build and deploy apps & Web

[Clamav-users] FYI: clamav-devel-20040301 build error on Solaris

2004-03-01 Thread Fajar A. Nugraha
/clamav-auto-build/clamav-devel-20040301/clamd' What does a 386 binary doing here? Surely my gcc can't produce that? Sure enough, I found these files on source tarball: ./clamd/dazukoio.o ./clamd/dazukoio_compat12.o Deleted these files, and clamav compiles OK. Regar

Re: [Clamav-users] debian-sid package broken

2004-03-01 Thread Stephen Gran
On Tue, Mar 02, 2004 at 12:00:28PM +0800, Me Its said: > I am using debian - sid, but I got error when I apt-get upgrade, when > it tries to install the new ClamAV > > Setting up clamav-base (0.67-5) ... > dirname: too few arguments > Try `dirname --help' for more information. > dpkg: error proce

[Clamav-users] Re: debian-sid package broken

2004-03-01 Thread Derrick 'dman' Hudson
On Tue, Mar 02, 2004 at 12:00:28PM +0800, Me Its wrote: | I am using debian - sid, but I got error when I apt-get upgrade, when | it tries to install the new ClamAV | What should I do next ? Look for a related bug report on http://bugs.debian.org. If there is none, report the bug. At any rate,

Re: [Clamav-users] debian-sid package broken

2004-03-01 Thread Derek J. Balling
On Mar 1, 2004, at 11:00 PM, Me Its wrote: I am using debian - sid, but I got error when I apt-get upgrade, when it tries to install the new ClamAV Sounds like something is odd. I just did that myself and now: # dpkg --list | grep clamav ii clamav 0.67-5 Antivirus scanner for Uni

[Clamav-users] debian-sid package broken

2004-03-01 Thread Me Its
I am using debian - sid, but I got error when I apt-get upgrade, when it tries to install the new ClamAV Setting up clamav-base (0.67-5) ... dirname: too few arguments Try `dirname --help' for more information. dpkg: error processing clamav-base (--configure): subprocess post-installation script

Re: [Clamav-users] Just setting up...Exim 4.2, Exiscan and Clam 0.66

2004-03-01 Thread Stephen Gran
On Mon, Mar 01, 2004 at 09:52:25PM -0500, Frank DeChellis DSL said: > On Mon, 1 Mar 2004, Stephen Gran wrote: > > On Mon, Mar 01, 2004 at 03:47:57PM -0500, Frank DeChellis DSL said: > > > Hi. > > > > > > We are running Exim 4.2 with Exiscan and SpamAssassin on a separate > > > server. I just setup

Re: [Clamav-users] Just setting up...Exim 4.2, Exiscan and Clam 0.66

2004-03-01 Thread Frank DeChellis DSL
I have those settings in there but there seems to be no communication between the 2 units. Is there an ACL entry for exim? Is there a way to tell if the 2 systems are talking? Thanks Frank On Mon, 1 Mar 2004, Stephen Gran wrote: > Date: Mon, 1 Mar 2004 20:37:53 -0500 > From: Stephen Gran <[EM

[Clamav-users] Re: password-protected Worm.Bagle.F

2004-03-01 Thread Derrick 'dman' Hudson
On Mon, Mar 01, 2004 at 09:06:12PM +0100, Erik Corry wrote: | On Mon, Mar 01, 2004 at 05:31:35PM +0700, Fajar A. Nugraha wrote: | > Bill Taroli wrote: | > However, judging from the fact that it IS spreading in my network now, | > some people tend to do exactly that. | | Kaspersky have added the

Re: [Clamav-users] Just setting up...Exim 4.2, Exiscan and Clam 0.66

2004-03-01 Thread Stephen Gran
On Mon, Mar 01, 2004 at 03:47:57PM -0500, Frank DeChellis DSL said: > Hi. > > We are running Exim 4.2 with Exiscan and SpamAssassin on a separate > server. I just setup clamav on a separate server. > > How do I structure av_scanner = clamd:/var/run/clamd.ctl line in my exim > configuration to us

RE: [Clamav-users] Correct clamav-milter options to --postmaster-only

2004-03-01 Thread Stevens, John
>Please post an example of the bounce message, then I can see where it's coming from. >-Nigel Hi Nigel, From: MAILER-DAEMON To: [EMAIL PROTECTED] CC: [EMAIL PROTECTED] Subject: Virus intercepted A message you sent to [EMAIL PROTECTED] contained a virus and has not been delivered. stream: Worm.Bagl

Re: [Clamav-users] ClamAV not detecting Netsky.C in .zip file

2004-03-01 Thread Tomasz Kojm
On Mon, 1 Mar 2004 11:01:19 -0800 (PST) Ninetwoaccord <[EMAIL PROTECTED]> wrote: > I scanned manually using clamscan -v yep.msg (the You must enable ScanMail in clamav.conf (for clamd) and use --mbox in clamscan. -- oo. Tomasz Kojm <[EMAIL PROTECTED]> (\/)\.

Re: [Clamav-users] Just setting up...Exim 4.2, Exiscan and Clam 0.66

2004-03-01 Thread Jesper Juhl
On Mon, 1 Mar 2004, Frank DeChellis DSL wrote: > Hi. > > We are running Exim 4.2 with Exiscan and SpamAssassin on a separate > server. I just setup clamav on a separate server. > > How do I structure av_scanner = clamd:/var/run/clamd.ctl line in my exim > configuration to use clam off another s

Re: [Clamav-users] ClamAV not detecting Netsky.C in .zip file

2004-03-01 Thread Ninetwoaccord
Nope not a typo, an overlook. Thank you VERY much for taking the time to read my post. Freshclam was running 24 times a day, and it stopped on the 23rd. Ran the update and it detected the virus. Thanks again for your time. Now to find out why it stopped on the 23rd... Ian --- Patrik Nilsson <[E

Re: [Clamav-users] password-protected Worm.Bagle.F

2004-03-01 Thread Martin Hermanowski
On Mon, Mar 01, 2004 at 09:06:12PM +0100, Erik Corry wrote: > On Mon, Mar 01, 2004 at 05:31:35PM +0700, Fajar A. Nugraha wrote: > > Bill Taroli wrote: > > > > >Perhaps a silly question... if the .ZIP attachment is passworded, how > > >are the target users supposed to be opening them and getting i

Re: [Clamav-users] ClamAV not detecting Netsky.C in .zip file

2004-03-01 Thread Patrik Nilsson
At 11:01 2004-03-01 -0800, Ninetwoaccord wrote: I checked to make sure I have been updating my definitions correctly and I have. Last update was Mon Feb 23 at 15:04:35 2004. (This morning) Was that a typo? If not - Feb 23 was monday last week, not this morning... Patrik ---

Re: [Clamav-users] ClamAV not detecting Netsky.C in .zip file

2004-03-01 Thread Ninetwoaccord
Hello Kristof, thank you VERY much for your response. I tried what you suggested and it did not find the virus. I also have mail scanning on. One other person replied and requested I send them the .zip file and clamAV did not detect it as worm.somefool.B This is what they detected: The virus de

[Clamav-users] Just setting up...Exim 4.2, Exiscan and Clam 0.66

2004-03-01 Thread Frank DeChellis DSL
Hi. We are running Exim 4.2 with Exiscan and SpamAssassin on a separate server. I just setup clamav on a separate server. How do I structure av_scanner = clamd:/var/run/clamd.ctl line in my exim configuration to use clam off another server? What do I enter in my clamav.conf to give another serv

Re: [Clamav-users] ClamAV not detecting Netsky.C in .zip file

2004-03-01 Thread Kristof Hardy
Ninetwoaccord wrote: I wanted to make sure my archive scanning settings were correct for clamd. I searched these email archives and found that Archive support should be turned on (it was) as well as StreamSaveToDisk (it wasn't). I tested with StreamSaveToDisk and it still did not find the virus. is

Re: [Clamav-users] Suspected.Zip

2004-03-01 Thread Tomasz Kojm
On Mon, 01 Mar 2004 14:43:27 +0100 Kristof Hardy <[EMAIL PROTECTED]> wrote: > Hi, > > Clamd (v067-1) on our CGPro just reported: > Mon Mar 1 14:16:10 2004 -> /tmp/cgpavyuPWe6: Suspected.Zip FOUND > > Now, I have searched the mailing list archives and did a "sigtool > --list-sigs | grep -i Susp

Re: [Clamav-users] password-protected Worm.Bagle.F

2004-03-01 Thread Erik Corry
On Mon, Mar 01, 2004 at 05:31:35PM +0700, Fajar A. Nugraha wrote: > Bill Taroli wrote: > > >Perhaps a silly question... if the .ZIP attachment is passworded, how > >are the target users supposed to be opening them and getting infected? > >Has the password been included in the email in which the

Re: [Clamav-users] Clamscan not detecting virus

2004-03-01 Thread Matthew Daubenspeck
On Mon, Mar 01, 2004 at 05:53:59PM +0100, Thomas Lamy wrote: > >But my local copy is not working. I checked the syslog and it says > >nothing other then the message is clean. Any ideas where to start > >checking? > > What is your exact setup, i.e. what is the "glue" between your mailer > and clam

[Clamav-users] ClamAV not detecting Netsky.C in .zip file

2004-03-01 Thread Ninetwoaccord
Hello, I have just joined the email list and would like to thank everyone in advance for their help. I have searched the archives and google until my eyes have hurt and have waited about 10 days before escelating my issue to this list. Here is my issue. I have setup Postfix/Amavis-new/ClamAV/Spam

RE: [Clamav-users] E-mail Notice Replies

2004-03-01 Thread Rob
> -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf > Of Marc Brooks > > Is it possible to turn off the e-mail notification that is > returned to the > user (who sent the virus)? > > Running Clamav 0.67 w/ milter on FreeBSD 4.7 Yup - don't use --bounce

Re: [Clamav-users] clamdscan: input via stdin

2004-03-01 Thread Adam Webb - Network Manager
cat filename | clamdscan - Marc Cuypers [EMAIL PROTECTED] wrote: > Hi, > > I'm running clamav 0.60 on Debian. > > Can I 'cat' a file to clamdscan, or must it be a physical file on the disk? > > Thanks for your time, > > --Marc > > > > ---

[Clamav-users] E-mail Notice Replies

2004-03-01 Thread Marc Brooks
Hello All, Is it possible to turn off the e-mail notification that is returned to the user (who sent the virus)? Running Clamav 0.67 w/ milter on FreeBSD 4.7 Marc S. Brooks Programmer/Systems Admin 975 Andreasen Escondido, CA 92029 760-740-2625 ph 760-740-2643 fx -

Re: [Clamav-users] virus getting thru

2004-03-01 Thread Nagy Ferenc László
Peter McCreath wrote: --- Loren Salsgiver <[EMAIL PROTECTED]> wrote: > Norton AntiVirus removed the attachment: bill.zip. >>The attachment was infected with the [EMAIL PROTECTED] virus. >> This seems to be common, can anyone help? Loren I;m having the same problem, it always seems to be Bse

Re: [Clamav-users] Correct clamav-milter options to --postmaster-only

2004-03-01 Thread Nigel Horne
On Monday 01 Mar 2004 4:55 am, Stevens, John wrote: > Hi All, > I have clamd and clamav-milter (0.67-1) on my two mail gateways, and am > really happy with the performance and detection rates. Job well done to > the devs. The only problem I have at the moment is getting alerted to a > virus detect

Re: [Clamav-users] Clamscan not detecting virus

2004-03-01 Thread Thomas Lamy
Matthew Daubenspeck wrote: I am using the backported.org package of ClamAV: $ clamscan --version clamscan / ClamAV version 0.67+CVS20040221 So far clam has been catching 90% of the viruses that are sent to the server, but it has missed a few others. I downloaded the specific virus itself and tried

Re: [Clamav-users] sigtool --list-sigs

2004-03-01 Thread Tomasz Papszun
On Mon, 01 Mar 2004 at 8:18:25 -0600, Joe Kletch wrote: > >sigtool --list-sigs > > Does not work on my install. Is the best way to get this corrected to > upgrade Clam 0.67? > > mail burtonmayer.com $ clamd -V > clamd / ClamAV version 0.65 > Please, don't "top-post". Yes. -- Tomasz Papszu

RE: [Clamav-users] Segmentation Fault (Again Again)!

2004-03-01 Thread Trog
On Mon, 2004-03-01 at 10:37, Philipp Grosswiler wrote: > Well, this happened about 2-3 times (before, I was not able to use gdb). But > I am using the current CVS snapshot (20040229) and it is working great until > now. I didn't have any crashes since then. Could be that it is already > solved in t

Re: [Clamav-users] virus getting thru

2004-03-01 Thread Peter McCreath
--- Loren Salsgiver <[EMAIL PROTECTED]> wrote: > >>Norton AntiVirus removed the attachment: > bill.zip. > >>The attachment was infected with the > [EMAIL PROTECTED] virus. > >> > > This seems to be common, can anyone help? > > Loren > > > I;m having the same problem, it always seems to be B

[Clamav-users] Clamscan not detecting virus

2004-03-01 Thread Matthew Daubenspeck
I am using the backported.org package of ClamAV: $ clamscan --version clamscan / ClamAV version 0.67+CVS20040221 So far clam has been catching 90% of the viruses that are sent to the server, but it has missed a few others. I downloaded the specific virus itself and tried to submit it using the on

Re: [Clamav-users] sigtool --list-sigs

2004-03-01 Thread Kristof Hardy
Joe Kletch wrote: sigtool --list-sigs Does not work on my install. Is the best way to get this corrected to upgrade Clam 0.67? mail burtonmayer.com $ clamd -V clamd / ClamAV version 0.65 It can't hurt anyway to upgrade to v0.67-1. Maybe try finding it with 'whereis sigtool' (or 'locate sigtool')

Re: [Clamav-users] Segmentation Fault (Again Again)!

2004-03-01 Thread Trog
On Mon, 2004-03-01 at 14:04, Loren Salsgiver wrote: > Set your thread timeout to zero. Setting this to any other value causes > users with dialup connections to timeout while sending attachments, in > addition my seg faults are gone. This is the best reason to do this, > I've been running for

[Clamav-users] sigtool --list-sigs

2004-03-01 Thread Joe Kletch
sigtool --list-sigs Does not work on my install. Is the best way to get this corrected to upgrade Clam 0.67? mail burtonmayer.com $ clamd -V clamd / ClamAV version 0.65 Thanks! Joe Kletch On Mar 1, 2004, at 7:43 AM, Kristof Hardy wrote: sigtool --list-sigs ---

[Clamav-users] virus getting thru

2004-03-01 Thread Loren Salsgiver
>>Norton AntiVirus removed the attachment: bill.zip. >>The attachment was infected with the [EMAIL PROTECTED] virus. >> This seems to be common, can anyone help? Loren --- SF.Net is sponsored by: Speed Start Your Linux Apps Now. Build and depl

Re: [Clamav-users] Segmentation Fault (Again Again)!

2004-03-01 Thread Loren Salsgiver
Set your thread timeout to zero. Setting this to any other value causes users with dialup connections to timeout while sending attachments, in addition my seg faults are gone. This is the best reason to do this, I've been running for 4 days now without a single crash, previoiusly I was resta

[Clamav-users] Suspected.Zip

2004-03-01 Thread Kristof Hardy
Hi, Clamd (v067-1) on our CGPro just reported: Mon Mar 1 14:16:10 2004 -> /tmp/cgpavyuPWe6: Suspected.Zip FOUND Now, I have searched the mailing list archives and did a "sigtool --list-sigs | grep -i Suspected" but could not find this anywhere. Any idea what this might be? Ps, Bagle.A3 now als

Re: [Clamav-users] Virus

2004-03-01 Thread Antony Stone
On Monday 01 March 2004 1:23 pm, Adrian Gurbina (main) wrote: > i allways run clamd with freshclam so i;m updated all the time i got some > problem with a virus is : [EMAIL PROTECTED] > is not reconised by clamscan > I find it out using NAV/Symantec > What shall i do? Submit a sample of the virus

[Clamav-users] Virus

2004-03-01 Thread Adrian Gurbina (main)
i allways run clamd with freshclam so i;m updated all the time i got some problem with a virus is : [EMAIL PROTECTED] is not reconised by clamscan I find it out using NAV/Symantec What shall i do? --- SF.Net is sponsored by: Speed Start Your Li

[Clamav-users] clamdscan: input via stdin

2004-03-01 Thread Marc Cuypers
Hi, I'm running clamav 0.60 on Debian. Can I 'cat' a file to clamdscan, or must it be a physical file on the disk? Thanks for your time, --Marc --- SF.Net is sponsored by: Speed Start Your Linux Apps Now. Build and deploy apps & Web service

RE: [Clamav-users] Segmentation Fault (Again Again)!

2004-03-01 Thread Trog
On Mon, 2004-03-01 at 10:37, Philipp Grosswiler wrote: > Hello Trog. > > > The libpthread thread manager seg faulted. I've never seen that happen > > before. I guess that would be either a bug in libpthread or some very > > bad memory corruption somewhere. > > Well, this happened about 2-3 tim

Re: [Clamav-users] libclamav question

2004-03-01 Thread Thomas Lamy
Jose Marcio Martins da Cruz schrieb: Hello, libclamav has three functions to scan an object : cl_scanbuff, cl_scandesc and cl_scanfile. Only cl_scanbuff doesn't have the parameter "options". What kind of objects are scanned by cl_scanbuff ? Memory buffers. This needs no "options", as it is s

[Clamav-users] libclamav question

2004-03-01 Thread Jose Marcio Martins da Cruz
Hello, libclamav has three functions to scan an object : cl_scanbuff, cl_scandesc and cl_scanfile. Only cl_scanbuff doesn't have the parameter "options". What kind of objects are scanned by cl_scanbuff ? Thanks, Jose-Marcio -- ---

[Clamav-users] Re: password-protected Worm.Bagle.F

2004-03-01 Thread Toorop
Bill Taroli, BT> Perhaps a silly question... if the .ZIP attachment is passworded, how BT> are the target users supposed to be opening them and getting infected? BT> Has the password been included in the email in which the .ZIP was attached? Perhaps the password is in the message : "Open my co

RE: [Clamav-users] Segmentation Fault (Again Again)!

2004-03-01 Thread Philipp Grosswiler
Hello Trog. > The libpthread thread manager seg faulted. I've never seen that happen > before. I guess that would be either a bug in libpthread or some very > bad memory corruption somewhere. Well, this happened about 2-3 times (before, I was not able to use gdb). But I am using the current CV

Re: [Clamav-users] password-protected Worm.Bagle.F

2004-03-01 Thread Jesper Juhl
On Mon, 1 Mar 2004, Ola Thoresen wrote: > Mon, 01 Mar 2004 at 09:06 GMT "Fajar A. Nugraha" <[EMAIL PROTECTED]> wrote > > > > Since the password is the same, hopefully it won't take virus db team > > long to update the signature. > > However what IF: > > > > - there's a new virus > > - the vir

Re: [Clamav-users] password-protected Worm.Bagle.F

2004-03-01 Thread Fajar A. Nugraha
Bill Taroli wrote: Perhaps a silly question... if the .ZIP attachment is passworded, how are the target users supposed to be opening them and getting infected? Has the password been included in the email in which the .ZIP was attached? No, silly me. I forgot to mention that the password is inc

Re: [Clamav-users] password-protected Worm.Bagle.F

2004-03-01 Thread Ola Thoresen
Mon, 01 Mar 2004 at 09:06 GMT "Fajar A. Nugraha" <[EMAIL PROTECTED]> wrote > Since the password is the same, hopefully it won't take virus db team > long to update the signature. > However what IF: > > - there's a new virus > - the virus just passes known (detected) worm, in a zip file > -

Re: [Clamav-users] password-protected Worm.Bagle.F

2004-03-01 Thread Bill Taroli
Perhaps a silly question... if the .ZIP attachment is passworded, how are the target users supposed to be opening them and getting infected? Has the password been included in the email in which the .ZIP was attached? Fajar A. Nugraha wrote: Fajar A. Nugraha wrote: So far (I only have two diffe

[Clamav-users] Re: Re: Re: 5 from testvirus.com came through

2004-03-01 Thread Ignasi Prat
> > Hi all at clamav-users: > > > > I am in the same situation as Jim, the only test failed is #17. Any hints ? > > > > All mail scanned with clamdscan with ScanMail and ScanArchive active, > > running Win32 Clamav-devel 20040219. > > > > Has this been corrected in last CVS ? I can send the specifi

Re: [Clamav-users] password-protected Worm.Bagle.F

2004-03-01 Thread Fajar A. Nugraha
Fajar A. Nugraha wrote: So far (I only have two different samples now) the password is the same : 31517. Update : I just got another sample with different password (submission number 1534). Should I start blocking .zip files too? Regards, Fajar A. Nugraha

RE: [Clamav-users] Segmentation Fault (Again Again)!

2004-03-01 Thread Trog
On Sun, 2004-02-29 at 17:55, Philipp Grosswiler wrote: > OK, now I got something for you... but could be that the problem is already > solved in the latest CVS version... just that the latest CVS is not working > for me (see my earlier post about readdb()). > > (gdb) continue > Continuing. > [New

[Clamav-users] password-protected Worm.Bagle.F

2004-03-01 Thread Fajar A. Nugraha
Hi, Recently (starting 15.00 +07.00 GMT) our network is infected by yet another mass-mailing worm. I already submitted this worm as submission number 1530. ClamAv hasn't detected it yet. The thing is, after I manually unpack the zip file (which contains a .scr), the .scr was recognized as Worm

Re: [Clamav-users] Re: Re: 5 from testvirus.com came through

2004-03-01 Thread Thomas Lamy
Ignasi Prat schrieb: On Friday 27 February 2004 10:27 pm, Bryce wrote: Test # 17, 8, 5, 4, and 2 are making it through. I am using version What can I do to prevent this? Binhex was added in 0.67, so all binhex encoded e-mails will get through unless you upgrade. -Nigel I guess that answers my que

[Clamav-users] Re: Re: 5 from testvirus.com came through

2004-03-01 Thread Ignasi Prat
> >>On Friday 27 February 2004 10:27 pm, Bryce wrote: > >> > >> > >>>Test # 17, 8, 5, 4, and 2 are making it through. I am using version .65. > >>>What can I do to prevent this? > >>> > >>> > >> > >>Binhex was added in 0.67, so all binhex encoded e-mails will get through > >>unless you upgrade. > >