Effective virus scanners

Alan Fiebig mailscanner at ELKNET.NET
Mon Aug 25 17:33:50 IST 2003


I'll try and parse the maillog file later today to see which ones ClamAV missed that e-Trust got... Monday's are always crazy timewise :)

I won't have the actual infected messages, as e-Trust DID catch them, and I have MS delete infected files, not quarentine them.

-Alan

>On Monday 25 August 2003 4:36 pm, Stephane Lentz wrote:
>
>> On Mon, Aug 25, 2003 at 10:27:41AM -0500, Alan Fiebig wrote:
>> > Just for comparison...
>> >
>> > I run both ClamAV and e-Trust.
>> > Over the last three days:
>> >    ClamAV has caught 34,248 viruses
>> >    and e-Trust has caught 34,672.
>> >
>> > I concurr that for a free, OpenSource package, ClamAV does a very good
>> > job.
>> >
>> > -Alan
>>
>> Have, you isolated the messages that contained the infected attachments
>> not detected by ClamAv ?
>> It would be great to submit these viruses not detected. You can do it
>> through : http://clamav.sourceforge.net/cgi-bin/sendvirus.cgi
>
>You can also simply email the offending file to virus at clamav.elektrapro.com
>
>If ClamAV already recognises it, you'll get a bounce back for sending them a
>virus :)   If ClamAV doesn't recognise it, it'll get fed into the pipeline
>for processing a new signature.
>
>> I did this for the WORM_SOBIG.F.DAM  virus. Hope they will include it
>> real soon.
>
>You can send me a copy of that if you like - I'm just creating a bunch of
>ClamAV signatures now :)
>
>Antony.
>
>--
>
>There are only 10 types of people in the world:
>those who understand binary notation,
>and those who don't.



More information about the MailScanner mailing list