Re: [Clamav-users] Re: Curl-trouble on for clamav-0.88.7_1

2006-12-15 Thread Rob MacGregor
On 12/16/06, Mark <[EMAIL PROTECTED]> wrote: Which was my point: yesterday I grabbed and untarred the ENTIRE ports collection, and it only has curl-7.15.5. So, maybe curl-7.16.0 is only in cvs or something? The curl port (/usr/ports/ftp/curl) was updated to 7.16.0 about 3 days ago. It sounds

Re: [Clamav-users] Maybe Oversized.Zip bug in clamav 0.88.7

2006-12-15 Thread Simon Péter
Hi ks, > > On Friday December 15, 2006 at 07:31:52 (AM) Péter Simon wrote: > > > Simon Péter írta: > > > > Hi List, > > > > > > > > Yesterday I updated on my server from clamav 0.88.6 to clamav 0.88.7. > > > > In daytime ClamAV detected a lot of Oversized.Zip from our partners. > > > > It was a l

Re: [Clamav-users] Maybe Oversized.Zip bug in clamav 0.88.7

2006-12-15 Thread ks ks
Hi Peter, You are not the only one facing this problem. I am facing this problem eversince i upgraded to clamav 0.88.7 I did not face this problem in previous versions. But a search on the web shows references to this problem even in older versions. I even consulted a mailscanner expert and he fe

RE: [Clamav-users] Re: Curl-trouble on for clamav-0.88.7_1

2006-12-15 Thread Mark
> -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of > Chuck Swiger > Sent: vrijdag 15 december 2006 18:20 > To: ClamAV users ML > Subject: Re: [Clamav-users] Re: Curl-trouble on for clamav-0.88.7_1 > > > > Stop in /usr/ports/security/clamav. > > > > Pr

RE: [Clamav-users] Re: Newbie-inquiry

2006-12-15 Thread jean-paul natola
jean-paul natola wrote: > I'm running; > Freebsd 5.4 clamav 88.7 SA 3.1.7 > > In the paniclog /var/log/exim/paniclog is where I 'm seeing these entries > I did check the 'messages' log and there are no entries- > > It seems that clamav is timing out when it is attempting to scan large > mes

[Clamav-users] Re: Newbie-inquiry

2006-12-15 Thread René Berber
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 jean-paul natola wrote: >>> > How do I enable timestamping ? >>> >>> In /etc/clamd.conf, around line 34 : >>> >>> # Log time with each message. >>> # Default: no >>> LogTime yes >>> >> >> was not happy with that >> Starting clamav_clamd. >> ERROR: Par

RE: [Clamav-users] Re: Newbie-inquiry

2006-12-15 Thread jean-paul natola
> How do I enable timestamping ? In /etc/clamd.conf, around line 34 : # Log time with each message. # Default: no LogTime yes was not happy with that Starting clamav_clamd. ERROR: Parse error at line 34: Option LogTime doesn't support arguments (got 'yes'). ERROR: Can't open/parse the

RE: [Clamav-users] Re: Newbie-inquiry

2006-12-15 Thread jean-paul natola
> How do I enable timestamping ? In /etc/clamd.conf, around line 34 : # Log time with each message. # Default: no LogTime yes was not happy with that Starting clamav_clamd. ERROR: Parse error at line 34: Option LogTime doesn't support arguments (got 'yes'). ERROR: Can't open/parse the con

[Clamav-users] Re: Newbie-inquiry

2006-12-15 Thread René Berber
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 jean-paul natola wrote: > How do I enable timestamping ? In /etc/clamd.conf, around line 34 : # Log time with each message. # Default: no LogTime yes > and again it happened with the same type of message > > /var/spool/exim/scan/1GvHgK-000AQG-Eo/

RE: [Clamav-users] Re: Newbie-inquiry

2006-12-15 Thread jean-paul natola
jean-paul natola wrote: Saw your other message, you probably want to enable time stamping to correlate (with the exim log) what is going on. How do I enable timestamping ? and again it happened with the same type of message /var/spool/exim/scan/1GvHgK-000AQG-Eo/1GvHgK-000AQG-Eo.eml:

[Clamav-users] Re: Newbie-inquiry

2006-12-15 Thread René Berber
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 jean-paul natola wrote: > I'm running; > Freebsd 5.4 clamav 88.7 SA 3.1.7 > > In the paniclog /var/log/exim/paniclog is where I 'm seeing these entries > I did check the 'messages' log and there are no entries- > > It seems that clamav is timing out

Re: [Clamav-users] syntax error in Exploit.CVE_2006 signature?

2006-12-15 Thread Tomasz Kojm
On Fri, 15 Dec 2006 10:28:14 -0800 "Christian Chita" <[EMAIL PROTECTED]> wrote: > Hi all, > > As of this morning, I am seeing this particular signature: > > ===> > Exploit.CVE_2006_4182:1:EP+0:b800{-480}0100973068c202005a4ef > fff0100973068c202005a4e0100973068c202005a

[Clamav-users] syntax error in Exploit.CVE_2006 signature?

2006-12-15 Thread Christian Chita
Hi all, As of this morning, I am seeing this particular signature: ===> Exploit.CVE_2006_4182:1:EP+0:b800{-480}0100973068c202005a4ef fff0100973068c202005a4e0100973068c202005a4e01009 73068c202005a4e0100:0:9 <=== The ':0:9' at the end of the signatur

Re: [Clamav-users] Re: Newbie-inquiry

2006-12-15 Thread jean-paul natola
jean-paul natola wrote: Hi everyone, Hello. I'm having a bit of a problem with clamav on my server- I'm getting about 3 to 4 of these per hour- and I dont know why its happening "malware acl condition: clamd: unable to read from socket (Operation timed out)" and yes mail is still com

[Clamav-users] my clamav can't find killwin trojan from 2333

2006-12-15 Thread Maxim Britov
I want test submitted: 625524 Trojan.Killwin-3 but: # clamscan win_death.* win_death.exe: OK win_death.zip: OK --- SCAN SUMMARY --- Known viruses: 82841 Engine version: devel-20061215 Scanned directories: 0 Scanned files: 2 Infected files: 0 Data scanned: 1.25 MB Time: 7.491 sec

Re: [Clamav-users] Maybe Oversized.Zip bug in clamav 0.88.7

2006-12-15 Thread Simon Péter
Hi, 2006. december 15. 14.32 dátummal Gerard Seibert ezt írta: > On Friday December 15, 2006 at 07:31:52 (AM) Péter Simon wrote: > > Simon Péter írta: > > > Hi List, > > > > > > Yesterday I updated on my server from clamav 0.88.6 to clamav 0.88.7. > > > In daytime ClamAV detected a lot of Oversiz

RE: [Clamav-users] 0.88.7 possible error

2006-12-15 Thread Robert Isaac
> -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of > Dennis Peterson > Sent: 15 December 2006 00:52 > To: ClamAV users ML > Subject: Re: [Clamav-users] 0.88.7 possible error > > Robert Isaac wrote: > > > > > There was only one instance running. Kill

Re: [Clamav-users] Re: Curl-trouble on for clamav-0.88.7_1

2006-12-15 Thread Chuck Swiger
On Friday December 15, 2006 at 06:49:42 (AM) Mark wrote: I'm having trouble with curl on FreeBSD 4.11 and clamav-0.88.7_1: ===> Compressing manual pages for curl-7.15.5_1 ===> Running ldconfig /sbin/ldconfig -m /usr/local/lib ===> Registering installation for curl-7.15.5_1 readlink: not fo

RE: [Clamav-users] Re: Curl-trouble on for clamav-0.88.7_1

2006-12-15 Thread Mark
> -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of > Gerard Seibert > Sent: vrijdag 15 december 2006 14:38 > To: clamav-users@lists.clamav.net > Subject: [Clamav-users] Re: Curl-trouble on for clamav-0.88.7_1 > > On Friday December 15, 2006 at 06:49:42 (

Re: [Clamav-users] Re: Newbie-inquiry

2006-12-15 Thread jean-paul natola
jean-paul natola wrote: Hi everyone, Hello. I'm having a bit of a problem with clamav on my server- I'm getting about 3 to 4 of these per hour- and I dont know why its happening "malware acl condition: clamd: unable to read from socket (Operation timed out)" and yes mail is still comin

Re: [Clamav-users] Maybe Oversized.Zip bug in clamav 0.88.7

2006-12-15 Thread Gerard Seibert
On Friday December 15, 2006 at 07:31:52 (AM) Péter Simon wrote: > Simon Péter írta: > > Hi List, > > > > Yesterday I updated on my server from clamav 0.88.6 to clamav 0.88.7. In > > daytime ClamAV detected a lot of Oversized.Zip from our partners. It was a > > little bit starnge because they're

[Clamav-users] Re: Curl-trouble on for clamav-0.88.7_1

2006-12-15 Thread Gerard Seibert
On Friday December 15, 2006 at 06:49:42 (AM) Mark wrote: > I'm having trouble with curl on FreeBSD 4.11 and clamav-0.88.7_1: > > ===> Compressing manual pages for curl-7.15.5_1 > ===> Running ldconfig > /sbin/ldconfig -m /usr/local/lib > ===> Registering installation for curl-7.15.5_1 > rea

Re: [Clamav-users] Maybe Oversized.Zip bug in clamav 0.88.7

2006-12-15 Thread Péter Simon
Hi All, Simon Péter írta: Hi List, Yesterday I updated on my server from clamav 0.88.6 to clamav 0.88.7. In daytime ClamAV detected a lot of Oversized.Zip from our partners. It was a little bit starnge because they're sending mails as usually earlier. Ok. At first try I changed ArchiveMaxCo

RE: [Clamav-users] Re: Clamav-milter installation

2006-12-15 Thread Arthur Sherman
> > Right now there are 2 services -- clamav-milter & clamd -- on. > > If I turn clamd off, I get an error from freshclam regarding it. > > So run freshclam without the --daemon-notify command-line option and > with the NotifyClamd config file option disabled. Thanks, I'll give it a try today.

[Clamav-users] Curl-trouble on for clamav-0.88.7_1

2006-12-15 Thread Mark
Hello, I'm having trouble with curl on FreeBSD 4.11 and clamav-0.88.7_1: ===> Compressing manual pages for curl-7.15.5_1 ===> Running ldconfig /sbin/ldconfig -m /usr/local/lib ===> Registering installation for curl-7.15.5_1 readlink: not found ===> Returning to build of clamav-0.88.7_1 Er

[Clamav-users] Re: Clamav-milter installation

2006-12-15 Thread Ian Abbott
On 14/12/2006 16:10, Arthur Sherman wrote: Right now there are 2 services -- clamav-milter & clamd -- on. If I turn clamd off, I get an error from freshclam regarding it. So run freshclam without the --daemon-notify command-line option and with the NotifyClamd config file option disabled. --