Re: [Clamav-users] (newbie on list - don't hit me) -> password .zips

2004-03-18 Thread Tomasz Kojm
On Fri, 19 Mar 2004 13:57:09 +1100 Jonathan Trott <[EMAIL PROTECTED]> wrote: > > On Thu, 18 Mar 2004 13:31:41 -0800, "Jonathan Mergy" <[EMAIL PROTECTED]> > > wrote: > > > I just joined the list and have been using clamav with my > > postfix/amavisd/spamasassin system for a while now. > > > > I

Re: [Clamav-users] pthreads instability?

2004-03-18 Thread Todd Lyons
On Thu, 2004-03-18 at 17:03, Tomasz Kojm wrote: > > On a stock RedHat 9.0 box (3 boxen load balanced) with updated kernel > > (2.4.20-20.9smp), I have stability problems with clamd. > > I'm using sendmail -> clamav-milter -> clamd. Our mail servers accept > 1) Which version of clamd ? > 2) Which v

Re: [Clamav-users] (newbie on list - don't hit me) -> password .zips

2004-03-18 Thread Jonathan Trott
On Thu, 18 Mar 2004 13:31:41 -0800, "Jonathan Mergy" <[EMAIL PROTECTED]> wrote: I just joined the list and have been using clamav with my postfix/amavisd/spamasassin system for a while now. I read some items in the list archives about the passworded zip problems. What is the status on this and h

RE: [Clamav-users] attachment-free worms

2004-03-18 Thread jef moskot
On Thu, 18 Mar 2004, Diego d'Ambra wrote: > A signature to detect these e-mails was added through daily.cvd version > 194, so I guess you must patch your amavis setup so ClamAV is allowed to > scan the raw e-mail. Thanks, looks like I've managed to apply a new layer of duct tape, and the script se

Re: [Clamav-users] clamd hanging on SunOS 5.8

2004-03-18 Thread Fajar A. Nugraha
turgut kalfaoglu wrote: Well, even after I disable urandom, which my system does not have anyway, I still have clamd hanging; eating up over 90% of the CPU, and doing nothing basically. I am trying daily builds, but it does not help. This sometimes happen after five minutes of runtime, but somet

Re: [Clamav-users] pthreads instability?

2004-03-18 Thread Tomasz Kojm
On Thu, 18 Mar 2004 16:45:30 -0800 Todd Lyons <[EMAIL PROTECTED]> wrote: > On a stock RedHat 9.0 box (3 boxen load balanced) with updated kernel > (2.4.20-20.9smp), I have stability problems with clamd. > > I'm using sendmail -> clamav-milter -> clamd. Our mail servers accept 1) Which version o

[Clamav-users] pthreads instability?

2004-03-18 Thread Todd Lyons
On a stock RedHat 9.0 box (3 boxen load balanced) with updated kernel (2.4.20-20.9smp), I have stability problems with clamd. I'm using sendmail -> clamav-milter -> clamd. Our mail servers accept about 50K mail per day (each box), of which about 35K gets rejected by spamassassin before it ever re

Re: [Clamav-users] clamd hanging on SunOS 5.8

2004-03-18 Thread Doug Hardie
On Mar 18, 2004, at 14:03, Thomas Lamy wrote: turgut kalfaoglu schrieb: Well, even after I disable urandom, which my system does not have anyway, I still have clamd hanging; eating up over 90% of the CPU, and doing nothing basically. I am trying daily builds, but it does not help. This sometime

Re: [Clamav-users] clamd hanging on SunOS 5.8

2004-03-18 Thread Doug Hardie
What I did is to be sure the build incorporate -g and then get it hung. Open it up with gdb and start stepping through the code to see where it is hanging. The hang I was was only about 6 instructions so it was easy to find that loop in the code. On Mar 18, 2004, at 12:39, turgut kalfaoglu wr

Re: [Clamav-users] Troubles with recent clamav's

2004-03-18 Thread Doug Hardie
My quick look at the code behind --disable-urandom gave me the impression that it only disabled the test for urandom and forced clamd to use urandom. Thats why I manually deleted the define. I guess I will have to look a bit closer. That would be easier to remember when moving to a new versi

Re: [Clamav-users] Troubles with recent clamav's

2004-03-18 Thread Doug Hardie
Go into the clamav.h file and remove the definition for C_URANDOM. I just commented it out. The make it again. On Mar 18, 2004, at 08:52, Robert Blayzor wrote: On 3/16/04 7:29 PM, "Doug Hardie" <[EMAIL PROTECTED]> wrote: The problem I encountered has now been identified and I have a working c

Re: [Clamav-users] clamd hanging on SunOS 5.8

2004-03-18 Thread Thomas Lamy
turgut kalfaoglu schrieb: Well, even after I disable urandom, which my system does not have anyway, I still have clamd hanging; eating up over 90% of the CPU, and doing nothing basically. I am trying daily builds, but it does not help. This sometimes happen after five minutes of runtime, but som

Re: [Clamav-users] clamd hanging on SunOS 5.8

2004-03-18 Thread Robert Blayzor
On 3/18/04 3:39 PM, "turgut kalfaoglu" <[EMAIL PROTECTED]> wrote: > Well, even after I disable urandom, which my system does not have anyway, > I still have clamd hanging; eating up over 90% of the CPU, and doing > nothing basically. > I am trying daily builds, but it does not help. This sometimes

[Clamav-users] (newbie on list - don't hit me) -> password .zips

2004-03-18 Thread Jonathan Mergy
I just joined the list and have been using clamav with my postfix/amavisd/spamasassin system for a while now. I read some items in the list archives about the passworded zip problems. What is the status on this and how can I help? jonathan mergy [EMAIL PROTECTED] ForwardSou

[Clamav-users] clamd hanging on SunOS 5.8

2004-03-18 Thread turgut kalfaoglu
Well, even after I disable urandom, which my system does not have anyway, I still have clamd hanging; eating up over 90% of the CPU, and doing nothing basically. I am trying daily builds, but it does not help. This sometimes happen after five minutes of runtime, but sometimes with just 2 minutes

RE: [Clamav-users] clamassassin and procmail config

2004-03-18 Thread Lynn Duerksen
> > Do someone have an HOWTO for > postfix+clamav+amavis+spamassassin under RH9 ? > > Phil CREATING A SPAMFILTER RELAY SERVER By Scott L. Henderson http://www.geocities.com/scottlhenderson/spamfilter.html Don't know if he has anything on adding Clamav but the rest is there. >From what I re

[Clamav-users] Phatbot Virus/Worm/Trojan

2004-03-18 Thread Rodney Green
Just got an email from SANS (http://sans.org) about this. The link requires registration for a washingtonpost.com account. http://www.washingtonpost.com/wp-dyn/articles/A3211-2004Mar17.html --- This SF.Net email is sponsored by: IBM Linux Tut

Re: [Clamav-users] testvirus.org eicar tests failing w/ ClamAV version devel-20040316 on OSX+CGPro (clamav-users: addressed to exclusive sender for this address)

2004-03-18 Thread Thomas Lamy
OpenMacNews schrieb: -- On Wednesday, March 17, 2004 1:42 PM -0800 OpenMacNews <[EMAIL PROTECTED]> wrote: -- On Wednesday, March 17, 2004 9:42 PM +0100 Thomas Lamy <[EMAIL PROTECTED]> wrote: I agree here. It just comes down to: - Have you enabled the ScanMail and ScanArchive options in your

Re: [Clamav-users] testvirus.org eicar tests failing w/ ClamAV version devel-20040316 on OSX+CGPro (clamav-users: addressed to exclusive sender for this address)

2004-03-18 Thread OpenMacNews
hi, seems like there's a bunch o' questions abt this ... is there anything we (users) can do abt this issue? is it, rather, a developer issue? or is it *not* a clamav issue at all, but the calling script's? richard -- On Wednesday, March 17, 2004 1:42 PM -0800 OpenMacNews <[EMAIL PROTECTED]

Re: [Clamav-users] clamassassin and procmail config

2004-03-18 Thread pi
Jim Maul wrote: If you already installed some of the dependencies then you can try to override them by using the --nodeps option with rpm. This may cause problems down the road but then again, it may not. Jim Okay done. Now let's configure. Do someone have an HOWTO for postfix+clamav+a

Re: [Clamav-users] Troubles with recent clamav's

2004-03-18 Thread Robert Blayzor
On 3/16/04 7:29 PM, "Doug Hardie" <[EMAIL PROTECTED]> wrote: > In case it might help someone else, the approach I used to find the > problem was to use a test system and pass a large number of directories > (The FreeBSD source code) to clamdscan and let it beat clamd up for > about 5 minutes. The

RE: [Clamav-users] clamassassin and procmail config

2004-03-18 Thread Jim Maul
> -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] Behalf Of pi > Sent: Thursday, March 18, 2004 12:38 PM > To: [EMAIL PROTECTED] > Subject: Re: [Clamav-users] clamassassin and procmail config > > > Ling C. Ho wrote: > > > > > > > You can also try amavis-new. http:

Re: [Clamav-users] clamassassin and procmail config

2004-03-18 Thread pi
Ling C. Ho wrote: You can also try amavis-new. http://www.ijs.si/software/amavisd ... ling It doesn't work, I can't succeed to install it on my RH9. If someone can help me Thought it was a perl problem tried to install another perl version but always the same problem. Any idea ?? Phil

Re: [Clamav-users] can't install amavisd-new on RH9

2004-03-18 Thread Ling C. Ho
pi wrote: Hello all I can't install amavis on my Redhat9 box here are the messages I got: [EMAIL PROTECTED] amavisd]# rpm -ivh amavisd-new-20030616-5.p8.rh90.dag.i386.rpm error: Failed dependencies: perl(Convert::TNEF) is needed by amavisd-new-20030616-5.p8.rh90.dag perl(MIME::Ent

Re: [Clamav-users] clamassassin and procmail config

2004-03-18 Thread Ling C. Ho
pi wrote: Nigel Horne wrote: On Thursday 18 Mar 2004 9:45 am, pi wrote: I thought milter was ONLY for scanmail, I use postfix. Milter is for sendmail. Phil Yes, that' what I wanted to say ;-) What can I use with postfix? Phil You can also try amavis-new. http://www.ijs.s

Re: [Clamav-users] Troubles with recent clamav's

2004-03-18 Thread Robert Blayzor
On 3/16/04 7:29 PM, "Doug Hardie" <[EMAIL PROTECTED]> wrote: > The problem I encountered has now been identified and I have a working > clamd that does not hang. I compiled it two different ways and both > worked. The problem was /dev/urandom returning either a -1 or a 0. > Either of those will

Re: [Clamav-users] clamassassin and procmail config

2004-03-18 Thread John Jolet
pi wrote: Nigel Horne wrote: On Thursday 18 Mar 2004 9:45 am, pi wrote: I thought milter was ONLY for scanmail, I use postfix. Milter is for sendmail. Phil Yes, that' what I wanted to say ;-) What can I use with postfix? Phil

RE: [Clamav-users] Bagle.Q

2004-03-18 Thread Jim Maul
> -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] Behalf Of Scott Ryan > Sent: Thursday, March 18, 2004 9:31 AM > To: Clam Antivirus List > Subject: [Clamav-users] Bagle.Q > > > I am running 0.67-1 and was looking to get a copy of the virus to test > if clamd catc

Re: [Clamav-users] clamassassin and procmail config

2004-03-18 Thread pi
Nigel Horne wrote: On Thursday 18 Mar 2004 9:45 am, pi wrote: I thought milter was ONLY for scanmail, I use postfix. Milter is for sendmail. Phil Yes, that' what I wanted to say ;-) What can I use with postfix? Phil ---

[Clamav-users] Bagle.Q

2004-03-18 Thread Scott Ryan
I am running 0.67-1 and was looking to get a copy of the virus to test if clamd catches it. where would i be able to get a copy of it from? Thanks Scott Ryan Telkom Internet South Africa signature.asc Description: This is a digitally signed message part

RE: [Clamav-users] attachment-free worms

2004-03-18 Thread Randal, Phil
Jeffrey Moskot wrote: > Based on what this article says, it looks like there will > soon be problems > with my config: > http://www.sophos.com/virusinfo/articles/bagletwist.html > > I wasn't able to get my version of amavis properly patched to > submit the > body of the message to clam (or at

RE: [Clamav-users] attachment-free worms

2004-03-18 Thread Diego d'Ambra
> -Original Message- > From: [EMAIL PROTECTED] [mailto:clamav-users- > [EMAIL PROTECTED] On Behalf Of jef moskot > Sent: 18. marts 2004 12:52 > To: [EMAIL PROTECTED] > Subject: [Clamav-users] attachment-free worms > > Based on what this article says, it looks like there will soon be proble

Re: [Clamav-users] SFX-RAR files

2004-03-18 Thread Tomasz Kojm
On Thu, 18 Mar 2004 10:52:44 +0100 "daniele" <[EMAIL PROTECTED]> wrote: > I've upgrade the database...but it doesn't change Please don't top-post. No, your database is still outdated. There's no Trojan.Orcamento signature: [EMAIL PROTECTED]:~$ sigtool -l | grep -i orcam [EMAIL PROTECTED]:~$

Re: [Clamav-users] why don't detect

2004-03-18 Thread Nigel Horne
On Thursday 18 Mar 2004 7:23 am, Korchmenuk Nickolay wrote: > Hi > I've 11 e-mails like that with SCO.A, Netsky, I-Frame.exploit etc. Please send to me, the more samples the better! -Nigel -- Nigel Horne. Arranger, Composer, Typesetter. NJH Music, Barnsley, UK. ICQ#20252325 [EMAIL PROTECTED]

Re: [Clamav-users] clamassassin and procmail config

2004-03-18 Thread Nigel Horne
On Thursday 18 Mar 2004 9:45 am, pi wrote: > I thought milter was ONLY for scanmail, I use postfix. Milter is for sendmail. > Phil -- Nigel Horne. Arranger, Composer, Typesetter. NJH Music, Barnsley, UK. ICQ#20252325 [EMAIL PROTECTED] http://www.bandsman.co.uk -

[Clamav-users] can't install amavisd-new on RH9

2004-03-18 Thread pi
Hello all I can't install amavis on my Redhat9 box here are the messages I got: [EMAIL PROTECTED] amavisd]# rpm -ivh amavisd-new-20030616-5.p8.rh90.dag.i386.rpm error: Failed dependencies: perl(Convert::TNEF) is needed by amavisd-new-20030616-5.p8.rh90.dag perl(MIME::Entity) is need

[Clamav-users] attachment-free worms

2004-03-18 Thread jef moskot
Based on what this article says, it looks like there will soon be problems with my config: http://www.sophos.com/virusinfo/articles/bagletwist.html I wasn't able to get my version of amavis properly patched to submit the body of the message to clam (or at least as far as I can tell, that's not wha

[Clamav-users] Rar module

2004-03-18 Thread Bo-Lina teknisk support
Hello.   Do annyone have a solution to this RAR Module error? In the documentation it says it's ok to get, but since new viruses use rar compressions for sending out viruses it's getting a pretty big problem. Before when I got this error message it discarded the mail and deleted it, so I cha

Re: [Clamav-users] SFX-RAR files

2004-03-18 Thread Thomas Lamy
daniele schrieb: From: "Michael L Torrie" <[EMAIL PROTECTED]> On Wed, 2004-03-17 at 06:51, Tomasz Kojm wrote: On Wed, 17 Mar 2004 12:53:43 +0100 "daniele" <[EMAIL PROTECTED]> wrote: I've installed clamav-0.60 and also 0.65 , but when sendmail must send a message with file .exe creates with winra

Re: [Clamav-users] Config change

2004-03-18 Thread Tomasz Kojm
On Wed, 17 Mar 2004 12:39:15 -0500 Dennis Skinner <[EMAIL PROTECTED]> wrote: > I noticed that the DataDirectory directive in the clamav.conf has > changed in recent versions to DatabaseDirectory. Are both valid and > will they remain so? I don't see any notes in the docs or ChangeLog Yes, they

FW: Re: [Clamav-users] Problem in install ClamAV

2004-03-18 Thread Muhammad Kashif Muneer
Dear All Members, I would like to thank all of u members out there for helping me in installation problem through replies. I have downloaded the RPM files from net and installed successfully. Now Clamav and Clamav-milter both start working fine. Now as administrator how can I find about rejected m

Re: [Clamav-users] SFX-RAR files

2004-03-18 Thread daniele
I've upgrade the database...but it doesn't change - Original Message - From: "Michael L Torrie" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Wednesday, March 17, 2004 4:47 PM Subject: Re: [Clamav-users] SFX-RAR files > On Wed, 2004-03-17 at 06:51, Tomasz Kojm wrote: > > On Wed, 17

Re: [Clamav-users] clamassassin and procmail config

2004-03-18 Thread pi
I thought milter was ONLY for scanmail, I use postfix. Can I install it ? Phil Nigel Horne wrote: On Wednesday 17 Mar 2004 10:47 pm, pi wrote: I want each mail detected as 'with a virus' to be forwarded in a special mailbox ([EMAIL PROTECTED]) Use the --quarantine=EMAILADDRESS option of

Re: [Clamav-users] OpenBSD clamav Port (0.67-1) RAR Files

2004-03-18 Thread Helmut Schneider
Helmut Schneider wrote: > Lynn Duerksen wrote: > >>> Thats the point, if clamav would have detected the virus in >>> the original mail I wouldn't have posted here... :) >> >> I am experiencing similar problems on my OpenBSD 3.4 box and was >> wondering if there has been any resolution on this is

Re: [Clamav-users] Clamd randomly hanging then eventually continuing

2004-03-18 Thread Trog
On Thu, 2004-03-18 at 03:49, Robert Blayzor wrote: > I am running devel snapshot 20040415 on FreeBSD 4.9. > > I'm having a problem with clamd, the process randomly hanging on either > reloading the database and sometimes scanning mbox files. It's very > strange. When the processes hangs clamd is

RE: [Clamav-users] why don't detect

2004-03-18 Thread Diego d'Ambra
> -Original Message- > From: [EMAIL PROTECTED] [mailto:clamav-users- > [EMAIL PROTECTED] On Behalf Of Korchmenuk Nickolay > Sent: 18. marts 2004 08:23 > To: [EMAIL PROTECTED] > Subject: Re: [Clamav-users] why don't detect > > > I'm unable to tell why the --mbox option didn't detect the vir