On Wed, 03 Mar 2004 at 12:36:56 -0500, Christopher X. Candreva wrote: > > Less than an hour after our users started getting a new virus pretending to > be from their mail administrator, Clam started picking it up as > Worm.Bagle.Gen-1 Congrats ! > > However, there seems to be a password protected zip version of virus too. > Since this is a new virus, does it come under the "don't submit any more > protected zips" edict ? >
1) Does ClamAV with fresh database detect a virus when scanning an original full email message? (by hand, not as mail in transfer) If "yes", then don't submit it. If "no", then submit it. 2) If ClamAV with fresh database does NOT detect a virus in _unzipped_ file, then submit it. -- Tomasz Papszun SysAdm @ TP S.A. Lodz, Poland | And it's only [EMAIL PROTECTED] http://www.lodz.tpsa.pl/ | ones and zeros. [EMAIL PROTECTED] http://www.ClamAV.net/ A GPL virus scanner ------------------------------------------------------- SF.Net is sponsored by: Speed Start Your Linux Apps Now. Build and deploy apps & Web services for Linux with a free DVD software kit from IBM. Click Now! http://ads.osdn.com/?ad_id=1356&alloc_id=3438&op=click _______________________________________________ Clamav-users mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/clamav-users