Re: [Clamav-users] Perl script for sorting logs entries

2004-08-31 Thread Brett Simpson
On Mon, 2004-08-30 at 18:33, Internet Helpdesk wrote: For example: ./source_virus_count.pl -l amavis -f amavis/amavis.log -r -c 10 For this to work for milter, what logging to I need to have? Do I enable verbose logging in clamav.conf? Right now In my log I have: Mon Aug 2

[Clamav-users] Perl script for sorting logs entries - version 0.20

2004-08-31 Thread Brett Simpson
I have corrected a few bugs, added smtp support, and added a minimum virus count. For smtp support you will need to define your smtp server and email address in perl script. You will also need LogSyslog enabled in your clamav.conf for Milter logging. Options: -h Help -f Log file -l Log type -

[Clamav-users] Trojan.Baglet?

2004-08-31 Thread henry j. mason
greetings all; i'm having a lot of grief with some very persistent worm infections, many of which are not detected by our Symantec NAV Corporate edition (with up to the minute definitions). i keep submitting files to Symantec, and they keep sending

[Clamav-users] Can I submit a file if I'm not sure it's a virus?

2004-08-31 Thread D.J. Fan
I just received 3 emails with a subject of 'foto' or 'fotos' and a zip attachment named 'foto.zip' with 'calc.exe' and 'foto.htm' contained therein that passed through 3 different scanners undetected. I don't want to infect my own machine by opening it. Can I forward it to someone to check it out?

[Clamav-users] Messages that got through clam

2004-08-31 Thread Philip Ershler
I am running clam in series with RAV on CommuniGate Pro via cgpav. The messages go through clam first and if clam says OK then they go through RAV. Today RAV caught 4 messages that clam thought were OK. The following lines are from the RAV log. Should I provide the original messages to the

[Clamav-users] [OT] Symantec update frequency

2004-08-31 Thread Niek
On 8/31/2004 11:02 PM +0200, John Jolet wrote: I don't believe Symantec updates their definitions more than once a week. Certainly not for us poor home users. you can update all you want, but the file won't change. The following are my experiences with new defs from Symantec: Liveupdate: 1-2

Re: [Clamav-users] List Down

2004-08-31 Thread [EMAIL PROTECTED]
Daniel J McDonald said: On Tue, 2004-08-31 at 13:17, Chris Jett wrote: Is the list down? I haven't gotten any list messages since this morning... No, merely slow. It only took 4 hours to be delivered to me. What do you want? Back in the bad old days we only got mail once a month, over a

Re: [Clamav-users] OS X Installer and Permissions

2004-08-31 Thread The Count of CipherSpace
Chris Jett at 2004-08-31 13:39 from [EMAIL PROTECTED] wrote: I am working on a double-click installer for Mac OS X. Everything seems to be working OK and I am able to start clamd just fine and scan files just fine. The only problem I am seeing is when trying to use freshclam. Here is the

Re: [Clamav-users] Can I submit a file if I'm not sure it's a virus?

2004-08-31 Thread List
I just received 3 emails with a subject of 'foto' or 'fotos' and a zip attachment named 'foto.zip' with 'calc.exe' and 'foto.htm' contained therein that passed through 3 different scanners undetected. I don't want to infect my own machine by opening it. Can I forward it to someone to

Re: [Clamav-users] Can I submit a file if I'm not sure it's a virus?

2004-08-31 Thread Niek
On 9/1/2004 1:49 AM +0200, D.J. Fan wrote: I just received 3 emails with a subject of 'foto' or 'fotos' and a zip attachment named 'foto.zip' with 'calc.exe' and 'foto.htm' contained therein that passed through 3 different scanners undetected. I don't want to infect my own machine by opening it.

Re: [Clamav-users] Can I submit a file if I'm not sure it's a virus?

2004-08-31 Thread [EMAIL PROTECTED]
D.J. Fan said: I just received 3 emails with a subject of 'foto' or 'fotos' and a zip attachment named 'foto.zip' with 'calc.exe' and 'foto.htm' contained therein that passed through 3 different scanners undetected. I don't want to infect my own machine by opening it. Can I forward it to

Re: [Clamav-users] Messages that got through clam

2004-08-31 Thread Niek
On 9/1/2004 1:52 AM +0200, Philip Ershler wrote: I am running clam in series with RAV on CommuniGate Pro via cgpav. The messages go through clam first and if clam says OK then they go through RAV. Today RAV caught 4 messages that clam thought were OK. The following lines are from the RAV log.

Re: [Clamav-users] List Down

2004-08-31 Thread Mike Nolan
1200 baud? Slow down, sonny! It wasn't that long ago that I was working at 50 baud with 5 bit code. Then some smart-aleck invented the lower case alphabet and we move to a blazing 56.8 baud and added a bit for the shift character. If you weren't able to whistle a connect tone for a 50 baud

Re: [Clamav-users] Can I submit a file if I'm not sure it's a virus?

2004-08-31 Thread James Lick
D.J. Fan wrote: I just received 3 emails with a subject of 'foto' or 'fotos' and a zip attachment named 'foto.zip' with 'calc.exe' and 'foto.htm' contained therein that passed through 3 different scanners undetected. This is Trojan.Dropper.Small-11 added in ClamAV update 475 just in the last

Re: [Clamav-users] Messages that got through clam

2004-08-31 Thread Philip Ershler
On Aug 31, 2004, at 8:02 PM, Niek wrote: On 9/1/2004 1:52 AM +0200, Philip Ershler wrote: I am running clam in series with RAV on CommuniGate Pro via cgpav. The messages go through clam first and if clam says OK then they go through RAV. Today RAV caught 4 messages that clam thought were OK.