>> Any hints will be very much appreciated!

> Was the zip file encrypted?  Doesn't sound like it was since you ran it 
> through
> the online scanner, but those are potentially the only zip files that can pass
> through.

Not encrypted, as you expected.


> What version of clamav are you using? or more to the point, does your local
> installation detect the virus inside the zip file? (e.g. clamscan sample.zip).
> What we're looking at here is if your local virus signatures database is up to
> date, the online scan showed that the virus is recognized in the current
> database but perhaps your local one is not updated (hint: freshclam should be
> executed at least once a day).

ClamAV 0.85.1/898/Sat May 28 15:11:03 2005
freshclam runs hourly (querying db.au.clamav.net)

I think what happened was that the worm went through prior to being updated in 
the db, so it wasn't detected.

Thanks for your help!

Cheers,
Frode
_______________________________________________
http://lurker.clamav.net/list/clamav-users.html

Reply via email to