Hi All I'm having a problem with the new Sober.P/O/Q whatever. I'm running mostly Exim 4.43 and clamd 0.84.
Clamd starting up with my options: Wed May 4 09:57:56 2005 -> clamd daemon 0.84 (OS: freebsd4.8, ARCH: i386, CPU: i386) Wed May 4 09:57:56 2005 -> Log file size limited to 10485760 bytes. Wed May 4 09:57:56 2005 -> Verbose logging activated. Wed May 4 09:57:56 2005 -> Running as user exim (UID 1001, GID 1001) Wed May 4 09:57:56 2005 -> Reading databases from /usr/local/share/clamav Wed May 4 09:57:57 2005 -> Protecting against 30801 viruses. Wed May 4 09:57:57 2005 -> Unix socket file /var/run/clamav/clamd Wed May 4 09:57:57 2005 -> Setting connection queue length to 15 Wed May 4 09:57:57 2005 -> Listening daemon: PID: 7488 Wed May 4 09:57:57 2005 -> Archive: Archived file size limit set to 10485760 bytes. Wed May 4 09:57:57 2005 -> Archive: Recursion level limit set to 8. Wed May 4 09:57:57 2005 -> Archive: Files limit set to 1000. Wed May 4 09:57:57 2005 -> Archive: Compression ratio limit set to 250. Wed May 4 09:57:57 2005 -> Archive support enabled. Wed May 4 09:57:57 2005 -> Archive: RAR support disabled. Wed May 4 09:57:57 2005 -> Portable Executable support enabled. Wed May 4 09:57:57 2005 -> Detection of broken executables enabled. Wed May 4 09:57:57 2005 -> Mail files support enabled. Wed May 4 09:57:57 2005 -> OLE2 support enabled. Wed May 4 09:57:57 2005 -> HTML support enabled. Wed May 4 09:57:57 2005 -> Self checking every 1800 seconds. Does not collect any Sober.P at all! But does see Worm.Mydoom.J and others. Now if I run clamscan on the email spools : Worm.Sober.P FOUND Worm.Sober.P FOUND Worm.Sober.P FOUND ... .. . ----------- SCAN SUMMARY ----------- Known viruses: 34149 Engine version: 0.84 Scanned directories: 860 Scanned files: 96660 Infected files: 268 Any Ideas ? Thanks David Peall :: Systems Administrator e-Schools' Network :: http://www.esn.org.za/ Phone +27 (021) 674-9140 _______________________________________________ http://lurker.clamav.net/list/clamav-users.html