[Clamav-users] For those using Procmail - a simple rule to hinder the Bagle-I virus

2004-03-02 Thread Support ePaxsys/FRWS
Maybe OT - but its a decent interim fix so people can continue sending large(r) Zips. SO - not sure if this is OT or what, but if you use procmail as the delivery agent on your system, this rule below will catch the ZIPs under 250k in size and having 'password:' somewhere in the body. Not

Re: [Clamav-users] For those using Procmail - a simple rule to hinder the Bagle-I virus

2004-03-02 Thread Support ePaxsys/FRWS
At 09:22 PM 3/2/04 +0100, Tomasz Papszun wrote: On Tue, 02 Mar 2004 at 11:18:25 -0700, Support ePaxsys/FRWS wrote: Maybe OT - but its a decent interim fix so people can continue sending large(r) Zips. SO - not sure if this is OT or what, but if you use procmail as the delivery agent on your

[Clamav-users] What exactly is the Worm.YoursID ?

2004-02-17 Thread Support ePaxsys/FRWS
What is the Worm.YoursID virus/worm? This is one virus/worm that has become active since last night. Any clue what it may be? Google searches, archived list searches and searches anywhere I can think of failed to find any record of the name. Is it just hitting this one instead of maybe Klez or

[Clamav-users] Digital Signatures warning

2003-11-11 Thread Support ePaxsys/FRWS
Greetings folks! Been reading my clam-update.log (since previous posts raised my curiousity) and noticed: SECURITY WARNING: NO SUPPORT FOR DIGITAL SIGNATURES A quick run through the docs, and a couple grep's on the source tree show nothing I should look for with the build. The ./configure

Re: [Clamav-users] Worm.Gibe.F

2003-09-19 Thread Support ePaxsys/FRWS
At 06:39 PM 9/19/03 -0400, Rick Macdougall wrote: Hi, Thomas Lamy wrote: when was the db updated for Worm.Gibe.F? I had it slip through 2 independant servers, one of them updates every hour... As far as I know, a couple of days ago. I'm not seeing anything get through here, running 0.60 here.

Re: [Clamav-users] clamav-milter, clamd, and high volume mail (SoBig.F)

2003-08-27 Thread Support ePaxsys/FRWS
Had/have the same problem. Switch to MailScanner from http://www.mailscanner.info until they can get that found and fixed. Seriously. We want to use the Milter also but cannot. JP At 11:23 AM 8/25/03 -0500, you wrote: I'm having a problem with clamd and clamav-milter. We just implemented a

[Clamav-users] Question about scanning viruses in bounces

2003-08-21 Thread Support ePaxsys/FRWS
Hey folks Love the ClamAV system - 25000+ Sobig.F viruses blocked across 6 servers in 3 days. *whew* But begs the question: As PostMaster of these servers we are blessed with bounces, re-mails and the like WITH the viruses in them in a lot of cases. I have most of these file types blocked by

Re: [Clamav-users] Signature for W32.Mimail.A@mm available?

2003-08-04 Thread Support ePaxsys/FRWS
I thought they updated late last week, our versions of the DB catch it as: Report: message.zip contains Trojan.Dropper.C And we have caught about 30 since late last night using ClamAV. Is there another version its not catching yet? Uh oh... JPP At 07:24 AM 8/4/03 -0700, you wrote: Hi,

Re: [clamav-users] Clamd with Clamav-Milter, Sendmail 8.12.9 timeout lockup?

2003-07-13 Thread Support ePaxsys/FRWS
Its something in the Milter for sure. I solved the problem using MailScanner (which someone suggested). But I do not like PERL scripts in the middle of the all the mail processes we spawn. Especially just for Virus Scanning. So I await a Milter that behaves well with ClamAV. The day will come!

Re: [clamav-users] Clamd with Clamav-Milter, Sendmail 8.12.9 timeout lockup?

2003-07-10 Thread Support ePaxsys/FRWS
Hi again To add to this thread. It seems to hang on quite a few (not all) Session TimeOuts and ALL 'WARNING: ScanStream: Size exceeded' events That may help. Jerome At 02:57 PM 7/10/03 -0600, you wrote: Hey all! Maybe someone here can help out with a curious problem. Its happening on at

[clamav-users] Clamd with Clamav-Milter, Sendmail 8.12.9 timeout lockup?

2003-07-10 Thread Support ePaxsys/FRWS
Hey all! Maybe someone here can help out with a curious problem. Its happening on at least 2 servers running RedHat 7.2 and 7.3 with patched Kernels... etc etc They are both running: Sendmail-8.12.9 OpenWebmail SASL for user auth And both have the latest and greatest Clamd and Clamav-Milter

[clamav-users] Sorry folks - ClamAV DOES catch W32.Sobig.E@mm just fine

2003-06-29 Thread Support ePaxsys/FRWS
False alarm. [EMAIL PROTECTED] is caught just fine. *goes back to checking installation* Regards Jerome the humbled ePaxsys, Inc. - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

[clamav-users] Catching W32.Sobig.E@mm ?

2003-06-29 Thread Support ePaxsys/FRWS
Good day Just installed Clamav and it appears to not catch [EMAIL PROTECTED] I caught it in my Antivirus/File blocking procmail filters, which is how I know it got through. The signature I use for this one is simple, I just look for: CSmtpMsgPart123X456_000 It shows as: