[clamav-users] False Positives for Bagle when looking at encrypted zip attachments

2012-08-23 Thread Mark Foster
Hi folks First time poster, please indulge me as I get to grips with how this group works I have had a case recently where a customer of my mail platform (protected with Clam) received an encrypted zip attachment. The body of the message immediately prior to the Base64 encoded attachment cont

Re: [clamav-users] False Positives for Bagle when looking at encrypted zip attachments

2012-09-25 Thread Mark Foster
Alain (and others), A month later and I am experiencing similar problems. Worm.Bagle.F-zippwd-6 instead of -7. The 'sigtool' output for both -6 and -7 appears to be identical minus a single ^M at the end of a line., but my take on it is, surely the presence of the word 'pass' followed by an encr

[clamav-users] freshclam failures - what causes this?

2013-02-12 Thread Mark Foster
Greetings, I frequently see errors such as this from several of our ClamAV installations. Pretty much every time I go to check manually (freshclam runs from cron, so I get the errors via email) there's no update available / freshclam works fine. So why would I get: ERROR: getpatch: Can't downl

Re: [clamav-users] freshclam failures - what causes this?

2013-02-12 Thread Mark Foster
On 13/02/13 14:37, Al Varnell wrote: > On 2/12/13 4:55 PM, "Mark Foster" wrote: > >> Greetings, >> >> I frequently see errors such as this from several of our ClamAV >> installations. >> Pretty much every time I go to check manually (freshclam ru