http://www.d3adlin3.8k.com/ The site didn't try to load any virus or activate any trojan that I could detect. The worm spreads itself via infected e-mail attachments in e-mails with a spoofed sender address. Right now, the QMAILQUEUE env variable is set to qmail-localfilter.sh, which calls qmail-localfilter.pl Here are those scripts.

my QS looks like this now,=20 if (&single_recip($recips)) { open(SA,"$spamc_binary $spamc_options -u \"$recips\" < $scandir/$wmaildir/new/$file_id|")||&tempfail("cannot run $spamc_binary < $scandir/$wmaildir/new/$file_id - $!");

Salvatore [Qmail-scanner-general]Qmail-scanner + SpamAssassin / domain-specific filters/databases From: Brian Ipsen - 2003-08-27 16:13:59 Hi! So far so good!!

my qmail-scanner queue is filling up = fast with messages and the logfile says: Aug 27 21:05:23 dude qmail-scanner[23499]: Clear:RC:1:SA:0(0.5/5.0): = 0.442984 179 <> <> <> <> 1062011122.23501-0.dude:0=20 Aug 27 21:05:25 [email protected] is a mass-mailing, network-aware worm that sends itself to all the email addresses it finds in the files that have the following extensions: .dbx .eml .hlp .htm .html .mht .wab The aforementioned de-activation date applies only to the mass-mailing, network propagation, and email address collection routines.

Earlier versions of Sobig have executed similar but simpler routines. return if (defined($ENV{'RELAYCLIENT'}) && !defined($ENV{'QS_SPAMASSASSIN'})); #SpamAssassin client scanner my ($spamassassin_found,$spamassassin_status); my ($start_spamassassin_time)=3D[gettimeofday]; my ($DD,$spamassassin_status,$stop_spamassassin_time,$spamassassin_time); my ($sa_status)=3D0; my ($sa_score)=3D0; my ($sa_max)=3D0; &debug("SA: run $spamc_binary $spamc_options < $scandir/$wmaildir/new/$file_id"); open(SA,"$spamc_binary $spamc_options < $scandir/$wmaildir/new/$file_id|")||&tempfail("cannot run Tyler ----- Original Message ----- From: "Tyler" To: Sent: Monday, August 25, 2003 11:16 PM Subject: [Qmail-scanner-general]Spam Assassin Scripts > Hello All, > > I was curious how to

users should not send executable content via email anyhow. http://www.engelken.net/code/SA-2.55-perdomain.patch this will allow you to pull global, per-domain, or per-user settings out of SQL.

  _______________________________________________ > Qmail-scanner-general mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general

By now, your computer should be completely free of W32/SobigF-Dam infection. dallas RE: [Qmail-scanner-general]performance issue From: Dallas L.

I wouldn't bet that F-Secure's crack team of geniuses can easily crack a Rot13 cypher. Sending standard test message - no viruses...

The new model uses a local application launcher to start the main HouseCall application. However, the concept it was using is a new idea on a typical virus/trojan. By the time we get a copy of the file, the infected computers have already downloaded and run it". done!

qmailscan]# tail qmail-queue.log Wed, 27 Aug 2003 13:24:03 -0400:24929: w_c: primary Content-Type of text/plain found Wed, 27 Aug 2003 13:24:03 -0400:24929: w_c: rename new msg from /var/spool/qmailscan/working/tmp/chopin106200504345524929 to /var/spool/qmailscan/working/new/chopin106200504345524929 [1062005043.18514] Wed, done!

Please let me know how I can integrate these with qmail-scanner. i can't get any grip on this. Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] I'll try and parse the maillog file later today to see which ones ClamAV missed that Although, I didn't install Spamassassin prior to the qmail-scanner it didn't install the sub-spamassassin.pl at the bottem.

they handle things in completely opposite ways. F-Secure Anti-Virus Command line client version: F-Secure Anti-Virus for Linux version 4.51 build 2312 F-Secure Anti-Virus Daemon version: F-Secure Anti-Virus for Linux version 4.51 build 2312 Scanner Engine versions: Frisk Software