[Clamav-users] Submit form treating samples as false positives

2010-03-09 Thread rafa
Hi, When submitting samples they are treated as false positives. Result: This file is not detected by ClamAV. Please update your CVD database before reporting false-positives. If you are using third-party databases/unofficial signatures, please contact the author of the signature. We can onl

Re: [Clamav-users] Finding html and related files infected with Gumblar

2009-07-21 Thread rafa
Peter M. Abraham wrote: Greetings Edwin: I just created a HTML file with an infection on purpose to test. clamscan -i -r test.html found no infections. Here's what I put in the test file: Bitdefender detects it as Trojan.Script.177381 ___ Help us b

Re: [Clamav-users] Suggestion

2009-04-17 Thread rafa
Tom Shaw wrote: > Currently, I am tracking 233 files containing malware that have been > submitted both directly to clamav.net and virustotal.com and yet > continue not to show up in the signature database so that they can be > detected. My scripts check them frequently against the current clama

[Clamav-users] Submission tracking request

2009-02-25 Thread rafa
Can the Submission-ID be shown when you submit a sample via web. It would make life a bit easier to track which of your submitted samples are added to the db. Best regards, rafael. ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clam

Re: [Clamav-users] problems with virus submission

2009-02-23 Thread rafa
Brandon Perry wrote: > Hundreds of submissions aer made every day. I would probably wait a week > after submitting before worrying about it. If it is a severe problem, as in > your are getting tons of emails a day infected with the trojan, I would hop > on IRC or email a dev about it and see what t

Re: [Clamav-users] WARNING: DNS record is older than 3 hours. (freshclam.log)

2009-02-09 Thread rafa
John Horne wrote: > I have been getting the occasional same warning. From one server today: me too. -- Received signal: wake up Max retries == 5 ClamAV update process started at Mon Feb 9 12:56:49 2009 Using IPv6 aware code Querying current.cvd.clamav.net TTL:

Re: [Clamav-users] Using clamav on internet gateway

2009-02-06 Thread rafa
Sunny K wrote: > Hi, > > Is there any way to use clamav on an internet gateway (linux based) to > protect connected hosts from virus/malicious content? > > (Internet)-| Internet Gateway (linux on x86) | Host-1 > | > | Host-2 > > Thanks, > Sa

Re: [Clamav-users] simplest replacement for ancient amavis-perl

2008-08-07 Thread rafa
jef moskot wrote: > On Thu, 7 Aug 2008, Henrik K wrote: >> I use both, but MD is IMO more of a hobbyist tool... > > I didn't mean to spark a milter fight, but as the Subject line says, we're > looking for the simplest thing out there. I'm replacing a simplistic perl > script that just broke a mes

Re: [Clamav-users] Description Trojan.VB-2953

2008-06-06 Thread rafa
Robert Schetterer wrote: > Dennis Peterson schrieb: >> Robert Schetterer wrote: >>> Ian Eiloart schrieb: --On 6 June 2008 11:03:22 +0200 Robert Schetterer <[EMAIL PROTECTED]> wrote: > Robert Schetterer schrieb: >> Hi @ll, >> where kann i find >> a description about T

Re: [Clamav-users] Missed Virus

2007-08-08 Thread rafa
Jason Bennett wrote: > Hi everyone, > > We're using ClamAV on our mail gateway which is in front of our exchange > server. It's been running great for a long time and stops thousands of virus > per day for us. Lately however our McAfee which is installed on exchange > itself is picking up thi

Re: [Clamav-users] Greeting Card virus

2007-07-20 Thread rafa
Jeff Thurston wrote: >> I'm using the sanesecurity and MSRBL files too and are getting the >> same spam. >> >> I'll start sending them to Steve to incorporate. >> >> James. >> ___ >> Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net

Re: [Clamav-users] clam newbie

2004-08-17 Thread rafa
Kern, Tom wrote: Hi, i just installed clamav 0.75 on a redhat ES3 with amavis new. I was wondering, when i look into the clamd.log, all i see is worm.somefool.p. I know i'm getting more virii than that as my symantec corporate edition is catching netsky and beagle and other varients. i ran fresh