On Mon, Aug 11, 2008 at 04:04:00PM +0400, Roman V. Isaev wrote: > > > I gave you example HAVP config to stop it more easily: > > ----> > > IGNOREVIRUS Email. > > <---- > > Yes, thanks, but I saw your letter after I alredy implemented my own > "solution" :) I just don't want to fiddle with clamd any more until 18:00 > (end of the workday). IGNOREVIRUS is a good solution. > > > There is not much point in searching "Email" viruses from web. Only marginal > > benefit is possibly catching something from peoples webmail. > > According to my squid logs about 40% of my office users visit various > webmail systems (and that's a lot) on regular basis. I'll block exactly the > culprit.
Unfortunately less than 5% of Email.* signatures match anything else than a real mail (mbox) file. So there is a pretty slim chance of even catching anything from webmails. But if it makes you happy, who am I to tell otherwise. :) _______________________________________________ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml