[Qmail-scanner-general]Fsecure error - qmailscanner

2004-04-20 Thread Greg Kelley
The exit status 8 is from f-secure and indicates a file is 'suspected' instead of 'infected'. You can modify the f-secure script to check for 8 as well as 3 or the word 'suspected' as well as 'infected'. Rgds, __ Greg Kelley, Technol

[Qmail-scanner-general]Update on Moodown/Netsky scanning

2004-02-19 Thread Greg Kelley
(website.doc.exe for example) are malformed and probably wouldn't launch if run anyway, but I'm not going to test it to find out! Even Norton AV running on the desktop isn't catching some of these where it's caught some others of the same form today. ______ Greg Kelley,

[Qmail-scanner-general]Netsky/Moodown Getting through

2004-02-19 Thread Greg Kelley
because of extension till 1:45 then many more that got scanned and the .zip file was discovered with f-secure. Will keep you posted on further developments. ______ Greg Kelley, Technology Director Britannic Aviation, US and UK US Office: Pease Int'l Tradeport 68 New Hamp

[Qmail-scanner-general]Novarg Getting Through - Findings

2004-02-16 Thread Greg Kelley
due to the way the attachment was embedded into the email message. Message was not scanned by QS as it is PLAIN Text with attachment at the end of the body. So, some of you may be getting 'false positives' from Norton AV on attachments that are benign. Rgds, __ G

[Qmail-scanner-general]MyDoom (Novarg) Not Scanned

2004-02-13 Thread Greg Kelley
Doug, Actually Norton DID quarantine an infected attachment named ofo.zip from the email message that got thru as PLAIN text. I have the file and it is a true infexted .zip file. So if someone did open it they would get infected. Rgds, __ Greg Kelley, Technology Director

Re: [Qmail-scanner-general]MyDoom (Novarg) Not Scanned

2004-02-12 Thread Greg Kelley
Thanks for looking at this. However, the virus has been removed from the message by Norton AV and it leaves the message: "Norton AntiVirus removed the attachment: ofo.zip. The attachment was infected with the [EMAIL PROTECTED] virus." in it's place where the attachment originally was in the messa

[Qmail-scanner-general]MyDoom (Novarg) Not Scanned

2004-02-12 Thread Greg Kelley
+++ Perhaps someone can discover why this was not scanned. I have redundant scanning on and I use f-secure which consistently finds the virus if it gets a chance to scan it. Thanks. Rgds, __ Greg Kelley, Technology Director Britannic Aviation, US and UK US Office: Pease Int&#x

[Qmail-scanner-general]Not scanning spoofed content-type

2004-02-12 Thread Greg Kelley
ntire message and the quarantined .zip file. Rgds, __ Greg Kelley, Technology Director Britannic Aviation, US and UK US Office: Pease Int'l Tradeport 68 New Hampshire Ave. Portsmouth, NH 03801 603.766.3005 http://www.britannicaviation.com AOPA, EAA, SSA CFII SEL, MEL; C

[Qmail-scanner-general]Not scanning spoofed content-type

2004-02-11 Thread Greg Kelley
t;, <mailto:[EMAIL PROTECTED]> List-Id: Red Hat Network Users List List-Unsubscribe: <https://www.redhat.com/mailman/listinfo/rhn-users>, <mailto:[EMAIL PROTECTED]> List-Archive: <https://www.redhat.com/archives/rhn-users/> Content-Transfer-Encoding: base64 Rgds, ___

[Qmail-scanner-general]F-Secure

2003-10-30 Thread Greg Kelley
or memory/resource/perms problem - exit status $fsecure_status"); } } $stop_fsecure_time=[gettimeofday]; $fsecure_time = tv_interval ($start_fsecure_time, $stop_fsecure_time); &debug("fsecure: finished scan of dir \"$scandir/$file_id\" in $fsecure_time secs")

[Qmail-scanner-general]Re: Fsav still broke?

2003-10-06 Thread Greg Kelley
I'm using 1.16 - policy here dictates we do not use Release Candidates in a Production environment, so when fsav 4.51 came out with modifications, I changed the code to handle Suspicious Files. __ Greg Kelley, Technology Director Britannic Aviation, US and UK US O

[Qmail-scanner-general]Fsav still broke?

2003-10-03 Thread Greg Kelley
"; } else { #This implies a corrupt set of DAT files or resource problems... &tempfail("corrupt or unknown Fsecure scanner error or memory/resource/perms problem - exit status $fsecure_status"); } } Rgds, __ Greg Kelley, Technology

[Qmail-scanner-general]fsav 4.51 Return Codes

2003-09-19 Thread Greg Kelley
Debug shows that when a return code of 8 (Suspicious File) is generated, there is no extra dialog output at all. Just shows Start Scan and Stop Scan, then returns the 8. This will probably impact the way the sub-fsecure.pl script is rewritten to handle this. __ Greg Kelley

[Qmail-scanner-general]New f-secure return codes

2003-09-19 Thread Greg Kelley
following priority order: 130, 7, 1, 3, 8, 6, 9, 0. Rgds, ______ Greg Kelley, Technology Director Britannic Aviation, US and UK US Office: Pease Int'l Tradeport 68 New Hampshire Ave. Portsmouth, NH 03801 603.766.3005 http://www.britannicaviation.com AOPA,

[Qmail-scanner-general]Re: f-secure fails again!

2003-09-18 Thread Greg Kelley
Folks, Unloaded the daemon, loaded it manually (exported the library location variable) and now fsav can connect to the daemon just fine. Something strange happened during/after the upgrade, so a complete unload and reload seemed to fix it. __ Greg Kelley, Technology

re: [Qmail-scanner-general]f-secure fails again!

2003-09-17 Thread Greg Kelley
Nyone who has sucessfully run this upgrade to 4.51 recently with no probs please respond. Thanks. Rgds, __ Greg Kelley, Technology Director Britannic Aviation, US and UK US Office: Pease Int'l Tradeport 68 New Hampshire Ave. Portsmouth, NH 03801 603.766.3005 http://www.

[Qmail-scanner-general]f-secure fails again!

2003-09-17 Thread Greg Kelley
Folks, Just upgraded to f-secure 4.51 from 4.50 and now the fsav client can't/won't connect to the daemon! fsavd is running as qmailq. Anyone run into this? What did the upgrade break? Rgds, __ Greg Kelley, Technology Director Britannic Aviation, US and UK

[Qmail-scanner-general]Sobig.F and attachment type

2003-08-20 Thread Greg Kelley
et. I have sobig in my silent-virus list, but it isn't getting processed (I think) because it's getting picked up first by perlscan. Is there a way to get an infected email with known attachment type to follow the silent-virus list? Rgds, ______ Greg Kelley, Technolog

[Qmail-scanner-general]Silent List

2003-07-28 Thread Greg Kelley
Should Fizzer.A be added to the silent list and if so, what form should it be listed as? Thanks. __ Greg Kelley, Technology Director Britannic Aviation, US and UK US Office: Pease Int'l Tradeport 68 New Hampshire Ave. Portsmouth, NH 03801 603.766.3005

[Qmail-scanner-general]Using daemon version 4.5 of f-secure av

2003-06-11 Thread Greg Kelley
aemon using the script 5. modify the command line in sub-fsecure.pl that runs fsav and add --usedaemon before $scandir 6. re-run config and copy qmail-scanner-queue.pl to /var/qmail/bin You should have three instances of fsavd running and email checking will go much quicker. Rgds,

[Qmail-scanner-general]f-secure commands

2003-06-06 Thread Greg Kelley
v-505 --standalone This kills the daemon because of the --standalone parameter. I can't see anywhere in the code where this is getting called this way - any ideas? I'd like the daemon to stay running to speed things up. Thanks. ______ Greg Kelley, Technology Director Britann