Re: [Wireshark-users] Barracuda false positive?

2007-05-10 Thread Ionreflex
I was just curious if there was any follow-up on this... 2007/4/20, Ionreflex <[EMAIL PROTECTED]>: So, the scan pinpoint again to sbus.dll as a ILookup.Sbus threat; I already had the file scanned by VirusTotal online solution, and the file is as clean as a surgeon before an operation! Gerald,

Re: [Wireshark-users] Barracuda false positive?

2007-04-20 Thread Ionreflex
So, the scan pinpoint again to sbus.dll as a ILookup.Sbus threat; I already had the file scanned by VirusTotal online solution, and the file is as clean as a surgeon before an operation! Gerald, since you already have a case open with Barracuda Networks, I'm gonna personally post you everything I

Re: [Wireshark-users] Barracuda false positive?

2007-04-19 Thread Frank Bulk
I have a Barracuda 600 if you want to test, too. Frank _ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ionreflex Sent: Thursday, April 19, 2007 1:10 PM To: Community support list for Wireshark Subject: Re: [Wireshark-users] Barracuda false positive? Well, I printed

Re: [Wireshark-users] Barracuda false positive?

2007-04-19 Thread Ionreflex
Well, I printed the report (should've kept a digital one!) and the spyware scantool from the Web-Filter appliance is clearly stating otherwise! I'm gonna rescan my laptop tonight, and post a follow-up tomorrow... Ion 2007/4/19, Gerald Combs <[EMAIL PROTECTED]>: I received a response about th

Re: [Wireshark-users] Barracuda false positive?

2007-04-19 Thread Gerald Combs
I received a response about the false positive issue. According to Barracuda, it shouldn't be possible. Their response follows: Gerald, We investigated your claim and found that our Web Filter could not be blocking the dll as described. Please see the attached explanation from one of o

Re: [Wireshark-users] Barracuda false positive?

2007-04-17 Thread Ionreflex
I hope you'll keep us informed... thanks! 2007/4/17, Gerald Combs <[EMAIL PROTECTED]>: ...so what happens when a malware writer decides to name one of his or her products "msvcr80.dll"? I've posted a question on Barracuda's support forum. It's pending approval. Ionreflex wrote: > Better now

Re: [Wireshark-users] Barracuda false positive?

2007-04-17 Thread Gerald Combs
...so what happens when a malware writer decides to name one of his or her products "msvcr80.dll"? I've posted a question on Barracuda's support forum. It's pending approval. Ionreflex wrote: > Better now than never! Since there was no feedback, I though I could > confirm that the Barracuda Web

[Wireshark-users] Barracuda false positive?

2007-04-17 Thread Ionreflex
Better now than never! Since there was no feedback, I though I could confirm that the Barracuda Web Filter appliance detects the stated infection since version 0.99.2 up to 0.99.5... *From*: Gerald Combs <[EMAIL PROTECTED] <[EMAIL PROTECTED]>> *Date*: Tue, 03 Oct 2006 09:11:17 -0700 I received

[Wireshark-users] Barracuda false positive?

2006-10-03 Thread Gerald Combs
I received a message from a user that the Barracuda spam/virus firewall has detected the ILookup.Sbus worm in the Wireshark 0.99.2 release. This appears to a false positive -- the worm comes in a file named "sbus.dll", which is the same name used by Wireshark's S-Bus plugin. Are there any Barracud