Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jari Fredriksson
> I am a tad confused about your reporting comment as the > clamav web reporting mechanism works fine at least for me > and you can also > report via virustotal as well. > > Anyway glad your happy with your config. > > Tom > > btw its winnow as in to remove the wheat from the chaff > and has >

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jari Fredriksson
> Jari Fredriksson wrote: > >> I give rat's ass to WinNow. If I would have been >> interested in SaneSecurity or WinNow I would have >> installed those again, and tested with them. >> > > Don't let it fall through the cracks that people here are > trying to help you. > Of course, just like I

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Tom Shaw
At 12:20 AM +0300 9/24/09, Jari Fredriksson wrote: >> This is what I found about Phishing and Heuristics. Dangerous? When I review the quaratine anyway. No more than sanesecurity rules and alot more than my winnow_malware.hdb which would have caught your virus. Point being you might jus

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Dennis Peterson
Jari Fredriksson wrote: I give rat's ass to WinNow. If I would have been interested in SaneSecurity or WinNow I would have installed those again, and tested with them. Don't let it fall through the cracks that people here are trying to help you. dp ___

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jari Fredriksson
>> >> This is what I found about Phishing and Heuristics. >> Dangerous? When I review the quaratine anyway. > > No more than sanesecurity rules and alot more than my > winnow_malware.hdb which would have caught your virus. > > Point being you might just want to consider what you have > running..

Re: [Clamav-users] Duplicate Clamd Processes

2009-09-23 Thread Bernd Petrovitsch
Hi mailinglist, On Mit, 2009-09-23 at 11:44 -0500, Dan Denton wrote: [...] > I've got an RHEL 3 server (yes, I know...) running clamd on generic > hardware. When I start clamd, it appears two processes are created. > None of my other systems do this (RHEL 4 and 5 systems). I didn't > notice this h

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Tom Shaw
At 11:31 PM +0300 9/23/09, Jari Fredriksson wrote: > At 10:39 PM +0300 9/23/09, Jari Fredriksson wrote: >> I don't run ClamAV via SpamAssassin. I have it called by amavisd-new, which does what it does: quarantine. Sure hope your not using heuristics, phishing and/or safebrowsing op

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jari Fredriksson
> At 10:39 PM +0300 9/23/09, Jari Fredriksson wrote: >> >> I don't run ClamAV via SpamAssassin. I have it called by amavisd-new, which does what it does: quarantine. >>> >>> Sure hope your not using heuristics, phishing and/or >>> safebrowsing options in ClamAV if you feel that way.

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Tom Shaw
At 10:42 PM +0300 9/23/09, Jari Fredriksson wrote: > On Wed, Sep 23, 2009 at 08:11:41PM +0300, Jari Fredriksson wrote: Ehm, were you scoring SaneSecurity hits like one is supposed to, or just plain rejecting with them? Sounds like the latter. I don't run ClamAV via SpamAssassin. I hav

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Tom Shaw
At 10:39 PM +0300 9/23/09, Jari Fredriksson wrote: >> I don't run ClamAV via SpamAssassin. I have it called by amavisd-new, which does what it does: quarantine. Sure hope your not using heuristics, phishing and/or safebrowsing options in ClamAV if you feel that way. I use amavisd-new d

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jari Fredriksson
> On Wed, Sep 23, 2009 at 08:11:41PM +0300, Jari > Fredriksson wrote: >>> >>> Ehm, were you scoring SaneSecurity hits like one is >>> supposed to, or just plain rejecting with them? Sounds >>> like the latter. >>> >> >> I don't run ClamAV via SpamAssassin. I have it called by >> amavisd-new, wh

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jari Fredriksson
>> >> I don't run ClamAV via SpamAssassin. I have it called by >> amavisd-new, which does what it does: quarantine. > > Sure hope your not using heuristics, phishing and/or > safebrowsing options in ClamAV if you feel that way. > I use amavisd-new default options, have not touched those. Anywa

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jose-Marcio Martins da Cruz
Jari Fredriksson wrote: I have not tried virustotal. I have the zip file and the extracted exe as well on disk, and clamscan does NOT detect it. I have F-Prot and BitDefender in my amavisd-new as well, and I have no problems detecting these. The point in this post is that ClamAV website

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Tom Shaw
At 8:11 PM +0300 9/23/09, Jari Fredriksson wrote: > On Wed, Sep 23, 2009 at 07:07:53PM +0300, Jari Fredriksson wrote: Jari Fredriksson wrote: Then I decided SaneSecurity is not worth it, as SpamAssassin catches those too, and has less false positives. SaneSecurity triggers way too of

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Henrik K
On Wed, Sep 23, 2009 at 08:11:41PM +0300, Jari Fredriksson wrote: > > > > Ehm, were you scoring SaneSecurity hits like one is > > supposed to, or just plain rejecting with them? Sounds > > like the latter. > > > > I don't run ClamAV via SpamAssassin. I have it called by amavisd-new, > which doe

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jari Fredriksson
> On Wed, Sep 23, 2009 at 07:07:53PM +0300, Jari > Fredriksson wrote: >>> Jari Fredriksson wrote: >>> Then I decided SaneSecurity is not worth it, as SpamAssassin catches those too, and has less false positives. SaneSecurity triggers way too often when some dumb us

[Clamav-users] Duplicate Clamd Processes

2009-09-23 Thread Dan Denton
Hello forum. I've got an RHEL 3 server (yes, I know...) running clamd on generic hardware. When I start clamd, it appears two processes are created. None of my other systems do this (RHEL 4 and 5 systems). I didn't notice this happening until a couple days ago when nagios started alerting low m

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Henrik K
On Wed, Sep 23, 2009 at 07:07:53PM +0300, Jari Fredriksson wrote: > > Jari Fredriksson wrote: > > > >> > >> Then I decided SaneSecurity is not worth it, as > >> SpamAssassin catches those too, and has less false > >> positives. > >> > >> SaneSecurity triggers way too often when some dumb user >

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jari Fredriksson
> Jari Fredriksson wrote: > >> >> Then I decided SaneSecurity is not worth it, as >> SpamAssassin catches those too, and has less false >> positives. >> >> SaneSecurity triggers way too often when some dumb user >> pastes a spam into his mail, or some robot sends a >> bounce with an attachment.

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Dennis Peterson
Jari Fredriksson wrote: Then I decided SaneSecurity is not worth it, as SpamAssassin catches those too, and has less false positives. SaneSecurity triggers way too often when some dumb user pastes a spam into his mail, or some robot sends a bounce with an attachment. I do not want to report th

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jari Fredriksson
>> I get lots of 'invoices' from DHL containing a zipped >> trojan. F-Prot recognizes them as Win32/Bredolab!Generic >> but ClamAV does not. > > Hi, > > Just in case this helps block them... I've been detecting > these for a while if its the same sort of fake invoices > I've been receiving here,

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jari Fredriksson
>> -Original Message- >> From: clamav-users-boun...@lists.clamav.net >> [mailto:clamav-users- boun...@lists.clamav.net] On >> Behalf Of Jari Fredriksson >> Sent: Wednesday, September 23, 2009 9:14 AM >> To: ClamAV Users >> Subject: [Clamav-users] DHL invoices >> >> >> I get lots of 'invo

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Tom Shaw
At 3:09 PM +0100 9/23/09, Steve Basford wrote: > I get lots of 'invoices' from DHL containing a zipped trojan. F-Prot recognizes them as Win32/Bredolab!Generic but ClamAV does not. Hi, Just in case this helps block them... I've been detecting these for a while if its the same sort of fake

[Clamav-users] false positives

2009-09-23 Thread Frédéric SOSSON
Hello, I would like to test my virus protection behavior by using false positives in clamav-0.95.2.tar.gz/test/.split McAfee found viruses but ClamAV did not (by using clamscan) what could be wrong ? regards, Fred ___ Help us build a comprehensive C

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Steve Basford
> > I get lots of 'invoices' from DHL containing a zipped trojan. F-Prot > recognizes them as Win32/Bredolab!Generic but ClamAV does not. Hi, Just in case this helps block them... I've been detecting these for a while if its the same sort of fake invoices I've been receiving here, using the Sanes

Re: [Clamav-users] DHL invoices

2009-09-23 Thread Jason Bertoch
> -Original Message- > From: clamav-users-boun...@lists.clamav.net [mailto:clamav-users- > boun...@lists.clamav.net] On Behalf Of Jari Fredriksson > Sent: Wednesday, September 23, 2009 9:14 AM > To: ClamAV Users > Subject: [Clamav-users] DHL invoices > > > I get lots of 'invoices' from DH

[Clamav-users] DHL invoices

2009-09-23 Thread Jari Fredriksson
I get lots of 'invoices' from DHL containing a zipped trojan. F-Prot recognizes them as Win32/Bredolab!Generic but ClamAV does not. I tried to post one to ClamAV site, but it was said to be recognized already. I have ClamAV 0.95.2/9826/Wed Sep 23 14:06:01 2009 main.cvd is up to date

Re: [Clamav-users] local mirror

2009-09-23 Thread Frédéric SOSSON
thanx it works well now 2009/9/23 Török Edwin : > On 2009-09-23 12:14, Frédéric SOSSON wrote: >> yes but I do not understand why I get daily.cld instead of daily.cvd >> > > Freshclam converts a daily.cvd to a daily.cld when it downloads updates > if you have ScriptedUpdates turned On. > See the FA

Re: [Clamav-users] local mirror

2009-09-23 Thread Török Edwin
On 2009-09-23 12:14, Frédéric SOSSON wrote: > yes but I do not understand why I get daily.cld instead of daily.cvd > Freshclam converts a daily.cvd to a daily.cld when it downloads updates if you have ScriptedUpdates turned On. See the FAQ. Best regards, --Edwin __

Re: [Clamav-users] local mirror

2009-09-23 Thread Frédéric SOSSON
yes but I do not understand why I get daily.cld instead of daily.cvd 2009/9/23 Török Edwin : > On 2009-09-23 10:35, Frédéric SOSSON wrote: >> Hello, >> >> I've made a local mirror using Apache.  I can download daily.cld and >> main.cvd via wget or linx but freshclam on client displays : >> > > Tha

Re: [Clamav-users] local mirror

2009-09-23 Thread Török Edwin
On 2009-09-23 10:35, Frédéric SOSSON wrote: > Hello, > > I've made a local mirror using Apache. I can download daily.cld and > main.cvd via wget or linx but freshclam on client displays : > Thats the problem, you should have a daily.cvd, not a daily.cld. Best regards, --Edwin

[Clamav-users] local mirror

2009-09-23 Thread Frédéric SOSSON
Hello, I've made a local mirror using Apache. I can download daily.cld and main.cvd via wget or linx but freshclam on client displays : Wed Sep 23 09:23:41 2009 -> WARNING: Can't read main.cvd header from mymachine.mydomain (IP: ) Wed Sep 23 09:23:41 2009 -> Trying again in 5 secs... Wed Sep 23