Still not recognised.
On Wed, Jun 29, 2011 at 4:00 PM, Mihamina Rakotomandimby
wrote:
>> On Wed, 29 Jun 2011 12:45:37 +0300
>> Henrik K wrote:
>> So your users receive lot of legimate exes?
>
> Nope, exes are zipped
>
> --
> RMA.
> ___
> Help us build
> On Wed, 29 Jun 2011 12:45:37 +0300
> Henrik K wrote:
> So your users receive lot of legimate exes?
Nope, exes are zipped
--
RMA.
___
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml
> Seriously! Why not have the user shut down his mail system entirely.
> That would pretty much ensure that no Virus or Malware is delivered via
> SMTP.
>
> Your suggest is only feasible if the user never wants to receive any
> executable or archived file formats. Assuming that they do, a better
>
On 2011 Jun 29, at 12:49 , Joel Esler wrote:
> If you have a sample of the file, submitting it through ClamAV's submission
> interface makes it "bubble up" so the rule writers can get to it faster.
Or if you're lucky and it's the exact same file every time, you can trivially
create your own sign
I think he should demand all his money back.
--
Michael Scheidell, CTO
SECNAP Network Security
-Original message-
From: Joel Esler
To: ClamAV users ML
Sent: Wed, Jun 29, 2011 10:50:25 GMT+00:00
Subject: Re: [clamav-users] Virus not detected by Clamav
If you have a sample of the file
On Jun 29, 2011, at 7:58 AM, polloxx wrote:
> On Wed, Jun 29, 2011 at 12:49 PM, Joel Esler wrote:
>> If you have a sample of the file, submitting it through ClamAV's submission
>> interface makes it "bubble up" so the rule writers can get to it faster.
>>
>> (instead of waiting for it to come
On Wed, Jun 29, 2011 at 12:49 PM, Joel Esler wrote:
> If you have a sample of the file, submitting it through ClamAV's submission
> interface makes it "bubble up" so the rule writers can get to it faster.
>
> (instead of waiting for it to come through Virustotal)
>
Joel,
I did that yesertday.
On Wed, 29 Jun 2011 13:12:30 +0300
Török Edwin articulated:
> On 2011-06-29 13:04, polloxx wrote:
> > On Wed, Jun 29, 2011 at 11:45 AM, Henrik K wrote:
> >> On Wed, Jun 29, 2011 at 12:27:46PM +0300, Mihamina Rakotomandimby
> >> wrote:
> On Wed, 29 Jun 2011 11:24:24 +0200
> polloxx wrot
If you have a sample of the file, submitting it through ClamAV's submission
interface makes it "bubble up" so the rule writers can get to it faster.
(instead of waiting for it to come through Virustotal)
J
On Jun 29, 2011, at 5:24 AM, polloxx wrote:
> Dear,
>
> One of our customers got a viru
On Jun 29, 2011, at 6:04 AM, polloxx wrote:
> On Wed, Jun 29, 2011 at 11:45 AM, Henrik K wrote:
>> On Wed, Jun 29, 2011 at 12:27:46PM +0300, Mihamina Rakotomandimby wrote:
On Wed, 29 Jun 2011 11:24:24 +0200
polloxx wrote:
>>>
Are there other user with the same problem? Any solut
On 2011-06-29 13:04, polloxx wrote:
> On Wed, Jun 29, 2011 at 11:45 AM, Henrik K wrote:
>> On Wed, Jun 29, 2011 at 12:27:46PM +0300, Mihamina Rakotomandimby wrote:
On Wed, 29 Jun 2011 11:24:24 +0200
polloxx wrote:
>>>
Are there other user with the same problem? Any solution?
>>>
>>
On Wed, Jun 29, 2011 at 11:45 AM, Henrik K wrote:
> On Wed, Jun 29, 2011 at 12:27:46PM +0300, Mihamina Rakotomandimby wrote:
>> > On Wed, 29 Jun 2011 11:24:24 +0200
>> > polloxx wrote:
>>
>> > Are there other user with the same problem? Any solution?
>>
>> I have the same problem.
>> I manage a m
On Wed, Jun 29, 2011 at 12:27:46PM +0300, Mihamina Rakotomandimby wrote:
> > On Wed, 29 Jun 2011 11:24:24 +0200
> > polloxx wrote:
>
> > Are there other user with the same problem? Any solution?
>
> I have the same problem.
> I manage a mail server used by a vendor of DHL.
>
> Pretty annoying a
> On Wed, 29 Jun 2011 11:24:24 +0200
> polloxx wrote:
> Are there other user with the same problem? Any solution?
I have the same problem.
I manage a mail server used by a vendor of DHL.
Pretty annoying as far as all emails from DHL are sensible and
important for the suers :-)
Unfortunately, I
Dear,
One of our customers got a virus not detected by
Clamav:dhl-express-prtcopy-Delivery-Failure-Notification-HXZsVlN[...].exe
A fake DHL non-delivery report.
Other engines do detect it:
BitDefender 7.2 2011.06.27 Trojan.Zbot.1911
F-Secure 9.0.16440.0 2011.06.27 Trojan.Zbot.1911
Kaspersky
On Dec 20, 2005, at 04:40 , Luis Miguel R. wrote:
Not detected here too, oldest clamav versions detect it well.
Detection of viruses in a buffer scan isn't working well either, it
doesn't recognize most viruses including the ClamAV test viruses that
the older versions (pre 0.87) recognize
Not detected here too, oldest clamav versions detect it well.
Linux cubo 2.4.27-2-686 #1 Mon May 16 17:03:22 JST 2005 i686 GNU/Linux
ClamAV 0.87.1/1213/Mon Dec 19 15:48:34 2005
([EMAIL PROTECTED]:~)# clamscan attreg.zip
attreg.zip: OK
([EMAIL PROTECTED]:~)# f-prot -ver
Program version: 4.6.3
En
Rob Chanter said:
> On Mon, Dec 19, 2005 at 08:39:10AM -0800, Dennis Peterson wrote:
>>
>> In fact it would be nice to have a command line switch that generates a
>> listing of what is seen and understood by the applications after reading
>> the clamd.conf and freshclam.conf files, as well as where
On Mon, Dec 19, 2005 at 08:39:10AM -0800, Dennis Peterson wrote:
>
> In fact it would be nice to have a command line switch that generates a
> listing of what is seen and understood by the applications after reading
> the clamd.conf and freshclam.conf files, as well as where they were found.
Po
On Mon, 19 Dec 2005 16:39:17 + in [EMAIL PROTECTED]
Nigel Horne <[EMAIL PROTECTED]> wrote:
> Brian Morrison wrote:
>
> >On Mon, 19 Dec 2005 16:28:47 + in [EMAIL PROTECTED]
> >Nigel Horne <[EMAIL PROTECTED]> wrote:
> >
> >
> >
> >>>www.i2.com.br/~hamilton/reg_pass.zip
> >>>
> >
Hamilton Vera wrote:
Hi list,
Since November, I noticed that clamav 87.1 does not recognize the
following virus.
www.i2.com.br/~hamilton/reg_pass.zip
So I posted it in http://cgi.clamav.net/sendvirus.cgi, but I got no answer
NOD32 detects it as Win32/Sober.Y worm, I'd like to know if it
Brian Morrison wrote:
On Mon, 19 Dec 2005 16:28:47 + in [EMAIL PROTECTED]
Nigel Horne <[EMAIL PROTECTED]> wrote:
www.i2.com.br/~hamilton/reg_pass.zip
Try the development version:
[EMAIL PROTECTED] ~]$ clamscan reg_pass.zip
reg_pass.zip: Worm.Sober.U FOUND
So does that mean a new
Brian Morrison wrote:
On Mon, 19 Dec 2005 16:28:47 + in [EMAIL PROTECTED]
Nigel Horne <[EMAIL PROTECTED]> wrote:
www.i2.com.br/~hamilton/reg_pass.zip
Try the development version:
[EMAIL PROTECTED] ~]$ clamscan reg_pass.zip
reg_pass.zip: Worm.Sober.U FOUND
So does that
Nigel Horne said:
> Hamilton Vera wrote:
>
>> Hi list,
>>
>> Since November, I noticed that clamav 87.1 does not recognize the
>> following virus.
>>
>> www.i2.com.br/~hamilton/reg_pass.zip
>
>
> Try the development version:
>
It would be very nice if future releases of clamd and freshclam pri
On Mon, 19 Dec 2005 16:28:47 + in [EMAIL PROTECTED]
Nigel Horne <[EMAIL PROTECTED]> wrote:
> > www.i2.com.br/~hamilton/reg_pass.zip
>
>
> Try the development version:
>
> [EMAIL PROTECTED] ~]$ clamscan reg_pass.zip
> reg_pass.zip: Worm.Sober.U FOUND
So does that mean a new release is i
On Mon, 19 Dec 2005 13:34:00 -0200 (BRDT) in
[EMAIL PROTECTED] Hamilton Vera
<[EMAIL PROTECTED]> wrote:
> NOD32 detects it as Win32/Sober.Y worm, I'd like to know if it is an
> isolated case.
Don't assume that NOD32 has identified it correctly, other packages
have false positives you know.
--
Hamilton Vera wrote:
Hi list,
Since November, I noticed that clamav 87.1 does not recognize the
following virus.
www.i2.com.br/~hamilton/reg_pass.zip
Try the development version:
[EMAIL PROTECTED] ~]$ clamscan reg_pass.zip
reg_pass.zip: Worm.Sober.U FOUND
--- SCAN SUMMARY --
Hamilton Vera said:
> Hi Denis, thanks for answering.
>
> What version are you using? I am using and updated 87.1, and I think
> that this version is not working.
>
>
>
I'm running v 87.1. Examine your clamd.conf and freshclam.conf files and
ensure they agree on where the cvd files are being place
> What version are you using? I am using and updated 87.1, and I think
> that this version is not working.
my clamscan (87.1/1213) definitely finds it here (Worm.Sober.U).
--
___
http://lurker.clamav.net/list/clamav-users.html
Hi Denis, thanks for answering.
What version are you using? I am using and updated 87.1, and I think
that this version is not working.
clamd -V
ClamAV 0.87.1
Received signal: wake up
ClamAV update process started at Mon Dec 19 13:51:22 2005
main.cvd is up to date (version: 34, sigs: 39625, f-l
On Mon, 19 Dec 2005, Hamilton Vera wrote:
; Since November, I noticed that clamav 87.1 does not recognize the following
; virus.
;
; www.i2.com.br/~hamilton/reg_pass.zip
;
; So I posted it in http://cgi.clamav.net/sendvirus.cgi, but I got no answer
;
; NOD32 detects it as Win32/Sober.Y worm,
Hamilton Vera said:
> Hi list,
>
> Since November, I noticed that clamav 87.1 does not recognize the
> following virus.
>
> www.i2.com.br/~hamilton/reg_pass.zip
>
> So I posted it in http://cgi.clamav.net/sendvirus.cgi, but I got no answer
>
> NOD32 detects it as Win32/Sober.Y worm, I'd like
Hi list,
Since November, I noticed that clamav 87.1 does not recognize the
following virus.
www.i2.com.br/~hamilton/reg_pass.zip
So I posted it in http://cgi.clamav.net/sendvirus.cgi, but I got no answer
NOD32 detects it as Win32/Sober.Y worm, I'd like to know if it is an
isolated c
33 matches
Mail list logo