On Mon, Aug 11, 2008 at 12:45:51PM +0400, Roman V. Isaev wrote: > > > > Your virus database was updated at 9 august 2008, and a lot of sites are > > > > recognised as virus threat. For example: ixbt.com, thg.ru, > > > > overclockers.ru. > > > > Virus is: > > > > Submission-ID: 4157162 > > > > Sender: Ricardo > > > > Added: Email.Trojan-8 > > > > I think that this is mistake. > > > > > > Yes!!! rambler.ru and utro.ru are blocked too. That's a huge problem, > > > we use > > > havp+clamav and my phone is ringing all the time, angry users complain > > > about > > > blocked sites, most of russian internet is blocked. How to remove this > > > "virus" > > > before everything is fixed? > > Have you checked HAVP configuration? > > Yes I did. I had to stop freshclam, unpack daily.cld with sigtool, > remove daily.cld and > remove this string: > > Email.Trojan-8:3:*:696d67207372633d22687474703a2f2f61642e616472697665722e72752f6367692d62696e > > After that everything works ok.
I gave you example HAVP config to stop it more easily: ----> IGNOREVIRUS Email. <---- There is not much point in searching "Email" viruses from web. Only marginal benefit is possibly catching something from peoples webmail. _______________________________________________ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml