> > I get lots of 'invoices' from DHL containing a zipped trojan. F-Prot > recognizes them as Win32/Bredolab!Generic but ClamAV does not.
Hi, Just in case this helps block them... I've been detecting these for a while if its the same sort of fake invoices I've been receiving here, using the Sanesecurity signatures: http://sanesecurity.co.uk/download_scripts_linux.htm Cheers, Steve Sanesecurity _______________________________________________ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml