virus

  1. C

    Better Protection against ransomware

    Recently we had a client that had a machine on their network get ransomware. The virus encrypted every computer on the network, including the Proxmox server. They are in a Windows environment so I am not 100% sure how it spread to Proxmox, but it did. Including to the backups stored on a...
  2. K

    Virus durch clamav erkannt aber nicht gefiltert.

    Hallo, ich habe jetzt den seltsamen Fall, dass eine (identifizierte) Phishing-Mail durchkam und nicht gefiltert wurde. Hier die entscheidenden Header-Zeilen: Oct 9 14:52:00 mailgw01 pmg-smtp-filter[32779]: 2141E6523F7707357F: virus detected: Heuristics.Phishing.Email.SpoofedDomain (clamav) Oct...
  3. S

    Nasty virus with an empty sender e-mail

    Hello! Today several users recieved an email with an empty sender and attached file 3282023.gz with 3282023.scr inside, I'm pretty sure it is a virus, because nobody really use or send screensavers anymore. :) I already set backscatter score to 3, but I guess it will also quarantine all...
  4. K

    detect one-note attachment abuse (malware)

    Hi, We are witness of one-Note attachment with .one file extension which execute payload using cmd & Power-shell when user tryied to open it from MS Outlook mail client. Can we detect & Block abuse contain inside of any one-note / document at Email Gateway ? We have remove attachment rule for...
  5. B

    How can I see why a virus was not detected ?

    Hi, I received a virus file with a .xz extension (a compressed file apparently) It was not blocked by ClamAV, all logs files of clamav are empty even if the virus filter is actived. For spam I can easily see in the original mail why it is blocked / not blocked but how can I do that for virus...
  6. S

    [SOLVED] Spam Quarantine master and slave didn't match

    Hello everybody, I've been checking on my cluster hardisk consumption and found that there is a significant different on Master and all slave server. Further check, I found that there is a different stored file inside /var/spool/pmg/cluster on Master and slave server. Here is from slave...
  7. 3

    Viewing Quarantined attachments?

    Hi everyone, I'm looking into implementing PMG for our business, currently in the testing stages. I have a quick question that I've not been able to find an answer too. Is there a way to view/download quarantined email attachments so they can be investigated further? This would be really...