[Clamav-users] Submit form treating samples as false positives

2010-03-09 Thread rafa
Hi, When submitting samples they are treated as false positives. Result: This file is not detected by ClamAV. Please update your CVD database before reporting false-positives. If you are using third-party databases/unofficial signatures, please contact the author of the signature. We can

Re: [Clamav-users] Finding html and related files infected with Gumblar

2009-07-21 Thread rafa
Peter M. Abraham wrote: Greetings Edwin: I just created a HTML file with an infection on purpose to test. clamscan -i -r test.html found no infections. Here's what I put in the test file: Bitdefender detects it as Trojan.Script.177381 ___ Help us

Re: [Clamav-users] Suggestion

2009-04-17 Thread rafa
Tom Shaw wrote: Currently, I am tracking 233 files containing malware that have been submitted both directly to clamav.net and virustotal.com and yet continue not to show up in the signature database so that they can be detected. My scripts check them frequently against the current clamav

[Clamav-users] Submission tracking request

2009-02-25 Thread rafa
Can the Submission-ID be shown when you submit a sample via web. It would make life a bit easier to track which of your submitted samples are added to the db. Best regards, rafael. ___ Help us build a comprehensive ClamAV guide: visit

Re: [Clamav-users] problems with virus submission

2009-02-23 Thread rafa
Brandon Perry wrote: Hundreds of submissions aer made every day. I would probably wait a week after submitting before worrying about it. If it is a severe problem, as in your are getting tons of emails a day infected with the trojan, I would hop on IRC or email a dev about it and see what they

Re: [Clamav-users] WARNING: DNS record is older than 3 hours. (freshclam.log)

2009-02-09 Thread rafa
John Horne wrote: I have been getting the occasional same warning. From one server today: me too. -- Received signal: wake up Max retries == 5 ClamAV update process started at Mon Feb 9 12:56:49 2009 Using IPv6 aware code Querying current.cvd.clamav.net TTL:

Re: [Clamav-users] Using clamav on internet gateway

2009-02-06 Thread rafa
Sunny K wrote: Hi, Is there any way to use clamav on an internet gateway (linux based) to protect connected hosts from virus/malicious content? (Internet)-| Internet Gateway (linux on x86) | Host-1 | | Host-2 Thanks, Sam You can

Re: [Clamav-users] simplest replacement for ancient amavis-perl

2008-08-07 Thread rafa
jef moskot wrote: On Thu, 7 Aug 2008, Henrik K wrote: I use both, but MD is IMO more of a hobbyist tool... I didn't mean to spark a milter fight, but as the Subject line says, we're looking for the simplest thing out there. I'm replacing a simplistic perl script that just broke a message

Re: [Clamav-users] Description Trojan.VB-2953

2008-06-06 Thread rafa
Robert Schetterer wrote: Dennis Peterson schrieb: Robert Schetterer wrote: Ian Eiloart schrieb: --On 6 June 2008 11:03:22 +0200 Robert Schetterer [EMAIL PROTECTED] wrote: Robert Schetterer schrieb: Hi @ll, where kann i find a description about Trojan.VB-2953 sorry i slipped into

Re: [Clamav-users] Missed Virus

2007-08-08 Thread rafa
Jason Bennett wrote: Hi everyone, We're using ClamAV on our mail gateway which is in front of our exchange server. It's been running great for a long time and stops thousands of virus per day for us. Lately however our McAfee which is installed on exchange itself is picking up this

Re: [Clamav-users] Greeting Card virus

2007-07-20 Thread rafa
Jeff Thurston wrote: I'm using the sanesecurity and MSRBL files too and are getting the same spam. I'll start sending them to Steve to incorporate. James. ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net

Re: [Clamav-users] clam newbie

2004-08-17 Thread rafa
Kern, Tom wrote: Hi, i just installed clamav 0.75 on a redhat ES3 with amavis new. I was wondering, when i look into the clamd.log, all i see is worm.somefool.p. I know i'm getting more virii than that as my symantec corporate edition is catching netsky and beagle and other varients. i ran