Thanks for the response! I just wanted to identify the cases where paypal.com is the real URL and yahoo.com is the displayable URL, to be identified as virus. Seems like clamscan doesn't identify cases where (real_URL != displayable_URL) as virus automatically (or am I missing something).
>> Why do you need regular expressions for the domainlist? My idea of using regular expressions is to match cases where you might have numbers or some special characters (like hyphens) before a subdomain. Thanks, Srini _______________________________________________ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml
