RE: [Clamav-users] password protected zip files

2004-06-18 Thread Simon Fishley
-Original Message- From: Robin Lynn Frank [mailto:[EMAIL PROTECTED] Sent: 18 June 2004 02:48 AM To: [EMAIL PROTECTED] Subject: [Clamav-users] password protected zip files emails with the eicar test virus in password protected zip files were not caught.

Re: [Clamav-users] password protected zip files

2004-06-18 Thread Jeremy Kitchen
On Friday 18 June 2004 03:12 am, Simon Fishley wrote: When you think about it though - does it really matter if you don't stop a virus in an encrypted archive file? Unless the recipient knows the password there is very little risk of damage. Not a very successful way of getting a virus to

Re: [Clamav-users] password protected zip files

2004-06-18 Thread Antony Stone
On Friday 18 June 2004 9:12 am, Simon Fishley wrote: When you think about it though - does it really matter if you don't stop a virus in an encrypted archive file? Unless the recipient knows the password there is very little risk of damage. Not a very successful way of getting a virus to

[Clamav-users] Qmail-scanner Statistics with QS 1.22st

2004-06-18 Thread Andrej Trobentar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello all, Does anyone have working QS Statistics with the above version of QS? The statistics were working OK until I upgraded to 1.22st - now my statistics look like this - http://www.sk-branik.si/qss =( - -- Thanks for the info and have a nice day,

Re: [Clamav-users] Qmail-scanner Statistics with QS 1.22st

2004-06-18 Thread Andrej Trobentar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Andrej Trobentar wrote: | Hello all, | | Does anyone have working QS Statistics with the above version of QS? The | statistics were working OK until I upgraded to 1.22st - now my | statistics look like this - http://www.sk-branik.si/qss =( Ups, sorry,

Re: [Clamav-users] How to disinfect an mbox file?

2004-06-18 Thread Jim Maul
Quoting Bill Randle [EMAIL PROTECTED]: On Thu, 2004-06-17 at 19:16, Michael D. Crawford wrote: I think the virus that's assaulting me is what this page calls the PE_ZAFI.B virus: http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=PE_ZAFI.BVSect=T The clamav database lists a virus

[Clamav-users] uncompressing/scanning Mac archives (i.e. .sit, .sitx, and .hqx)

2004-06-18 Thread Timo Schöler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 hi, after having clamav up and running for a while -- it's great! thanks to all who develop || support it -- there's still another topic in status 'wip': how to uncompress .sit, .sitx, and .hqx files (usually sent/received by Mac users)? i asked

[Clamav-users] Sendmail pukes

2004-06-18 Thread Scott Rothgaber
Good Morning! Some time ago I installed clamav from source on a FreeBSD 5.0 machine that was also running Sendmail 8.12.10 and SA 2.63. Sendmail immediately complained that it couldn't allocate any memory, so I abandoned the project. At the time, I chalked it up to a FreeBSD issue. The 5.x tree

Re: [Clamav-users] password protected zip files

2004-06-18 Thread Tomasz Kojm
On Fri, 18 Jun 2004 09:25:31 +0100 Antony Stone [EMAIL PROTECTED] wrote: On Friday 18 June 2004 9:12 am, Simon Fishley wrote: When you think about it though - does it really matter if you don't stop a virus in an encrypted archive file? Unless the recipient knows the password there is

Re: [Clamav-users] uncompressing/scanning Mac archives (i.e. .sit, .sitx, and .hqx)

2004-06-18 Thread Tomasz Papszun
On Fri, 18 Jun 2004 at 15:24:27 +0200, Timo Schöler wrote: after having clamav up and running for a while -- it's great! thanks to all who develop || support it -- there's still another topic in status 'wip': how to uncompress .sit, .sitx, and .hqx files (usually sent/received by Mac

Re: [Clamav-users] How to disinfect an mbox file?

2004-06-18 Thread Jeremy Kitchen
On Friday 18 June 2004 06:29 am, Jim Maul wrote: Its also interesting to note that even before clamav detected zafi it was being blocked by qmail-scanner: Jun 15 12:25:19 external qmail-scanner[29017]: Policy:Bad_MIME_Break:RC:0(24.188.90.209):SA:1(10.5/5.0): 2.184665 18140 [EMAIL

Re: [Clamav-users] password protected zip files

2004-06-18 Thread Robin Lynn Frank
-BEGIN PGP SIGNED MESSAGE- Hash: RIPEMD160 On Friday 18 June 2004 01:12, Simon Fishley wrote: -Original Message- From: Robin Lynn Frank [mailto:[EMAIL PROTECTED] Sent: 18 June 2004 02:48 AM To: [EMAIL PROTECTED] Subject: [Clamav-users] password protected zip files emails

Re: [Clamav-users] password protected zip files

2004-06-18 Thread Robin Lynn Frank
-BEGIN PGP SIGNED MESSAGE- Hash: RIPEMD160 On Friday 18 June 2004 04:25, Tomasz Kojm wrote: ClamAV is able to detect it (in contrast to many commercial scanners) and there's no need to reeject all encrypted files. If you note my original post, password-protected zips were getting by

Re: [Clamav-users] password protected zip files

2004-06-18 Thread Matt
On Thursday 17 June 2004 18:01, Matt wrote: #ArchiveDetectEncrypted Hmm, my config file had #ArchiveBlockEncrypted I uncommented it and restarted clamd, but I wonder which is the correct one? - -- I could be wrong, but I think the later versions still accept the older syntax, so

Re: [Clamav-users] password protected zip files

2004-06-18 Thread Tomasz Kojm
On Fri, 18 Jun 2004 08:31:55 -0700 Robin Lynn Frank [EMAIL PROTECTED] wrote: -BEGIN PGP SIGNED MESSAGE- Hash: RIPEMD160 On Friday 18 June 2004 04:25, Tomasz Kojm wrote: ClamAV is able to detect it (in contrast to many commercial scanners) and there's no need to reeject all

Re: [Clamav-users] password protected zip files

2004-06-18 Thread Robin Lynn Frank
-BEGIN PGP SIGNED MESSAGE- Hash: RIPEMD160 On Friday 18 June 2004 10:46, Tomasz Kojm wrote: In your original post you mentioned a problem with detection of the test #12 from testvirus.org. I consider this particular test (encrypted eicar test file) rather useless and stupefying and

Re: [Clamav-users] How to disinfect an mbox file?

2004-06-18 Thread Michael D. Crawford
I've been using formail, procmail and clamav to disinect a 200 MB mailbox, and since last night it's only processed 80 MB of mail so far. It's a 350 Mhz box that I'm running it on, and clamav must be pretty CPU intensive. Somebody tipped me off to the following procmail config, which filters on

[Clamav-users] Determining the Current Virus DB Version / Date

2004-06-18 Thread Lee W
Hi All, I have just compiled ClamAV and have started playing out with it, however after reading though the man pages I have been unable to find an easy way of determining the current version or date of the Virus DB files. The --version switch the freshclam only reports the version of

Re: [Clamav-users] Determining the Current Virus DB Version / Date

2004-06-18 Thread Ryan Moore
Lee W wrote: Hi All, I have just compiled ClamAV and have started playing out with it, however after reading though the man pages I have been unable to find an easy way of determining the current version or date of the Virus DB files. The --version switch the freshclam only reports the version

Re: [Clamav-users] How to disinfect an mbox file?

2004-06-18 Thread Tomasz Papszun
On Fri, 18 Jun 2004 at 15:08:32 -0700, Michael D. Crawford wrote: I've been using formail, procmail and clamav to disinect a 200 MB mailbox, and since last night it's only processed 80 MB of mail so far. It's a 350 Mhz That's a very slow progress! I suspect you use clamscan. So clamscan is

Re: [Clamav-users] Determining the Current Virus DB Version / Date

2004-06-18 Thread [EMAIL PROTECTED]
Ryan Moore said: Lee W wrote: Hi All, I have just compiled ClamAV and have started playing out with it, however after reading though the man pages I have been unable to find an easy way of determining the current version or date of the Virus DB files. The --version switch the freshclam

[Clamav-users] Sendmail pukes (more info)

2004-06-18 Thread Scott Rothgaber
A list member suggested running clamd as root (temporarily, of course). Sendmail no longer complains. I'm getting the following error now... clamav-milter[17693]: Expected port information from clamd, got '' sm-mta[17703]: i5J2IuTg017703: Milter: data, reject=451 4.7.1 Please try again later