> -----Original Message-----
> From: clamav-users-boun...@lists.clamav.net [mailto:clamav-users-
> boun...@lists.clamav.net] On Behalf Of Jari Fredriksson
> Sent: Wednesday, September 23, 2009 9:14 AM
> To: ClamAV Users
> Subject: [Clamav-users] DHL invoices
> 
> 
> I get lots of 'invoices' from DHL containing a zipped trojan. F-Prot
> recognizes them as Win32/Bredolab!Generic but ClamAV does not.
> 
> I tried to post one to ClamAV site, but it was said to be recognized
> already.
> 

Have you tried using a site like virustotal to see if _their_ version of
ClamAV detects it?  I've run into problems before where the glue between
e-mail and clam caused detection to fail.  I've also seen an instance where
clamav-milter failed detection but clamscan did not.  I now have both
clamav-milter and my glue run separate scans and haven't seen the problem
since.


Jason A. Bertoch
Network Administrator
ja...@electronet.net
Electronet Broadband Communications
3411 Capital Medical Blvd.
Tallahassee, FL 32308
(V) 850.222.0229 (F) 850.222.8771


_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml

Reply via email to