[Clamav-users] Re: Queries on Clam AV

2003-08-16 Thread Darren Keech
Thanks for the help guys, I will have another read through the documentation but I must have missed the part about cron jobs as I didn't think there was anything there that would have been able to help me. Thanks again. Cheers Darren --- Thi

Re: [Clamav-users] FOO.EXE

2003-08-16 Thread Antony Stone
On Saturday 16 August 2003 8:26 pm, Kevin Spicer wrote: > > sigtool -c "clamscan --stdout" -f message.zip -s "message" > > Someone correct me if I'm wrong but I'm pretty sure you can't use > sigtool to extract the virus signature from a zip (no matter what > scanner you use). The zip itself is no

Re: [Clamav-users] FOO.EXE

2003-08-16 Thread Tomasz Kojm
On 16 Aug 2003 20:26:44 +0100 Kevin Spicer <[EMAIL PROTECTED]> wrote: > > sigtool -c "clamscan --stdout" -f message.zip -s "message" > > Someone correct me if I'm wrong but I'm pretty sure you can't use > sigtool to extract the virus signature from a zip (no matter what You're completely right.

Re: [Clamav-users] FOO.EXE

2003-08-16 Thread Kevin Spicer
> sigtool -c "clamscan --stdout" -f message.zip -s "message" Someone correct me if I'm wrong but I'm pretty sure you can't use sigtool to extract the virus signature from a zip (no matter what scanner you use). The zip itself is not infected, you need to unzip the file and extract the signature f

Re: [Clamav-users] FOO.EXE

2003-08-16 Thread Tomasz Kojm
On 16 Aug 2003 07:57:50 -0800 "W.D. McKinney" <[EMAIL PROTECTED]> wrote: > sigtool -c "clamscan --stdout" -f message.zip -s "message" > Not detected at 5, moving backward. > Not detected at 1, moving backward. > Not detected at 0, moving backward. > Not detected at 0, moving backward. > Starting

Re: [Clamav-users] FOO.EXE

2003-08-16 Thread Antony Stone
On Saturday 16 August 2003 5:58 pm, W.D. McKinney wrote: > Hi, > > One of our customers we host e-mail sent it to me from down in AU and it > was from [EMAIL PROTECTED] as it made it to her from our > server.(Like you said :-) When was the message sent (or, more accurately, when was it received &

Re: [Clamav-users] FOO.EXE

2003-08-16 Thread W.D. McKinney
Hi, One of our customers we host e-mail sent it to me from down in AU and it was from [EMAIL PROTECTED] as it made it to her from our server.(Like you said :-) This is the first instance of a known viris making through our system that I know. Thanks We run qmail/qmail-scanner/SA/clamav and it h

Re: [Clamav-users] FOO.EXE

2003-08-16 Thread Antony Stone
On Saturday 16 August 2003 4:57 pm, W.D. McKinney wrote: > Here I am looking at manual. > Using my clamav tools I find. > > webmail:/home/dee# clamscan viri > viri/message.zip: Trojan.Dropper.C FOUND Yup - that's the one I thought it would be :) It's been detected by ClamAV since 1st August. >

Re: [Clamav-users] message.zip ?

2003-08-16 Thread Michael Sullenszino
Sure, post it somewhere we can get to. Sounds like mimail.a? Mike On Sat, Aug 16, 2003 at 07:30:02AM -0800, W.D. McKinney wrote: > Hi, > > One of our customers recieved a message that had a .zip attachment and > looks suspect. Anyone here here what to take a look at at it ? > > Dee > -- >

Re: [Clamav-users] message.zip ?

2003-08-16 Thread Antony Stone
On Saturday 16 August 2003 4:30 pm, W.D. McKinney wrote: > Hi, > > One of our customers recieved a message that had a .zip attachment and > looks suspect. Anyone here here what to take a look at at it ? Let me guess - it's called message.zip (you said that in your subject), it's 20567 bytes long

[Clamav-users] FOO.EXE

2003-08-16 Thread W.D. McKinney
Here I am looking at manual. Using my clamav tools I find. --- SCAN SUMMARY --- Known viruses: 9317 Scanned directories: 1 Scanned files: 33 Infected files: 0 Data scanned: 27.98 Mb I/O buffer size: 131072 bytes Time: 14.597 sec (0 m 14 s) webmail:/home/dee# clamscan viri viri/mess

Re: [Clamav-users] Still Fighting Problem with clamd bombing out on Openbsd 3.3 w amavisd-new and postfix

2003-08-16 Thread Tomasz Kojm
On Sat, 16 Aug 2003 17:43:03 +1000 "Ben Hooper" <[EMAIL PROTECTED]> wrote: > > > If anyone has any suggestions I would love the help. I have two > > > installs doing the exact same thing. So if I made a mistake > > > in my setup > > > I made it more than once. > > > > FWIW, I am seeing the sa

[Clamav-users] message.zip ?

2003-08-16 Thread W.D. McKinney
Hi, One of our customers recieved a message that had a .zip attachment and looks suspect. Anyone here here what to take a look at at it ? Dee -- W.D.McKinney (Dee) Alaska Wireless Systems 11310 Lillan Lane, Anchorage, AK 99515-2914 Direct (907)349-4308 -=- http://www.akwireless.net --

RE: [Clamav-users] Still Fighting Problem with clamd bombing out on Openbsd 3.3 w amavisd-new and postfix

2003-08-16 Thread Ben Hooper
> > If anyone has any suggestions I would love the help. I have two > > installs doing the exact same thing. So if I made a mistake > > in my setup > > I made it more than once. > > FWIW, I am seeing the same thing happen under 3.3-stable on two of my > machines. Ktrace shows clamd bombing ou