Email.Phishing.RB-3083 tripping FPs

Glenn Steen glenn.steen at gmail.com
Fri Mar 21 19:09:13 GMT 2008


On 21/03/2008, dnsadmin 1bigthink.com <dnsadmin at 1bigthink.com> wrote:
> Hello Bobby,
>
>  Okay, since I've run into this problem, I decided to upgrade, but I
>  can only do that to one server at a time and verify each one. I've
>  upgraded one to install-Clam-0.92.1-SA-3.2.4.tar.gz. My other two
>  have install-Clam-0.91.1-SA-3.2.1.tar.gz installed All MailScanner
>  4.65.3 by rpm install. Using clamavmodule on all.
>
>  Now I've decided I really need to understand better what is happening.
>
>  Where are my virus definitions? I ran freshclam. It said it updated,
>  but I go to look for main.cvd and daily.cvd and they aren't there;
>  anywhere! What am I missing? I thought I understood this setup, but
>  apparently not?
Hello Glenn,

After a successful run of freshclam you might have had your .cvd files
replaced with .inc (incremental...) directories containing your
signature DBs.... Or do you mean you don't have any such either?

>  Thanks,
>  Glenn Parsons
>
I'm not sure if your version of MS has the fix posted to the list a
while back ... specifically to call clamavmodule without the
(equivalent) --no-phishong-restrictedscan ... posted by Gareth. It
should be fixed in a newish version (of MailScanner), but I just can't
remember what version that was... Search for his modification to
SweepViruses.pm, or simply upgrade to the latest and see if that
helps...
As usual... I might be terribly wrong:-)

Cheers
-- 
-- Glenn
email: glenn < dot > steen < at > gmail < dot > com
work: glenn < dot > steen < at > ap1 < dot > se


More information about the MailScanner mailing list