[Clamav-users] mirrors down.

2004-10-19 Thread Thomas Kinghorn
Hi list Just to let you know that the US mirrors seem to be down. The following mirror is stil working fine. http://ovh.dl.sourceforge.net/sourceforge/clamav/clamav-0.80.tar.gz http://ovh.dl.sourceforge.net/sourceforge/clamav/clamav-0.80.tar.gz Regards, Tom Kinghorn

Re: [Clamav-users] Freshclam DNS Warnings

2004-10-19 Thread Rob MacGregor
On Tue, 19 Oct 2004 14:42:48 +1000, Bill Maidment [EMAIL PROTECTED] wrote: One of my servers is giving these warnings. What causes this and is it anything to worry about? I've been seeing the same error from time to time, so you're not alone :) -- Please keep list traffic on

Re: [Clamav-users] non detection problem

2004-10-19 Thread Meni Shapiro
Tomasz Kojm wrote: Is that a problem??? or what? The problem is you haven't even read my yesterday's e-mails in this case. Sorry about that , BUT scanning the tons of emails i get from this mailing list and others (mimedefang thinstation) is sometimes too hard work sometimes too boring.

Re: [Clamav-users] non detection problem

2004-10-19 Thread Rob MacGregor
On Tue, 19 Oct 2004 08:34:48 +0200, Meni Shapiro [EMAIL PROTECTED] wrote: Sorry about that , BUT scanning the tons of emails i get from this mailing list and others (mimedefang thinstation) is sometimes too hard work sometimes too boring. If you're not going to even try to read the replies,

[Clamav-users] non detection problem

2004-10-19 Thread Meni Shapiro
Rob MacGregor wrote: On Tue, 19 Oct 2004 08:34:48 +0200, Meni Shapiro [EMAIL PROTECTED] wrote: Sorry about that , BUT scanning the tons of emails i get from this mailing list and others (mimedefang thinstation) is sometimes too hard work sometimes too boring. If you're not going to even try to

[Clamav-users] can't compile clamav 0.80

2004-10-19 Thread Korchmenuk Nickolay
Hi I'v got next errors and warnings whe try configure clamav 0.80: configure: WARNING: resolv.h: present but cannot be compiled configure: WARNING: resolv.h: check for missing prerequisite headers? configure: WARNING: resolv.h: see the Autoconf documentation configure: WARNING: resolv.h:

Re: [Clamav-users] can't compile clamav 0.80

2004-10-19 Thread Dale Walsh
On Oct 19, 2004, at 03:10, Korchmenuk Nickolay wrote: Hi I'v got next errors and warnings whe try configure clamav 0.80: configure: WARNING: resolv.h: present but cannot be compiled configure: WARNING: resolv.h: check for missing prerequisite headers? configure: WARNING: resolv.h: see the

Re: [Clamav-users] can't compile clamav 0.80

2004-10-19 Thread Korchmenuk Nickolay
On Tue, 19 Oct 2004 03:16:53 -0400 Dale Walsh [EMAIL PROTECTED] wrote: OS: FreeBSD 5.2.1-RELEASE-p1 -- Korchmenuk Nickolay 19 Oct 2004 10:23:50 ___ http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users

[Clamav-users] milter version

2004-10-19 Thread christian laubscher
when i enter 'clamd -V' i get a version line reflecting the i get a version line indicating the current database version, eg .../535/..., currently. the clamav-milter X-Virus-Scanned lines, however, seem to reflect the version feedback of clamd when the milter was started, not the current

[Clamav-users] Problems after upgrading to 0.80

2004-10-19 Thread Graham Dodd
So I made the leap from 0.75.1 to 0.80 and get the following error in exim log 2004-10-19 09:20:52 1CJoIe-0002Ut-E3 malware acl condition: clamd: unable to read from socket (No such file or directory) 2004-10-19 09:20:52 1CJoIe-0002Ut-E3 H=floyd.blarg.net (mail.blarg.net) [206.124.128.8]:56990

[Clamav-users] Your ClamAV installation is OUTDATED ?

2004-10-19 Thread Michael Hübler
Hello together Iam a new ClamAV user. I have installed it a few days ago on my win2k windows PC. I have an scheudled update every hour. but now i always got this warnings here: --- WARNING: Your ClamAV installation is OUTDATED - please update immediately ! WARNING: Current functionality level =

Re: [Clamav-users] Problems after upgrading to 0.80

2004-10-19 Thread Brian Morrison
On Tue, 19 Oct 2004 09:42:23 +0200 in [EMAIL PROTECTED] Graham Dodd [EMAIL PROTECTED] wrote: I'm still searching the archives, but if anyone can point me in the right direction it would help Have a look at the thread about Exim entitled Upgrading to 0.80rc3 breaks Exim malware acl. The

Re: [Clamav-users] Problems after upgrading to 0.80

2004-10-19 Thread Fajar A. Nugraha
Graham Dodd wrote: So I made the leap from 0.75.1 to 0.80 and get the following error in exim log 2004-10-19 09:20:52 1CJoIe-0002Ut-E3 malware acl condition: clamd: unable to read from socket (No such file or directory) 2004-10-19 09:20:52 1CJoIe-0002Ut-E3 H=floyd.blarg.net (mail.blarg.net)

Re: [Clamav-users] Your ClamAV installation is OUTDATED ?

2004-10-19 Thread Brian Morrison
On Tue, 19 Oct 2004 10:00:41 +0200 in [EMAIL PROTECTED] Michael Hübler [EMAIL PROTECTED] wrote: I couldnt find something about it on the net. So i ask you: What is this? Are my hourly updates not enough? How can i solve this problem? I have the Clamwin 0.35.2 running. IT IS the latest

Re: [Clamav-users] Your ClamAV installation is OUTDATED ?

2004-10-19 Thread Fajar A. Nugraha
Michael Hübler wrote: I have an scheudled update every hour. but now i always got this warnings here: --- WARNING: Your ClamAV installation is OUTDATED - please update immediately ! WARNING: Current functionality level = 2, required = 3 --- I couldnt find something about it on the net. So i ask

Re: [Clamav-users] Problems after upgrading to 0.80

2004-10-19 Thread Brian Morrison
On Tue, 19 Oct 2004 15:03:13 +0700 in [EMAIL PROTECTED] Fajar A. Nugraha [EMAIL PROTECTED] wrote: exim 4.24 (the exiscan patch of it, to be exact) seems to have that problem. Use exim 4.41 instead. Or even 4.43 with exiscan-acl-28. -- Brian Morrison bdm at fenrir dot org dot uk

AW: [Clamav-users] Problems after upgrading to 0.80

2004-10-19 Thread Mehnert
-- So I made the leap from 0.75.1 to 0.80 and get the following -- error in exim -- log -- -- 2004-10-19 09:20:52 1CJoIe-0002Ut-E3 malware acl condition: -- clamd: unable to -- read from socket (No such file or directory) -- 2004-10-19 09:20:52 1CJoIe-0002Ut-E3 H=floyd.blarg.net

Re: [Clamav-users] Problems after upgrading to 0.80

2004-10-19 Thread Frank Elsner
On Tue, 19 Oct 2004 15:03:13 +0700 Fajar A. Nugraha wrote: [ ... ] exim 4.24 (the exiscan patch of it, to be exact) seems to have that problem. Use exim 4.41 instead. Or use the newest exim-4.43/exiscan-acl-4.43-28 combination. Works great with ClamAV 0.80. --Frank Elsner

RE: [Clamav-users] Problems after upgrading to 0.80

2004-10-19 Thread Graham Dodd
[EMAIL PROTECTED] wrote: On Tue, 19 Oct 2004 15:03:13 +0700 Fajar A. Nugraha wrote: [ ... ] exim 4.24 (the exiscan patch of it, to be exact) seems to have that problem. Use exim 4.41 instead. Or use the newest exim-4.43/exiscan-acl-4.43-28 combination. Works great with ClamAV 0.80.

Re: [Clamav-users] Your ClamAV installation is OUTDATED ?

2004-10-19 Thread steve
Quoting Michael Hübler [EMAIL PROTECTED]: I couldnt find something about it on the net. So i ask you: What is this? Are my hourly updates not enough? How can i solve this problem? I have the Clamwin 0.35.2 running. IT IS the latest release. What is Outdated then? As people have already

Re: [Clamav-users] Problems after upgrading to 0.80

2004-10-19 Thread Brian Morrison
On Tue, 19 Oct 2004 10:23:04 +0200 in [EMAIL PROTECTED] Graham Dodd [EMAIL PROTECTED] wrote: [EMAIL PROTECTED] wrote: On Tue, 19 Oct 2004 15:03:13 +0700 Fajar A. Nugraha wrote: [ ... ] exim 4.24 (the exiscan patch of it, to be exact) seems to have that problem. Use exim 4.41

[Clamav-users] qmail-scanner-1.23 and clamav 0.80

2004-10-19 Thread Kareem Mahgoub
Hello list, I have upgraded from clamav 075.1 to clamav-80 using the rpm for FC2. after the upgrade, qmail-scanner ( 1.23 ) is not detecting clamav. I have recompiles qmail-scanner, ran qmail-scanner.pl -z and qmail-scanner.pl -g , with the same result. Any clue?? Best Regards, Kareem Mahgoub

Re: [Clamav-users] freshclam: Chunked Transfer Coding

2004-10-19 Thread Jo Mills
Hi, First let me apologize if this is way off the mark, but it has aroused my curiosity. When you say freshclam fails, do you get a return value of 1? I only ask because we have two Web Proxies in the office, one is a Novell box and the other is Squid/Debian. I built the Squid/Debian box as

[Clamav-users] Re: clamav-users Digest, Vol 2, Issue 57

2004-10-19 Thread Michael Hübler
PERFECT! -- Message: 12 Date: Tue, 19 Oct 2004 01:23:37 -0700 From: [EMAIL PROTECTED] Subject: Re: [Clamav-users] Your ClamAV installation is OUTDATED ? To: ClamAV users ML [EMAIL PROTECTED] Message-ID: [EMAIL PROTECTED] Content-Type: text/plain;

[Clamav-users] New version Clamd with Daemontools

2004-10-19 Thread Awie
All, I stuck to use clamd of version 0.80 with daemontools (I used this scheme very nicely for older version). Does anyone know how to do it? Thx Rgds, Awie ___ http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users

Re: [Clamav-users] can't compile clamav 0.80

2004-10-19 Thread Rob MacGregor
On Tue, 19 Oct 2004 10:24:07 +0300, Korchmenuk Nickolay [EMAIL PROTECTED] wrote: On Tue, 19 Oct 2004 03:16:53 -0400 Dale Walsh [EMAIL PROTECTED] wrote: OS: FreeBSD 5.2.1-RELEASE-p1 Update your ports and install from there. -- Please keep list traffic on the list. Rob

Re: [Clamav-users] qmail-scanner-1.23 and clamav 0.80

2004-10-19 Thread Alex Pleiner
* Kareem Mahgoub [EMAIL PROTECTED] [2004-10-19 10:32]: Hello list, I have upgraded from clamav 075.1 to clamav-80 using the rpm for FC2. after the upgrade, qmail-scanner ( 1.23 ) is not detecting clamav. I have recompiles qmail-scanner, ran qmail-scanner.pl -z and qmail-scanner.pl -g , with

Re: [Clamav-users] qmail-scanner-1.23 and clamav 0.80

2004-10-19 Thread Niek
On 10/19/2004 10:32 AM +0200, Kareem Mahgoub wrote: Hello list, I have upgraded from clamav 075.1 to clamav-80 using the rpm for FC2. after the upgrade, qmail-scanner ( 1.23 ) is not detecting clamav. I have recompiles qmail-scanner, ran qmail-scanner.pl -z and qmail-scanner.pl -g , with the same

Re: [Clamav-users] Problems after upgrading to 0.80

2004-10-19 Thread Tomasz Kojm
On Tue, 19 Oct 2004 09:42:23 +0200 Graham Dodd [EMAIL PROTECTED] wrote: So I made the leap from 0.75.1 to 0.80 and get the following error in exim log 2004-10-19 09:20:52 1CJoIe-0002Ut-E3 malware acl condition: clamd: unable to read from socket (No such file or directory) It's trying to

Re: [Clamav-users] qmail-scanner-1.23 and clamav 0.80

2004-10-19 Thread Kareem Mahgoub
Thanks for the quick help. I thought it is something in clamav not QS ( on a second thought, it should really go to QS mailing list ) my apology. For hitting reply on a previous thread, I thought it won't harm anybody, but it seems to be something bad. It will be my last time. Best Regards,

Re: [Clamav-users] qmail-scanner-1.23 and clamav 0.80

2004-10-19 Thread Tomasz Kojm
On Tue, 19 Oct 2004 12:39:44 +0200 Kareem Mahgoub [EMAIL PROTECTED] wrote: Thanks for the quick help. I thought it is something in clamav not QS ( on a second thought, it should really go to QS mailing list ) my apology. For hitting reply on a previous thread, I thought it won't harm

RE: [Clamav-users] Problems after upgrading to 0.80

2004-10-19 Thread Graham Dodd
[EMAIL PROTECTED] wrote: On Tue, 19 Oct 2004 09:42:23 +0200 Graham Dodd [EMAIL PROTECTED] wrote: So I made the leap from 0.75.1 to 0.80 and get the following error in exim log 2004-10-19 09:20:52 1CJoIe-0002Ut-E3 malware acl condition: clamd: unable to read from socket (No such file or

Re: [Clamav-users] Problems after upgrading to 0.80

2004-10-19 Thread Tomasz Kojm
On Tue, 19 Oct 2004 13:00:03 +0200 Graham Dodd [EMAIL PROTECTED] wrote: [EMAIL PROTECTED] wrote: On Tue, 19 Oct 2004 09:42:23 +0200 Graham Dodd [EMAIL PROTECTED] wrote: So I made the leap from 0.75.1 to 0.80 and get the following error in exim log 2004-10-19 09:20:52

Re: [Clamav-users] New version Clamd with Daemontools

2004-10-19 Thread Niek
On 10/19/2004 10:54 AM +0200, Awie wrote: All, I stuck to use clamd of version 0.80 with daemontools (I used this scheme very nicely for older version). Does anyone know how to do it? Thx Rgds, Awie I use daemontools to run clamd. I didn't change a thing when upgrading from 0.75.1 to

RE: [Clamav-users] Problems after upgrading to 0.80

2004-10-19 Thread Graham Dodd
[EMAIL PROTECTED] wrote: On Tue, 19 Oct 2004 13:00:03 +0200 Graham Dodd [EMAIL PROTECTED] wrote: [EMAIL PROTECTED] wrote: On Tue, 19 Oct 2004 09:42:23 +0200 Graham Dodd [EMAIL PROTECTED] wrote: So I made the leap from 0.75.1 to 0.80 and get the following error in exim log

Re: [Clamav-users] Problems after upgrading to 0.80

2004-10-19 Thread Tomasz Kojm
On Tue, 19 Oct 2004 13:23:21 +0200 Graham Dodd [EMAIL PROTECTED] wrote: Until 0.80 this worked Oh, I remember that issue. But this is due to an improvement in ClamAV and not a bug! -- oo. Tomasz Kojm [EMAIL PROTECTED] (\/)\.

Re: [Clamav-users] Problems after upgrading to 0.80

2004-10-19 Thread Frank Elsner
On Tue, 19 Oct 2004 13:23:21 +0200 Graham Dodd wrote: [ ... ] av_scanner = clamd:127.0.0.1 3310 That means your clamd listems for TCP connections on port 3310 And in check_data have the following: # Check for Virus/virii exiscan deny message = This message contains malware

Re: [Clamav-users] Freshclam DNS Warnings

2004-10-19 Thread Tomasz Kojm
On Tue, 19 Oct 2004 14:42:48 +1000 Bill Maidment [EMAIL PROTECTED] wrote: One of my servers is giving these warnings. What causes this and is it anything to worry about? freshclam daemon 0.80 (OS: linux-gnu, ARCH: i386, CPU: i686) ClamAV update process started at Tue Oct 19 14:39:06

Re: [Clamav-users] New version Clamd with Daemontools

2004-10-19 Thread Awie
I use daemontools to run clamd. I didn't change a thing when upgrading from 0.75.1 to 0.80rc-series, and 0.80 final. My run script and clamd.conf attached. Regards, Niek -- Hello Niek, I used your script and clamd.conf. The readproctitle said error in Library..bla.. bla... Then I

Re: [Clamav-users] Problems after upgrading to 0.80

2004-10-19 Thread Tomasz Kojm
On Tue, 19 Oct 2004 13:54:14 +0200 Graham Dodd [EMAIL PROTECTED] wrote: Well some people would say bug . :-) What happened to backward compatibility ? What do you call a backward incompatibility? The bug in exiscan? ;-) -- oo. Tomasz Kojm [EMAIL PROTECTED]

RE: [Clamav-users] Problems after upgrading to 0.80

2004-10-19 Thread Graham Dodd
[EMAIL PROTECTED] wrote: On Tue, 19 Oct 2004 13:23:21 +0200 Graham Dodd wrote: [ ... ] av_scanner = clamd:127.0.0.1 3310 That means your clamd listems for TCP connections on port 3310 And in check_data have the following: # Check for Virus/virii exiscan deny message = This

RE: [Clamav-users] Problems after upgrading to 0.80

2004-10-19 Thread Graham Dodd
[EMAIL PROTECTED] wrote: On Tue, 19 Oct 2004 13:54:14 +0200 Graham Dodd [EMAIL PROTECTED] wrote: Well some people would say bug . :-) What happened to backward compatibility ? What do you call a backward incompatibility? The bug in exiscan? ;-) I wonder what Tom would say :-)

Re: [Clamav-users] Problems after upgrading to 0.80

2004-10-19 Thread Tomasz Kojm
On Tue, 19 Oct 2004 14:01:13 +0200 Graham Dodd [EMAIL PROTECTED] wrote: Yep, and now that I've switched back to 0.75.1 it's running fine. I have no way to upgrade Exim from 4.24 to 4.43 as I inherited the system and it has custom patches to work with LDAP. Sounds like a laziness. Remember

Re: [Clamav-users] Problems after upgrading to 0.80

2004-10-19 Thread Tomasz Kojm
On Tue, 19 Oct 2004 14:06:44 +0200 Graham Dodd [EMAIL PROTECTED] wrote: Let's see. Exim 4.24 exiscan-acl patch rev. 12 ClamAV 0.75.1 - works Exim 4.24 exiscan-acl patch rev. 12 ClamAV 0.80 - doesn't work What changed ? Session handling has been improved in ClamAV and the old

Re: [Clamav-users] Problems after upgrading to 0.80

2004-10-19 Thread Fajar A. Nugraha
Graham Dodd wrote: I have no way to upgrade Exim from 4.24 to 4.43 as I inherited the system and it has custom patches to work with LDAP. Won't standard exim work with LDAP, assuming you set correct parameter during compile? I compiled one successfully, but I never did use the LDAP lookups for

[Clamav-users] 80 question: clamav.conf

2004-10-19 Thread alaslavic
Trying to upgrade to .80 on SuSE Linux PPC distro, from 0.75. It looks like /etc/clamav.conf in the .75 release, has been replaced by /etc/clamd.conf in the 80 release. Can anyone confirm, because this will effect my upgrade procedures. Alex Laslavic Havertys Tech Services

Re: [Clamav-users] 80 question: clamav.conf

2004-10-19 Thread Tomasz Kojm
On Tue, 19 Oct 2004 08:12:31 -0400 [EMAIL PROTECTED] wrote: Trying to upgrade to .80 on SuSE Linux PPC distro, from 0.75. It looks like /etc/clamav.conf in the .75 release, has been replaced by/etc/clamd.conf in the 80 release. Can anyone confirm, Confirmed. But next time please

Re: [Clamav-users] 80 question: clamav.conf

2004-10-19 Thread Frank Elsner
On Tue, 19 Oct 2004 08:12:31 EDT [EMAIL PROTECTED] wrote: Trying to upgrade to .80 on SuSE Linux PPC distro, from 0.75. It looks like /etc/clamav.conf in the .75 release, has been replaced by /etc/clamd.conf in the 80 release. Can anyone confirm, because this will effect my upgrade

RE: [Clamav-users] Problems after upgrading to 0.80

2004-10-19 Thread Graham Dodd
[EMAIL PROTECTED] wrote: Graham Dodd wrote: I have no way to upgrade Exim from 4.24 to 4.43 as I inherited the system and it has custom patches to work with LDAP. Won't standard exim work with LDAP, assuming you set correct If only I had a standard Exim, or the source and patches.

Re: [Clamav-users] can't compile clamav 0.80

2004-10-19 Thread Ken Jones
Hi I'v got next errors and warnings whe try configure clamav 0.80: configure: WARNING: resolv.h: present but cannot be compiled configure: WARNING: resolv.h: check for missing prerequisite headers? configure: WARNING: resolv.h: see the Autoconf documentation configure: WARNING:

[Clamav-users] Upgrade from 0.6 to 0.8 ? - clamd doesn't see viruses

2004-10-19 Thread Serge Leschinsky
Dear Sirs , I've seen quite strange behavior of new clamd: I try to send a message with virus: If old clamd 0.6 used: clamd.log Tue Oct 19 07:25:47 2004 - +++ Started at Tue Oct 19 07:25:47 2004 Tue Oct 19 07:25:47 2004 - Log file size limited to 1048576 bytes. Tue Oct 19 07:25:47 2004 -

Re: [Clamav-users] non detection problem

2004-10-19 Thread Jeff Smelser
On Tuesday 19 October 2004 01:34 am, Meni Shapiro wrote: Two or more scanners from different vendors are recommended in these days... OK, but the more is NOT the marrierthe more you got the more problems you have with interacting with the sendmail. Either find a better mailer, or

Re: [Clamav-users] non detection problem

2004-10-19 Thread Tomasz Kojm
On Tue, 19 Oct 2004 08:46:21 -0500 Jeff Smelser [EMAIL PROTECTED] wrote: I KNOW thatand i still work clamAV...I'm not looking for guarantees, just striving for perfection All I ment to say is that I learned of a problem (through the mailing list!!) and is it going to be fixed??

Re: [Clamav-users] non detection problem

2004-10-19 Thread Jeff Smelser
On Tuesday 19 October 2004 08:49 am, Tomasz Kojm wrote: Jeff Smelser [EMAIL PROTECTED] wrote: I KNOW thatand i still work clamAV...I'm not looking for guarantees, just striving for perfection All I ment to say is that I learned of a problem (through the mailing list!!) and is

Re: [Clamav-users] Problems after upgrading to 0.80

2004-10-19 Thread Brian Morrison
On Tue, 19 Oct 2004 14:32:08 +0200 in [EMAIL PROTECTED] Graham Dodd [EMAIL PROTECTED] wrote: Won't standard exim work with LDAP, assuming you set correct If only I had a standard Exim, or the source and patches. parameter during compile? I compiled one successfully, but I'd suggest

Re: [Clamav-users] qmail-scanner-1.23 and clamav 0.80

2004-10-19 Thread Jim Maul
Alex Pleiner wrote: * Kareem Mahgoub [EMAIL PROTECTED] [2004-10-19 10:32]: Hello list, I have upgraded from clamav 075.1 to clamav-80 using the rpm for FC2. after the upgrade, qmail-scanner ( 1.23 ) is not detecting clamav. I have recompiles qmail-scanner, ran qmail-scanner.pl -z and

Re: [Clamav-users] milter version

2004-10-19 Thread Nigel Horne
On Tuesday 19 Oct 2004 08:32, christian laubscher wrote: when i enter 'clamd -V' i get a version line reflecting the i get a version line indicating the current database version, eg .../535/..., currently. the clamav-milter X-Virus-Scanned lines, however, seem to reflect the version

[Clamav-users] What Just Happened??

2004-10-19 Thread Scott Ryan
I saw on my monitoring application just now that clamav was outdated and that i must update immediately. I was running 0.80rc3, and the moment I got this message i was inundated with users complaining that any jpeg attachment is flagged as a virus / comment 1. I upgraded to 0.80rc4 and the jpeg

Re: [Clamav-users] What Just Happened??

2004-10-19 Thread Trog
On Tue, 2004-10-19 at 15:07, Scott Ryan wrote: I saw on my monitoring application just now that clamav was outdated and that i must update immediately. I was running 0.80rc3, and the moment I got this message i was inundated with users complaining that any jpeg attachment is flagged as a

[Clamav-users] Exploit.JPEG.Comment.1

2004-10-19 Thread Scott Ryan
ClamAV databases updated (2004.10.19 12:59 +): daily.cvd version: 540 Submission: n/a Sender: Trog Updated: Exploit.JPEG.Comment.1 I dont know about anyone else, but this caused me huge issues... Flagged every jpeg attachment as a virus on 0.80rc3. Upgraded to 0.80rc4 and problem went away.

Re: [Clamav-users] What Just Happened??

2004-10-19 Thread Ken Jones
I saw on my monitoring application just now that clamav was outdated and that i must update immediately. I was running 0.80rc3, and the moment I got this message i was inundated with users complaining that any jpeg attachment is flagged as a virus / comment 1. I upgraded to 0.80rc4 and the

Re: [Clamav-users] Exploit.JPEG.Comment.1

2004-10-19 Thread Tomasz Kojm
On Tue, 19 Oct 2004 16:09:54 +0200 Scott Ryan [EMAIL PROTECTED] wrote: ClamAV databases updated (2004.10.19 12:59 +): daily.cvd version: 540 Submission: n/a Sender: Trog Updated: Exploit.JPEG.Comment.1 I dont know about anyone else, but this caused me huge issues... Flagged every

Re: [Clamav-users] What Just Happened??

2004-10-19 Thread Christopher X. Candreva
On Tue, 19 Oct 2004, Trog wrote: You should leave your cave more often :-) -trog . . This from someone calling himself trog ? :-) -Chris == Chris Candreva -- [EMAIL PROTECTED] -- (914) 967-7816 WestNet Internet Services of

Re: [Clamav-users] What Just Happened??

2004-10-19 Thread Trog
On Tue, 2004-10-19 at 15:49, Christopher X. Candreva wrote: On Tue, 19 Oct 2004, Trog wrote: You should leave your cave more often :-) . . This from someone calling himself trog ? :-) Ohh, the irony :-) -trog signature.asc Description: This is a digitally signed message part

[Clamav-users] ClamAV 0.80 and leave-temps

2004-10-19 Thread Pete D
Hello all. I just upgraded to the new ClamAV 0.80. I use the clamscan command along with the --leave-temps flag to generate the main.db and daily.db files. I am using a SMTP proxy spam program called ASSP that uses these db files for preliminary virus detection. The --leave-temps flag, which

[Clamav-users] clamdscan / results in ACCESS DENIED

2004-10-19 Thread Peter A Farago
I recently switched from Fedora Core 1 to Fedora Core 2. At the same time I upgraded to clamav 0.80. I have been using 'clamscan /' to scan my system in cron.daily. I am now running the clamd daemon and have changed from to 'clamscan /' to 'clamdscan /'. I am getting access denied messages

Re: [Clamav-users] ClamAV 0.80 and leave-temps

2004-10-19 Thread aCaB
On 10/19/04 17:26, Pete D wrote: Hello all. I just upgraded to the new ClamAV 0.80. I use the clamscan command along with the --leave-temps flag to generate the main.db and daily.db files. I am using a SMTP proxy spam program called ASSP that uses these db files for preliminary virus detection.

Re: [Clamav-users] What Just Happened??

2004-10-19 Thread Scott Ryan
On Tuesday 19 October 2004 16:34, Trog shaped the electrons to say: On Tue, 2004-10-19 at 15:07, Scott Ryan wrote: I saw on my monitoring application just now that clamav was outdated and that i must update immediately. I was running 0.80rc3, and the moment I got this message i was

Re: [Clamav-users] Exploit.JPEG.Comment.1

2004-10-19 Thread Scott Ryan
On Tuesday 19 October 2004 16:38, Tomasz Kojm shaped the electrons to say: On Tue, 19 Oct 2004 16:09:54 +0200 Scott Ryan [EMAIL PROTECTED] wrote: ClamAV databases updated (2004.10.19 12:59 +): daily.cvd version: 540 Submission: n/a Sender: Trog Updated: Exploit.JPEG.Comment.1

Re: [Clamav-users] ClamAV 0.80 and leave-temps

2004-10-19 Thread Pete D
Thanks for the great tip! The sigtool command works beautifully. However, it does make me wonder if there is a bug with the leave-temps flag. Thanks again. --- aCaB [EMAIL PROTECTED] wrote: On 10/19/04 17:26, Pete D wrote: Hello all. I just upgraded to the new ClamAV 0.80. I use the

Re: [Clamav-users] ClamAV 0.80 and leave-temps

2004-10-19 Thread Tomasz Kojm
On Tue, 19 Oct 2004 08:26:36 -0700 (PDT) Pete D [EMAIL PROTECTED] wrote: Hello all. I just upgraded to the new ClamAV 0.80. I use the clamscan command along with the --leave-temps flag to generate the main.db and daily.db files. I am using a SMTP proxy spam program called ASSP that uses

[Clamav-users] malware acl condition: clamd: connection to, 127.0.0.1, port 3310 failed (Bad file descriptor)

2004-10-19 Thread Graeme
Just upgraded my FreeBSD 4.10 to exim 4.43 exiscan patch 28 and clamav 0.80 using ports. I mow get the error malware acl condition: clamd: connection to, 127.0.0.1, port 3310 failed (Bad file descriptor) Any help would be appreciated Thanks Graeme

Re: [Clamav-users] malware acl condition: clamd: connection to, 127.0.0.1, port 3310 failed (Bad file descriptor)

2004-10-19 Thread Brian Morrison
On Tue, 19 Oct 2004 17:17:11 +0100 (BST) in [EMAIL PROTECTED] Graeme [EMAIL PROTECTED] wrote: malware acl condition: clamd: connection to, 127.0.0.1, port 3310 failed(Bad file descriptor) Can you post the av_scanner entry in your exim.conf file and the socket entries from clamd.conf. --

Re: [Clamav-users] ClamAV 0.80 and leave-temps

2004-10-19 Thread Pete D
Tomasz, I posted your response here to the ASSP forum. In the ASSP documentation, it mentions that ASSP lacks the ability to block all viruses (I guess that is what they mean by basic anti-virus filtering). I use ASSP in combination with a amavisd/clamd setup. Whatever ASSP doesn't catch, the

Re: [Clamav-users] clamdscan / results in ACCESS DENIED

2004-10-19 Thread Tomasz Papszun
On Tue, 19 Oct 2004 at 11:38:17 -0400, Peter A Farago wrote: I recently switched from Fedora Core 1 to Fedora Core 2. At the same time I upgraded to clamav 0.80. I have been using 'clamscan /' to scan my system in cron.daily. I am now running the clamd daemon and have changed from to

[Clamav-users] ClamAV 0.80 Compilation

2004-10-19 Thread Robin, Rob
All, Tried to upgrade to ClamAV 0.80 from 0.75.1. Failed to compile it. ~~~ ./configure --prefix=/usr/local/clamav/0.80 's warnings - configure: WARNING: resolv.h: present but cannot be compiled configure: WARNING: resolv.h: check for missing prerequisite headers? configure:

Re: [Clamav-users] ClamAV 0.80 Compilation

2004-10-19 Thread Thomas Lamy
Robin, Rob wrote: All, Tried to upgrade to ClamAV 0.80 from 0.75.1. Failed to compile it. ~~~ ./configure --prefix=/usr/local/clamav/0.80 's warnings - configure: WARNING: resolv.h: present but cannot be compiled configure: WARNING: resolv.h: check for missing prerequisite headers?

Re: [Clamav-users] malware acl condition: clamd: connection to, 127.0.0.1, port 3310 failed (Bad file descriptor)

2004-10-19 Thread Graeme
Odhiambo Washington said: * Graeme [EMAIL PROTECTED] [20041019 19:18]: wrote: Just upgraded my FreeBSD 4.10 to exim 4.43 exiscan patch 28 and clamav 0.80 using ports. I mow get the error malware acl condition: clamd: connection to, 127.0.0.1, port 3310 failed (Bad file descriptor) Any

Re: [Clamav-users] Zip AV Bypass Vulnerability

2004-10-19 Thread clamav
http://www.securiteam.com/securitynews/6E00G2ABFY.html Bit hard to say if this would impact ClamAV? Does clam skip the decompression if the local/global header contain a zero filesize? It sounds like from the article that those of use who Yes, it does. Unfortunately. The

Re: [Clamav-users] Upgrade from 75.1 to 80

2004-10-19 Thread Tomasz Kojm
On Tue, 19 Oct 2004 18:59:02 +0100 lnx [EMAIL PROTECTED] wrote: I have downloaded ver80 and now I'm not sure how to proceed. I've read the manual but I can't info on how to upgrade, is it best to remove the previous version or install over it.? The first option. -- oo.

Re: [Clamav-users] qmail-scanner-1.23 and clamav 0.80

2004-10-19 Thread clamav
I'm not sure what is more obnoxious. Top posting a short response ... On Tue, 19 Oct 2004, Tomasz Kojm wrote: On Tue, 19 Oct 2004 12:39:44 +0200 Kareem Mahgoub [EMAIL PROTECTED] wrote: Thanks for the quick help. I thought it is something in clamav not QS ( on a second thought, it

Re: [Clamav-users] qmail-scanner-1.23 and clamav 0.80

2004-10-19 Thread Tomasz Kojm
On Tue, 19 Oct 2004 11:47:33 -0700 (PDT) [EMAIL PROTECTED] wrote: I'm not sure what is more obnoxious. Top posting a short response ... On Tue, 19 Oct 2004, Tomasz Kojm wrote: On Tue, 19 Oct 2004 12:39:44 +0200 Kareem Mahgoub [EMAIL PROTECTED] wrote: Thanks for the quick help.

[Clamav-users] Re: pipechk: [kegger-daily:world-writable files (-222)]

2004-10-19 Thread clamav
Is there a reason that clamav comes with 777 modes in the tar? I would hate for someone to change something while I'm compiling, even though my parent directory is a bit more secure (700). Ideas? -- Eric Wheeler Vice President National Security Concepts, Inc. PO Box 3567 Tualatin, OR 97062

Re: [Clamav-users] Freshclam warning

2004-10-19 Thread Jeff Smelser
On Tuesday 19 October 2004 02:58 pm, Vernon A. Fort wrote: WARNING: DNS record is older than 3 hours. WARNING: Invalid DNS reply. This was just asked and answered.. Its telling something is suspicious with the dns update, so it is looking for updates the old way. Now pay attention next

Re: [Clamav-users] Freshclam warning

2004-10-19 Thread Tomasz Kojm
On Tue, 19 Oct 2004 14:58:56 -0500 Vernon A. Fort [EMAIL PROTECTED] wrote: I have been getting the following warning with freshclam for the last several hours. WARNING: DNS record is older than 3 hours. WARNING: Invalid DNS reply. All cvd files seem to be up-to-date but why am I getting

Re: [Clamav-users] Freshclam warning

2004-10-19 Thread Vernon A. Fort
Tomasz Kojm wrote: On Tue, 19 Oct 2004 14:58:56 -0500 "Vernon A. Fort" [EMAIL PROTECTED] wrote: I have been getting the following warning with freshclam for the last several hours. WARNING: DNS record is older than 3 hours. WARNING: Invalid DNS reply. All cvd files seem to be

Re: [Clamav-users] Freshclam warning

2004-10-19 Thread Todd Lyons
Tomasz Kojm wanted us to know: WARNING: DNS record is older than 3 hours. WARNING: Invalid DNS reply. Please read my today's post in this case. Could I suggest different verbage: WARNING: DNS record is older than 3 hours, falling back to HTTP GET. Would get rid of the questions of what does

Re: [Clamav-users] Freshclam warning

2004-10-19 Thread Jeff Smelser
On Tuesday 19 October 2004 04:29 pm, Todd Lyons wrote: Tomasz Kojm wanted us to know: WARNING: DNS record is older than 3 hours. WARNING: Invalid DNS reply. Please read my today's post in this case. Could I suggest different verbage: WARNING: DNS record is older than 3 hours, falling

[Clamav-users] Unable to open file or directory ERROR

2004-10-19 Thread Grant Supp
I'm using Clam AV 0.80 with Qmail-Scanner 1.23 and receive the following lines in my clamd.log: Tue Oct 19 15:22:34 2004 - /var/spool/qmailscan/tmp/newmail01.readyhosting.com109821735148216078/1098217354.16090-1.newmail01.readyhosting.com: Trojan.Dropper.JS.Zerolin-6 FOUND Tue Oct 19 15:30:44

[Clamav-users] OT - embedded message/rfc822 mimeparts in messages on this list

2004-10-19 Thread Daniel J McDonald
Am I the only one who sees several of the posters with embedded: Content-Type: message/rfc822 that includes embedded text/plain attachments. Evolution opens them up with only one extra step, but if I'm stuck with Outlook (or worse, OWA) you have to open three levels of attachments to read the

Re: [Clamav-users] OT - embedded message/rfc822 mimeparts in messages on this list

2004-10-19 Thread Stephen Gran
On Tue, Oct 19, 2004 at 05:20:38PM -0500, Daniel J McDonald said: Am I the only one who sees several of the posters with embedded: Content-Type: message/rfc822 that includes embedded text/plain attachments. Evolution opens them up with only one extra step, but if I'm stuck with Outlook

Re: [Clamav-users] OT - embedded message/rfc822 mimeparts in messages on this list

2004-10-19 Thread Damian Menscher
On Tue, 19 Oct 2004, Daniel J McDonald wrote: Am I the only one who sees several of the posters with embedded: Content-Type: message/rfc822 that includes embedded text/plain attachments. Evolution opens them up with only one extra step, but if I'm stuck with Outlook (or worse, OWA) you have to

Re: [Clamav-users] OT - embedded message/rfc822 mimeparts in messages on this list

2004-10-19 Thread Christopher X. Candreva
On Tue, 19 Oct 2004, Damian Menscher wrote: Yes, I'm seeing them, and they're annoying as hell. Most of them seem to be from Trog, thought the other poster that said they were forwarded messages broke his own claim, since his had the same issue. Ah -- could this be people who PGP-sign their

Re: [Clamav-users] OT - embedded message/rfc822 mimeparts in messages on this list

2004-10-19 Thread Todd Lyons
Christopher X. Candreva wanted us to know: Yes, I'm seeing them, and they're annoying as hell. Most of them seem to be from Trog, thought the other poster that said they were forwarded messages broke his own claim, since his had the same issue. Ah -- could this be people who PGP-sign their

Re: [Clamav-users] freshclam: Chunked Transfer Coding

2004-10-19 Thread shivaken
On Tuesday 19 October 2004 17:37, Jo Mills wrote: Hi, First let me apologize if this is way off the mark, but it has aroused my curiosity. When you say freshclam fails, do you get a return value of 1? I only ask because we have two Web Proxies in the office, one is a Novell box and the

Re: [Clamav-users] New version Clamd with Daemontools

2004-10-19 Thread Awie
All, When will the version of ClamAV 0.75-1 be expired? I hope it will be after I solve my problem of supervise clamd of new version. Thx Rgds, Awie - Original Message - From: Awie [EMAIL PROTECTED] To: ClamAV users ML [EMAIL PROTECTED] Sent: Tuesday, October 19, 2004 7:57 PM

Re: [Clamav-users] OT - embedded message/rfc822 mimeparts in messages on this list

2004-10-19 Thread Stephen Gran
On Tue, Oct 19, 2004 at 06:26:30PM -0700, Todd Lyons said: Christopher X. Candreva wanted us to know: Yes, I'm seeing them, and they're annoying as hell. Most of them seem to be from Trog, thought the other poster that said they were forwarded messages broke his own claim, since his had

Re: [Clamav-users] New version Clamd with Daemontools

2004-10-19 Thread Awie
Finally I can supervise new version of clamd. There are some parameter of clamav.conf that no need anymore in clamd.conf. After editing some lines, it works well. However, Qmail-scanner still has unrecognize command that I sure it should be OK. Wed, 20 Oct 2004 11:50:22 EDT:4600: run