Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 01-08-2010, 06:24 PM
Active Member
 
Posts: 32
Default [SOLVED] Every new message is flagged with Exploit.PDF-9669 - Nothing getting through

As of 3:30 this afternoon all messages started getting tagged with Exploit.PDF-9669 and quarantined. The server is 5.0.2_GA_1975.UBUNTU6. I ran some google searches for that message, but no luck.

Help.
Reply With Quote
  #2 (permalink)  
Old 01-08-2010, 07:29 PM
Member
 
Posts: 9
Default

I'm actually having the same issue, but have not found a solution yet.
Reply With Quote
  #3 (permalink)  
Old 01-08-2010, 07:36 PM
New Member
 
Posts: 3
Default

I'm having the same issue help!!!
Reply With Quote
  #4 (permalink)  
Old 01-08-2010, 07:40 PM
Starter Member
 
Posts: 1
Default Exploit.PDF-9669

We started at 3:30 pst as well - thought it was a server problem at first. After some digging, I found something that said that it had to do with HTML emails. After sever attemts at emailing myself and getting the message :

Attention! The message was sent with
VIRUS: Exploit.PDF-9669

I changed the email format from HTML to plain text and it went through.

So, is it a local virus on the users pc's? NOD32 doesn't seem to find it???
Reply With Quote
  #5 (permalink)  
Old 01-08-2010, 07:50 PM
Member
 
Posts: 9
Default

Ok, I found the issue.
Looks like it is related to clamav and I am guessing it's because of an update.
I edited /opt/zimbra/data/clamav/db/daily.inc/daily.hdb and removed the third from the last line that reads d41d8cd98f00b204e9800998ecf8427e:0:Exploit.PDF-9669

This so far has resolved my problem until the next freshclam update.
Older versions of zimbra might have the file in /opt/zimbra/clamav/data/db/daily.inc/daily.hdb
Reply With Quote
  #6 (permalink)  
Old 01-08-2010, 07:51 PM
Member
 
Posts: 9
Default

Just a note that removing this will cause it not to match if there is a virus. In my case the false positive is worse then someone getting the virus.
Just a warning, but this appears to be broken anyway so.....
Reply With Quote
  #7 (permalink)  
Old 01-08-2010, 07:53 PM
New Member
 
Posts: 3
Default Looks like a false positive to me

We have the same issue. When sending mail from Zimbra out to an external mail account neither our SPI firewall nor the AV filters at the receiving end are picking up anything. We've disabled the AV filter service in Zimbra and mail is now flowing as you'd expect.
Reply With Quote
  #8 (permalink)  
Old 01-08-2010, 07:55 PM
Member
 
Posts: 9
Default

I posted 2 other posts, but they are not appearing.
If they do, sorry for the duplicates.

I found the issue to be with clamav, most likely due to an update.
I edited /opt/zimbra/data/clamav/db/daily.inc/daily.hdb
and removed the line d41d8cd98f00b204e9800998ecf8427e:0:Exploit.PDF-9669 which was third from the bottom.

In older Zimbra installations it might be in /opt/zimbra/clamav/db/daily.inc/daily.hdb. You will need to restart zimbra or just the AV portion.
Reply With Quote
  #9 (permalink)  
Old 01-08-2010, 08:06 PM
Member
 
Posts: 9
Default

Ok, well, that posted.
Sorry for that if someone could just merge them into one that would be great. I tried several times to do a single response but they just disappeared.
Hope that helps.
Reply With Quote
  #10 (permalink)  
Old 01-08-2010, 08:16 PM
New Member
 
Posts: 3
Default Ask and you shall receive...

Quote:
Originally Posted by omniplex View Post
I will put it in parts.
Edit the file "/opt/zimbra/data/clamav/db/daily.inc/daily.hdb". Was the third from the last line for me. Restart Zimbra.

Quote:
Originally Posted by omniplex View Post
The line you want to remove should read "d41d8cd98f00b204e9800998ecf8427e:0:Exploit.PD F-9669"..
Thanks Omniplex... I think I'm going to wait and see if the next update of CLAM is better. Somehow I've got a sinking feeling that if I fix this now, I'll just fix it again after the next update.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.