Re: [Clamav-users] Stability clamav-milter + clamd

2003-09-25 Thread Kelsey Cummings
On Fri, Sep 26, 2003 at 08:03:23AM +0200, SCHULZ, Wolfgang wrote: > Hi! > I'm running sendmail (8.12.10) + clamav-milter + clamd (20030925 snapshot) on > Solaris 8 and in principal I like the software (including the design) very much. > Clamd has no problems to detect all t

[Clamav-users] Stability clamav-milter + clamd

2003-09-25 Thread SCHULZ, Wolfgang
Hi! I'm running sendmail (8.12.10) + clamav-milter + clamd (20030925 snapshot) on Solaris 8 and in principal I like the software (including the design) very much. Clamd has no problems to detect all the recent viruses (contrary to what I read during the last days in the list). The only pr

Re: [Clamav-users] Mail from clamav-milter

2003-09-25 Thread Nigel Horne
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Thursday 25 Sep 2003 11:40 pm, Mike Brodbelt wrote: > there doesn't seem to be any way to tell it not to mail > postmaster and the original recipient(s). You omitted to say what version of clamav-milter you are using. Ensure your version is at lea

Re: [Clamav-users] Re: Milter (climilter): local socketname ...../clamv-milter.sock unsafe

2003-09-25 Thread Tommi Rintala
Do you get these errors in your maillog (assuming you use Syslog): Sep 22 07:01:34 mailhost clamav-milter[29772]: Expected port information from clamd, got 'Session(1): Time out ERROR ' Do you get any other error messages, have you tried to run clamd with Debug and Foreground? I got these hwen

Re: [Clamav-users] Re: Milter (climilter): local socketname ...../clamv-milter.sock unsafe

2003-09-25 Thread Lim Pey Foong
HI Tommi, clamd status shown running.. and my sendmail.mc: INPUT_MAIL_FILTER(`clmilter',`S=local:/var/lib/clamv-milter.sock,F=,T=S:4m;R:4m')dnl define(`confINPUT_MAIL_FILTERS',`clmilter') i couldn't find more infor thru internet but thru the clamav PDF :( i hope u can give me some idea plea

[Clamav-users] Mail from clamav-milter

2003-09-25 Thread Mike Brodbelt
Hi, I've just installed clamav-milter on my mail gateway machine. It's serving about 50 users, and clamav is intercepting an rejecting viruses nicely. However, I have one question - each infected email is generating a bounce message to the original user, and Cc'ing it to postmaster and to the add

Re: [Clamav-users] Gibe/Swen virus getting through

2003-09-25 Thread Jean-Sébastien Guay
Thanks again for your answer, > If you want trashscan to stop sending emails, > edit the trashscan file (remember is a shell script) and remove the > lines that creates the message I'm not talking about the virus message, I'm talking about the message that ClamAV sends to root saying "File succe

[Clamav-users] Fwd: Ruh-Roh SOBIG.G?

2003-09-25 Thread Ray Slakinski
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 FYI: Begin forwarded message: From: Dragos Ruiu <[EMAIL PROTECTED]> Date: Thu Sep 25, 2003 3:01:16 AM Canada/Eastern To: [EMAIL PROTECTED] Subject: Ruh-Roh SOBIG.G? SOBIG was nasty for me. One of my clients was getting more than 7MB/s sustained of SO

Re: [Clamav-users] Gibe/Swen virus getting through

2003-09-25 Thread Ray Slakinski
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I can't answer the first question for you, but it is a good one... my best guess on it though is up until now, metamail was good enough to do the job. Gibe.F is a different beast that makes decoding more difficult. As for the file creation deal, if

Re: [Clamav-users] A lot of Virii-Stuff

2003-09-25 Thread Jeffrey Goldberg
On Thu, 25 Sep 2003, Mark, <[EMAIL PROTECTED]>, wrote: > I've a little archive with a lot of Virri and Sources too. > I've Sources and binarys, no doubles (I hope because I found no double > files) and there over 3000. I'm part of the "team", but I suspect that what would be interesting would be

Re: [Clamav-users] Gibe/Swen virus getting through

2003-09-25 Thread Jean-Sébastien Guay
Ray, > As suggested to me, use uudeview (see script for details) It makes a > world of difference! Thanks for the answer. That did seem to do the trick, at least for the 3 virii I've gotten since I've changed trashscan to use uudeview. First question: Why is this not mentioned in the README for

Re: [Clamav-users] clamd core dump - 20030923

2003-09-25 Thread Odhiambo Washington
* Tomasz Kojm <[EMAIL PROTECTED]> [20030924 18:45]: wrote: > > I for sure did not understand that question. I am African and English > > was forced on to me when they forced me into school (sincerely! I could > > have chosen to learn French if I had the choice;)). > > Anyway I forgot to attach the

Re: [Clamav-users] Internal logger not working

2003-09-25 Thread Kham Vue
t working > * Kham Vue <[EMAIL PROTECTED]> [20030925 18:18]: wrote: > > clamav owns the log file. > > > > Infact I even tried a different file and different location. Nothing. Same > > error > > > > Any more clues? > > > How did you install cl

Re: [Clamav-users] Internal logger not working

2003-09-25 Thread Odhiambo Washington
* Kham Vue <[EMAIL PROTECTED]> [20030925 18:18]: wrote: > clamav owns the log file. > > Infact I even tried a different file and different location. Nothing. Same > error > > Any more clues? How did you install clamav??? -Wash -- Odhiambo Washington <[EMAIL

Re: [Clamav-users] Internal logger not working

2003-09-25 Thread Kham Vue
M Subject: Re: [Clamav-users] Internal logger not working > * Kham Vue <[EMAIL PROTECTED]> [20030925 15:31]: wrote: > > I have a RAQ3 with RAQ4 OS. > > > > I installed CLAMAV and now my internal logger does not work. > > > > /root # freshclam -l clam-update.lo

Re: [Clamav-users] Gibe/Swen virus getting through

2003-09-25 Thread Ray Slakinski
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 As suggested to me, use uudeview (see script for details) It makes a world of difference! However you may need to install uudeview on your system, my RH 7.1 did not have it installed by default. On Thursday, September 25, 2003, at 10:20 AM, Jean-Séb

[Clamav-users] Gibe/Swen virus getting through

2003-09-25 Thread Jean-Sébastien Guay
Hello, I have a setup where procmail passes messages through SpamAssassin, and then through clamav (using the trashscan 0.08 script). This is getting most spam and virii I get, but some still get through. I have compared some of those that get through with some of the ones that get caught by clama

Re: [Clamav-users] ClamAV 0.60 and the virus found message

2003-09-25 Thread Daniel Wiberg
Emre Sümengen wrote: 1) To be able to localize the message returned by the daemon 2) To send the warning message to others, like the intended recipient of the mail and the admin of that recipient domain and etc... Qmail-scanner ( http://qmail-scanner.sourceforge.net/ ) can do 2 for you, I don't k

Re: [Clamav-users] Internal logger not working

2003-09-25 Thread Odhiambo Washington
* Kham Vue <[EMAIL PROTECTED]> [20030925 15:31]: wrote: > I have a RAQ3 with RAQ4 OS. > > I installed CLAMAV and now my internal logger does not work. > > /root # freshclam -l clam-update.log > ERROR: LOGGER: Can't open file clam-update.log to write. > ERROR: Pr

[Clamav-users] ClamAV 0.60 and the virus found message

2003-09-25 Thread Emre Sümengen
I am using ClamAV 0.60 with Qmail & qmail-scanner-queue patch for SpamAssassin. It is configured so that when I send a message containing a virus, it blocks delivery and returns me with a "Virus found mail". All is good up to this point. What I want more is: 1) To be able to localize the messag

Re: [Clamav-users] Strenge errors.

2003-09-25 Thread Daniel Wiberg
Lombardo Federico wrote: ERROR: Please edit the example config file /usr/local/etc/clamav.conf. ERROR: Can't parse configuration file. I attach you the file clamav.conf Try commenting out the line Example like this: #Example and it should work //daniel wiberg -- www.wiberg.nu -

[Clamav-users] Internal logger not working

2003-09-25 Thread Kham Vue
I have a RAQ3 with RAQ4 OS. I installed CLAMAV and now my internal logger does not work. /root # freshclam -l clam-update.log ERROR: LOGGER: Can't open file clam-update.log to write. ERROR: Problem with internal logger. /root # /etc/rc.d/init.d/postgresql start Setting up PostgreSQL: bash: /var/

Re: [Clamav-users] Strenge errors.

2003-09-25 Thread Christopher Tan
# Comment or remove the line below. Example Comment out the Example -- Fear not death itself, but how death would come. > I'm using the latest snapshot of clamav. > > When I launch it with this command: > > /usr/local/bin/clamdscan -r --disable-summary --max-recursion=10 > --max-space > =10

[Clamav-users] Strenge errors.

2003-09-25 Thread Lombardo Federico
I'm using the latest snapshot of clamav. When I launch it with this command: /usr/local/bin/clamdscan -r --disable-summary --max-recursion=10 --max-space =100 /var/spool/qmailscan/Caronte106448773945619934 2>&1 (exaclty launched from Qmail-Scanner) I receive this error: ERROR: Please edit

Re: [Clamav-users] A lot of Virii-Stuff

2003-09-25 Thread Nigel Horne
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I would be interested in binaries of viruses/worms sent out via e-mail, but only if you have the original e-mail intact, since I'd use it to test the unencoding. - -Nigel - -- Nigel Horne. Arranger, Composer, Conductor, Typesetter. Owner of the bra

Re: [Clamav-users] Re: Milter (climilter): local socketname ...../clamv-milter.sock unsafe

2003-09-25 Thread Tommi Rintala
1) Check that the clamd -daemon is running, and is not in defunct -state. 2) Check that sendmail -configuration is right, ie. no mismatched commas and semicolons. -- Tommi Rintalapuhelin: 044-767 7770 WasaLab Oy web: http://www.wasalab.fi/ PL 365 käyntios: Wolf

[Clamav-users] Re: Milter (climilter): local socketname ...../clamv-milter.sock unsafe

2003-09-25 Thread Lim Pey Foong
Dear sir, i just install clamav and clamav-milter which workign with my sendmail 8.12.8. but when i send mail with eicar.com, it doesn't stop the mail at all. even incoming mail with eicar.com. i gone thru the log file, i found this: sendmail[3009]: h8P7NSN2003009: Milter (clmilter): local socke