Re: [clamav-users] Clamav and ransomware

2014-06-12 Thread G.W. Haywood
B0;278;0cHi there, On Thu, 12 Jun 2014, Alex wrote: I'm using clamav with spamassassin and amavisd. We use sendmail, but that shouldn't matter. :) I have a few hundred whitelist entries, and I'm concerned that some of those accounts may have been compromised, and have become the source of

Re: [clamav-users] Clamav and ransomware

2014-06-12 Thread Henri Salo
On Thu, Jun 12, 2014 at 06:45:36PM +0100, G.W. Haywood wrote: I have a few hundred whitelist entries, and I'm concerned that some of those accounts may have been compromised, and have become the source of these attacks. Er, take them off the whitelist and explain to them why you did it? If

[clamav-users] Clamav and ransomware

2014-06-11 Thread Alex
Hi all, I'm using clamav-0.98.3 with fedora20 and amavisd-new-2.8.1. I have a few questions relating to so-called ransomware (cryptolocker and the like). Is there a specific category of patterns that are related to catching this class of attacks in email? Are they generally just phishing URLs?