Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 11-13-2008, 07:32 AM
Active Member
 
Posts: 37
Default Manually Scanning for Viruses

Hello everyone,

Recently, we have been hit with a large amount of viruses that have not been detected by clam. However, they are now reported. So, would it be possible to rescan the entire message database overnight with clam? That is: /opt/store.

I want to get rid of any residual viruses that got past our filter because people are still opening week-old emails and getting infected.

Here's what I found when I ran the following:
Code:
./clamscan -r -i -d /opt/zimbra/data/clamav/db /opt/zimbra/store/*
Here's a snippet of what was found:
Code:
/opt/zimbra/store/0/17/msg/3/13127-17639.msg: Email.Phishing.RB-3469 FOUND
/opt/zimbra/store/0/17/msg/3/12961-17451.msg: Email.Phishing.RB-3469 FOUND
/opt/zimbra/store/0/17/msg/3/13687-18288.msg: Trojan.Downloader.Agent-1297 FOUND
/opt/zimbra/store/0/17/msg/3/12776-17248.msg: Email.Phishing.Bank-72 FOUND
/opt/zimbra/store/0/17/msg/3/13757-18365.msg: Trojan.Downloader.Agent-1298 FOUND
/opt/zimbra/store/0/17/msg/3/13235-17757.msg: Trojan.Agent-57252 FOUND
Would it cause corruption if I had clamscan just remove the infected messages? Anyone have experience with this?

One other question: Does anyone know how to find out what virus definitions that clam is using to scan the incoming emails with?
When I type zmclamdctl status, it gives no output.

One additional thing to note: I upgraded to 0.94.1 and pointed the symlink "clamav" to the directory that I placed in /opt/zimbra.
__________________
cyberdeath

Last edited by cyberdeath; 11-13-2008 at 07:38 AM..
Reply With Quote
  #2 (permalink)  
Old 11-16-2008, 01:39 PM
Active Member
 
Posts: 37
Default Anti-Virus Not Working?

I went and checked to see today how the anti-virus software was doing and it's rarely detecting a virus. I know without a doubt the number of viruses has increased yet it's detecting less. I know that I upgraded to the new Clam version thinking that would solve the problem. But, it has not. Anyone have any suggestions or insight on this? I would greatly appreciate it.
__________________
cyberdeath
Reply With Quote
  #3 (permalink)  
Old 11-16-2008, 11:41 PM
Moderator
 
Posts: 7,928
Default

You could look at integrating a commercial AV scanner aswell into AmavisD. I would also recommend that you look at these third party signatures for Clam :- SaneSecurity
__________________
Reply With Quote
  #4 (permalink)  
Old 11-17-2008, 03:44 PM
Active Member
 
Posts: 37
Default

Well, I have considered that as well. But, I'm a bit curious as to why ClamAV isn't doing it's job. I've never had this problem before until recently. What prompted me was when I noticed that the database wasn't updating for whatever reason. That's when I upgraded the version of ClamAV. Would there be any reason why it would just stop updating? Also, upgrading ClamAV using the wiki should not cause any problems when upgrading zimbra later or with it properly scanning for viruses.

And, finally, here's my big question. Can I scan and remove the messages (.msg files) that contain malware? In other words, would that cause db/mbox corruption? Is there a way I should tackle this?

Thanks for the advice thus far .
__________________
cyberdeath
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.