Re: [clamav-users] missed virus

2012-11-16 Thread TR Shaw
Hi winnow.attachments.hdb winnow_bad_cw.hdb winnow_malware_links.ndb Also work to stop these On Nov 15, 2012, at 4:55 PM, Steve Basford wrote: > >> OK, I'm stumped as to why clamav-milter did not catch this virus. It was >> from this address, being masked as from UPS: >> >> >> File: Invoices

Re: [clamav-users] missed virus

2012-11-15 Thread David Raynor
On Thu, Nov 15, 2012 at 4:25 PM, McGranahan, Jamen < jamen.mcgrana...@vanderbilt.edu> wrote: > OK, I'm stumped as to why clamav-milter did not catch this virus. It was > from this address, being masked as from UPS: > > rowanhorst...@live.ca, masked as > customerdesk_u

Re: [clamav-users] missed virus

2012-11-15 Thread Steve Basford
> OK, I'm stumped as to why clamav-milter did not catch this virus. It was > from this address, being masked as from UPS: > > > File: Invoices-14-2012.htm" > Hi Jamen, I've been seeing these java/htm combos over the last few days and been adding detection to phish.ndb. The other bad stuff coming

[clamav-users] missed virus

2012-11-15 Thread McGranahan, Jamen
OK, I'm stumped as to why clamav-milter did not catch this virus. It was from this address, being masked as from UPS: rowanhorst...@live.ca, masked as customerdesk_upsdeliveryservi...@ups.com Nov 14 14:13:33 XX s

Re: [Clamav-users] Missed Virus

2007-08-08 Thread Dennis Peterson
Jason Bennett wrote: > Hi everyone, > > We're using ClamAV on our mail gateway which is in front of our exchange > server. It's been running great for a long time and stops thousands of virus > per day for us. Lately however our McAfee which is installed on exchange > itself is picking up thi

Re: [Clamav-users] Missed Virus

2007-08-08 Thread Steve Basford
SM wrote: > At 11:55 08-08-2007, Jonathan Armitage wrote: > > It's not a virus, it's these greeting card messages with a link to > download the malware. It's currently being identified as > Email.Phishing.RB-1222. > > And this is when it was added to the database: http://lurker.clamav.ne

Re: [Clamav-users] Missed Virus

2007-08-08 Thread SM
At 11:55 08-08-2007, Jonathan Armitage wrote: >Didn't I read somewhere recently that there have been a lot of new >variants of this virus? It's not a virus, it's these greeting card messages with a link to download the malware. It's currently being identified as Email.Phishing.RB-1222. Regards

Re: [Clamav-users] Missed Virus

2007-08-08 Thread rafa
Jason Bennett wrote: > Hi everyone, > > We're using ClamAV on our mail gateway which is in front of our exchange > server. It's been running great for a long time and stops thousands of virus > per day for us. Lately however our McAfee which is installed on exchange > itself is picking up thi

Re: [Clamav-users] Missed Virus

2007-08-08 Thread Jonathan Armitage
Jason Bennett wrote: > Hi everyone, > > We're using ClamAV on our mail gateway which is in front of our > exchange server. It's been running great for a long time and stops > thousands of virus per day for us. Lately however our McAfee which > is installed on exchange itself is picking up this v

Re: [Clamav-users] Missed Virus

2007-08-08 Thread Ralf Hildebrandt
* Ralf Hildebrandt <[EMAIL PROTECTED]>: > False positive? By any means, submit it to the team. http://www.clamav.net/sendvirus/ ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://lurker.clamav.net/list/clamav-users.htm

Re: [Clamav-users] Missed Virus

2007-08-08 Thread Ralf Hildebrandt
* Jason Bennett <[EMAIL PROTECTED]>: > Hi everyone, > > We're using ClamAV on our mail gateway which is in front of our exchange > server. It's been running great for a long time and stops thousands of virus > per day for us. Lately however our McAfee which is installed on exchange > itself i

[Clamav-users] Missed Virus

2007-08-08 Thread Jason Bennett
Hi everyone, We're using ClamAV on our mail gateway which is in front of our exchange server. It's been running great for a long time and stops thousands of virus per day for us. Lately however our McAfee which is installed on exchange itself is picking up this virus: W32/Zhelatin.gen!eml