Re: [Clamav-users] DHL invoices

2009-09-24 Thread Jari Fredriksson
> On 2009-09-24 16:01, Jari Fredriksson wrote: >>> Hello Jari, >>> >>> clamav NOW detects that even without pua, things updated. But the older DHL-incoices. No. Not even with detect-pua=yes. >>> what does the form answer you when you try to submit it? >>> It should reject it

Re: [Clamav-users] DHL invoices

2009-09-24 Thread Tom Shaw
At 9:53 AM -0400 9/24/09, Tom Shaw wrote: At 2:19 PM +0100 9/24/09, Steve Basford wrote: > Yeah, we already know that. Can you please cut&paste the full message returned by the form? Thanks, Hi Luca, I've *just* uploaded 4 copies of the dhl invoice malware that have been missed by up-to-da

Re: [Clamav-users] DHL invoices

2009-09-24 Thread Tom Shaw
At 2:19 PM +0100 9/24/09, Steve Basford wrote: > Yeah, we already know that. Can you please cut&paste the full message returned by the form? Thanks, Hi Luca, I've *just* uploaded 4 copies of the dhl invoice malware that have been missed by up-to-date official sigs. These were blocked using

Re: [Clamav-users] DHL invoices

2009-09-24 Thread Steve Basford
> Yeah, we already know that. Can you please cut&paste the full message > returned by the form? Thanks, Hi Luca, I've *just* uploaded 4 copies of the dhl invoice malware that have been missed by up-to-date official sigs. These were blocked using Sanesecurity.Malware.12505.UNOFFICIAL. Hope it h

Re: [Clamav-users] DHL invoices

2009-09-24 Thread Luca Gibelli
Hello Jari, > >> clamav NOW detects that even without pua, things updated. > >> But the older DHL-incoices. No. Not even with > >> detect-pua=yes. > > what does the form answer you when you try to submit it? > > It should reject it with a message. > > That message can help us to track down the i

Re: [Clamav-users] DHL invoices

2009-09-24 Thread Török Edwin
On 2009-09-24 16:01, Jari Fredriksson wrote: >> Hello Jari, >> >> >>> clamav NOW detects that even without pua, things updated. >>> But the older DHL-incoices. No. Not even with >>> detect-pua=yes. >>> >> what does the form answer you when you try to submit it? >> It should reject it w

Re: [Clamav-users] DHL invoices

2009-09-24 Thread Jari Fredriksson
> Hello Jari, > >> clamav NOW detects that even without pua, things updated. >> But the older DHL-incoices. No. Not even with >> detect-pua=yes. > > what does the form answer you when you try to submit it? > It should reject it with a message. > > That message can help us to track down the issu

Re: [Clamav-users] DHL invoices

2009-09-24 Thread Luca Gibelli
Hello Jari, > clamav NOW detects that even without pua, things updated. > But the older DHL-incoices. No. Not even with detect-pua=yes. what does the form answer you when you try to submit it? It should reject it with a message. That message can help us to track down the issue. Best regards -

Re: [Clamav-users] DHL invoices

2009-09-24 Thread Jari Fredriksson
>> Seems to work. I just got this: >> >> -- >> A virus was found: W32/Downldr3.GW >> >> Banned name: .exe,.exe-ms,open.exe >> Scanners detecting a virus: F-PROT Antivirus for UNIX, >> BitDefender >> >> Content type: Virus >> Internal reference

Re: [Clamav-users] DHL invoices

2009-09-24 Thread Török Edwin
On 2009-09-24 01:02, Jari Fredriksson wrote: >> I am a tad confused about your reporting comment as the >> clamav web reporting mechanism works fine at least for me >> and you can also >> report via virustotal as well. >> >> Anyway glad your happy with your config. >> >> Tom >> >> btw its winnow a

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jari Fredriksson
> I am a tad confused about your reporting comment as the > clamav web reporting mechanism works fine at least for me > and you can also > report via virustotal as well. > > Anyway glad your happy with your config. > > Tom > > btw its winnow as in to remove the wheat from the chaff > and has >

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jari Fredriksson
> Jari Fredriksson wrote: > >> I give rat's ass to WinNow. If I would have been >> interested in SaneSecurity or WinNow I would have >> installed those again, and tested with them. >> > > Don't let it fall through the cracks that people here are > trying to help you. > Of course, just like I

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Tom Shaw
At 12:20 AM +0300 9/24/09, Jari Fredriksson wrote: >> This is what I found about Phishing and Heuristics. Dangerous? When I review the quaratine anyway. No more than sanesecurity rules and alot more than my winnow_malware.hdb which would have caught your virus. Point being you might jus

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Dennis Peterson
Jari Fredriksson wrote: I give rat's ass to WinNow. If I would have been interested in SaneSecurity or WinNow I would have installed those again, and tested with them. Don't let it fall through the cracks that people here are trying to help you. dp ___

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jari Fredriksson
>> >> This is what I found about Phishing and Heuristics. >> Dangerous? When I review the quaratine anyway. > > No more than sanesecurity rules and alot more than my > winnow_malware.hdb which would have caught your virus. > > Point being you might just want to consider what you have > running..

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Tom Shaw
At 11:31 PM +0300 9/23/09, Jari Fredriksson wrote: > At 10:39 PM +0300 9/23/09, Jari Fredriksson wrote: >> I don't run ClamAV via SpamAssassin. I have it called by amavisd-new, which does what it does: quarantine. Sure hope your not using heuristics, phishing and/or safebrowsing op

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jari Fredriksson
> At 10:39 PM +0300 9/23/09, Jari Fredriksson wrote: >> >> I don't run ClamAV via SpamAssassin. I have it called by amavisd-new, which does what it does: quarantine. >>> >>> Sure hope your not using heuristics, phishing and/or >>> safebrowsing options in ClamAV if you feel that way.

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Tom Shaw
At 10:42 PM +0300 9/23/09, Jari Fredriksson wrote: > On Wed, Sep 23, 2009 at 08:11:41PM +0300, Jari Fredriksson wrote: Ehm, were you scoring SaneSecurity hits like one is supposed to, or just plain rejecting with them? Sounds like the latter. I don't run ClamAV via SpamAssassin. I hav

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Tom Shaw
At 10:39 PM +0300 9/23/09, Jari Fredriksson wrote: >> I don't run ClamAV via SpamAssassin. I have it called by amavisd-new, which does what it does: quarantine. Sure hope your not using heuristics, phishing and/or safebrowsing options in ClamAV if you feel that way. I use amavisd-new d

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jari Fredriksson
> On Wed, Sep 23, 2009 at 08:11:41PM +0300, Jari > Fredriksson wrote: >>> >>> Ehm, were you scoring SaneSecurity hits like one is >>> supposed to, or just plain rejecting with them? Sounds >>> like the latter. >>> >> >> I don't run ClamAV via SpamAssassin. I have it called by >> amavisd-new, wh

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jari Fredriksson
>> >> I don't run ClamAV via SpamAssassin. I have it called by >> amavisd-new, which does what it does: quarantine. > > Sure hope your not using heuristics, phishing and/or > safebrowsing options in ClamAV if you feel that way. > I use amavisd-new default options, have not touched those. Anywa

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jose-Marcio Martins da Cruz
Jari Fredriksson wrote: I have not tried virustotal. I have the zip file and the extracted exe as well on disk, and clamscan does NOT detect it. I have F-Prot and BitDefender in my amavisd-new as well, and I have no problems detecting these. The point in this post is that ClamAV website

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Tom Shaw
At 8:11 PM +0300 9/23/09, Jari Fredriksson wrote: > On Wed, Sep 23, 2009 at 07:07:53PM +0300, Jari Fredriksson wrote: Jari Fredriksson wrote: Then I decided SaneSecurity is not worth it, as SpamAssassin catches those too, and has less false positives. SaneSecurity triggers way too of

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Henrik K
On Wed, Sep 23, 2009 at 08:11:41PM +0300, Jari Fredriksson wrote: > > > > Ehm, were you scoring SaneSecurity hits like one is > > supposed to, or just plain rejecting with them? Sounds > > like the latter. > > > > I don't run ClamAV via SpamAssassin. I have it called by amavisd-new, > which doe

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jari Fredriksson
> On Wed, Sep 23, 2009 at 07:07:53PM +0300, Jari > Fredriksson wrote: >>> Jari Fredriksson wrote: >>> Then I decided SaneSecurity is not worth it, as SpamAssassin catches those too, and has less false positives. SaneSecurity triggers way too often when some dumb us

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Henrik K
On Wed, Sep 23, 2009 at 07:07:53PM +0300, Jari Fredriksson wrote: > > Jari Fredriksson wrote: > > > >> > >> Then I decided SaneSecurity is not worth it, as > >> SpamAssassin catches those too, and has less false > >> positives. > >> > >> SaneSecurity triggers way too often when some dumb user >

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jari Fredriksson
> Jari Fredriksson wrote: > >> >> Then I decided SaneSecurity is not worth it, as >> SpamAssassin catches those too, and has less false >> positives. >> >> SaneSecurity triggers way too often when some dumb user >> pastes a spam into his mail, or some robot sends a >> bounce with an attachment.

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Dennis Peterson
Jari Fredriksson wrote: Then I decided SaneSecurity is not worth it, as SpamAssassin catches those too, and has less false positives. SaneSecurity triggers way too often when some dumb user pastes a spam into his mail, or some robot sends a bounce with an attachment. I do not want to report th

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jari Fredriksson
>> I get lots of 'invoices' from DHL containing a zipped >> trojan. F-Prot recognizes them as Win32/Bredolab!Generic >> but ClamAV does not. > > Hi, > > Just in case this helps block them... I've been detecting > these for a while if its the same sort of fake invoices > I've been receiving here,

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jari Fredriksson
>> -Original Message- >> From: clamav-users-boun...@lists.clamav.net >> [mailto:clamav-users- boun...@lists.clamav.net] On >> Behalf Of Jari Fredriksson >> Sent: Wednesday, September 23, 2009 9:14 AM >> To: ClamAV Users >> Subject: [Clamav-us

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Tom Shaw
At 3:09 PM +0100 9/23/09, Steve Basford wrote: > I get lots of 'invoices' from DHL containing a zipped trojan. F-Prot recognizes them as Win32/Bredolab!Generic but ClamAV does not. Hi, Just in case this helps block them... I've been detecting these for a while if its the same sort of fake

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Steve Basford
> > I get lots of 'invoices' from DHL containing a zipped trojan. F-Prot > recognizes them as Win32/Bredolab!Generic but ClamAV does not. Hi, Just in case this helps block them... I've been detecting these for a while if its the same sort of fake invoices I've been receiving here, using the Sanes

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jason Bertoch
> -Original Message- > From: clamav-users-boun...@lists.clamav.net [mailto:clamav-users- > boun...@lists.clamav.net] On Behalf Of Jari Fredriksson > Sent: Wednesday, September 23, 2009 9:14 AM > To: ClamAV Users > Subject: [Clamav-users] DHL invoices > > > I

[Clamav-users] DHL invoices

2009-09-23 Thread Jari Fredriksson
I get lots of 'invoices' from DHL containing a zipped trojan. F-Prot recognizes them as Win32/Bredolab!Generic but ClamAV does not. I tried to post one to ClamAV site, but it was said to be recognized already. I have ClamAV 0.95.2/9826/Wed Sep 23 14:06:01 2009 main.cvd is up to date