Re: encrypted zips / sophie
David Broome <[email protected]> Tue, 6 Apr 2004 17:01:02 -0700 (PDT)
| Newsgroups | gmane.comp.security.virus.vtools |
|---|---|
| Message-ID | <[email protected]> |
Interesting ... Do have the "W32/Bagle-Zip" ide file and current sophos? - just thinking of the basics. ;-) I'm rejecting hundreds a day. Dave, -- David Broome Senior_Programmer-Analyst.FineArts.UVic.CA /BSc 250.721-6307 [email protected] FIA 221 On Tue, 6 Apr 2004, Jim Savoy wrote: > > Hi people, > > Still struggling with this. I changed all of the Grp flags in > sophie.savi > from '2' to '1' and changed Mime from '0' to '1'. I also added Ed's code > to sophie_core.c and recompiled. > > But when I run this: > > # ./sophie -f /tmp/virus.txt (where virus.txt contains the Bagle-H worm) > > the results are (here's the tail end of them): > > Sophie version : 3.04rc2 > NOTICE : Scanning file '/tmp/virus.txt' > NOTICE : pSAVI cleaned up and released/terminated > NOTICE : SAVI cleaned up and terminated > > > Shouldn't this display that it found the Bagle-H or Bagle-Zip? > As I mentioned this morning, I have thousands of infected mailboxes > and wish to clean them all out tonight using sophie. But the results of > this test seem to indicate it is still not detecting anything. Any ideas? > Thanks! > > - jim - > > > > _______________________________________________ > vtools mailing list > [email protected] > http://www.vanja.com/list/listinfo.cgi/vtools >