Are you sure CLAMAV is hitting on this or is this a hit from the SANE phish 
database being used with CLAM?

Darrell
------------------------------------------------------------------------
Check out http://www.invariantsystems.com for utilities for Declude And Imail.  
IMail/Declude Overflow Queue Monitoring, SURBL/URI integration, MRTG 
Integration, and Log Parsers.
  ----- Original Message ----- 
  From: Bonno Bloksma 
  To: [email protected] 
  Sent: Monday, May 21, 2007 7:09 AM
  Subject: [Declude.Virus] False Positive ClamAV


  Hi,

  Some of our mail is getting caught bij ClamAV. I've had two reports on two 
completely unrelated mails.

  Body of message generated response:
  554 5.7.1 virus Email.Phishing.RB-882 detected by ClamAV - 
http://www.clamav.net

  I submitted a virus http://cgi.clamav.net/sendvirus.cgi tagging it as a false 
positive report. When I hit Submit I get an error stating this virus is already 
known and I should fix something in the submission. :-(

  Can anyone tell me:
  1) Whether this is normail behaviour for that page?
  2) Where I can report this bug in the webpage? It's not a bug in the program 
so I don't think the Bugzilla page is the right place. If I need to report it 
via a mailing list, which one?
  3) How I can check whether my report was received?


  Met vriendelijke groet,
  Bonno Bloksma
  hoofd systeembeheer



  tio hogeschool hotelmanagement en toerisme 
  begijnenhof 8-12 / 5611 el eindhoven
  t 040 296 28 28 / f 040 237 35 20
  [EMAIL PROTECTED]  / www.tio.nl 

  ---
  This E-mail came from the Declude.Virus mailing list. To
  unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
  type "unsubscribe Declude.Virus". The archives can be found
  at http://www.mail-archive.com. 

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to