Community Discussions and Support
ClamWall, how to ban zipped EXE files

[quote user="Thomas R. Stephenson"]

What you really need to do is have your Pegasus Mail users use the Virscan extension to scan the file when opened with your a-v program of choice.

[/quote]

I agree that Virscan, where practical, is the way to go. 

 The caveats:  Some command line scanners are slow and/or intrusiveness.  This can be

tolerated in low email environments or in environments where attachments are the exception but in environments where attachments are routine the attachment scanning can

be a productivity killer.  Some command line scanners are not designed to scan a single file so will not work with Virscan.  Vipre has one of those.  

[quote user="Thomas R. Stephenson"]<div>What you really need to do is have your Pegasus Mail users use the Virscan extension to scan the file when opened with your a-v program of choice.</div><p>[/quote]</p><p>I agree that Virscan, where practical, is the way to go.  </p><p> The caveats:  Some command line scanners are slow and/or intrusiveness.  This can be tolerated in low email environments or in environments where attachments are the exception but in environments where attachments are routine the attachment scanning can be a productivity killer.  Some command line scanners are not designed to scan a single file so will not work with Virscan.  Vipre has one of those.   </p>

==== 

 sorry, should have been posted in Mercury forums

====

 

Hi,

 I'd like to configure ClamWall to ban e-mails with ZIP files that contain EXE files (or other dangerous file types).

Any tips on how to do that?

Thanks

Ron

<P>==== </P> <P> sorry, should have been posted in Mercury forums</P> <P>====</P> <P mce_keep="true"> </P> <P>Hi,</P> <P> I'd like to configure ClamWall to ban e-mails with ZIP files that contain EXE files (or other dangerous file types).</P> <P>Any tips on how to do that?</P> <P>Thanks</P> <P>Ron</P>

In mercury

click on "Configuration"

Click on "Clamwall"

Click the "basic settings" tab

enter in all the extensions you want banned.

These are the ones i have entered.

ADE,ADP,ASP,BAS,BAT,CHM,CMD,COM,CPL,CRT,EXE,HLP,HTA,INF,INS,ISP,JSE,MSC,MSI,MSP,MST,PCD,SCT,SHB,SHS,VB,VBE,WS,VBS,PIF,SCR,REG,SHS,WS,WSC,WSF,WSH

<p>In mercury </p><p>click on "Configuration"</p><p>Click on "Clamwall"</p><p>Click the "basic settings" tab</p><p>enter in all the extensions you want banned.</p><p>These are the ones i have entered.</p><p>ADE,ADP,ASP,BAS,BAT,CHM,CMD,COM,CPL,CRT,EXE,HLP,HTA,INF,INS,ISP,JSE,MSC,MSI,MSP,MST,PCD,SCT,SHB,SHS,VB,VBE,WS,VBS,PIF,SCR,REG,SHS,WS,WSC,WSF,WSH </p>

Clamwall doesn't appear to look at the extensions of files inside of .zip attachments.  I have .exe as a banned extension but .exe's inside of .zip attachments are getting through.

I had a recent infection which was the result of a user running a .exe from inside of a .zip.  It got past ClamAV so either the virus def for ClamAV was inadequate or ClamAV isn't checking .zip attachments.  I can't exclusively fault ClamAV though.  I have Vipre for local protection and it didn't detect until after the infection had taken over the PC.

<p>Clamwall doesn't appear to look at the extensions of files inside of .zip attachments.  I have .exe as a banned extension but .exe's inside of .zip attachments are getting through.</p><p>I had a recent infection which was the result of a user running a .exe from inside of a .zip.  It got past ClamAV so either the virus def for ClamAV was inadequate or ClamAV isn't checking .zip attachments.  I can't exclusively fault ClamAV though.  I have Vipre for local protection and it didn't detect until after the infection had taken over the PC. </p>

> Clamwall doesn't appear to look at the extensions of files inside of
> .zip attachments.  I have .exe as a banned extension but .exe's inside
> of .zip attachments are getting through. 
>
> I had a recent infection which was the result of a user running a .exe
> from inside of a .zip.  It got past ClamAV so either the virus def for
> ClamAV was inadequate or ClamAV isn't checking .zip attachments.  I
> can't exclusively fault ClamAV though.  I have Vipre for local
> protection and it didn't detect until after the infection had taken
> over the PC. 

One of the problem with this is that sending of an EXE file in a zipped file is about the only way you can send a program anymore.  If your anti-virus system blocked the programs in a ZIP archive you'd never get any valid programs sent as an attachment. You can of course block all ZIP files and then the postmaster can handle this but that would be a real pain in the rear.  
 
What you really need to do is have your Pegasus Mail users use the Virscan extension to scan the file when opened with your a-v program of choice.
 
Name of Program: VIRSCAN: Virus Scanning Extension for Pegasus Mail 

Location/Filename <URL:mailto:irelam@telus.net?Subject=send_virscan> 
<URL:http://www3.telus.net/public/irelam/> 

Author/email contact: Martin Ireland <irelam@telus.net> 

Status: Freeware 

Documentation: Included in zip file.

Features: Extension to invoke virus scanning program of user choice when Pegasus Mail saves or views mail message attachments. 

Defaults to NAI's VirusScan engine. Multi-language support included.  
 
 

&lt;div&gt;&amp;gt; Clamwall doesn&#039;t appear to look at the extensions of files inside of&lt;/div&gt;&lt;div&gt;&amp;gt; .zip attachments. &amp;nbsp;I have .exe as a banned extension but .exe&#039;s inside&lt;/div&gt;&lt;div&gt;&amp;gt; of .zip attachments are getting through.&amp;nbsp;&lt;/div&gt;&lt;div&gt;&amp;gt;&lt;/div&gt;&lt;div&gt;&amp;gt; I had a recent infection which was the result of a user running a .exe&lt;/div&gt;&lt;div&gt;&amp;gt; from inside of a .zip. &amp;nbsp;It got past ClamAV so either the virus def for&lt;/div&gt;&lt;div&gt;&amp;gt; ClamAV was inadequate or ClamAV isn&#039;t checking .zip attachments. &amp;nbsp;I&lt;/div&gt;&lt;div&gt;&amp;gt; can&#039;t exclusively fault ClamAV though. &amp;nbsp;I have Vipre for local&lt;/div&gt;&lt;div&gt;&amp;gt; protection and it didn&#039;t detect until after the infection had taken&lt;/div&gt;&lt;div&gt;&amp;gt; over the PC.&amp;nbsp;&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;One of the problem with this is that sending of an EXE file in a zipped file is about the only way you can send a program anymore. &amp;nbsp;If your anti-virus system blocked the programs in a ZIP archive you&#039;d never get any valid programs sent as an attachment. You can of course block all ZIP files and then the postmaster can handle this but that would be a real pain in the rear. &amp;nbsp;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;What you really need to do is have your Pegasus Mail users use the Virscan extension to scan the file when opened with your a-v program of choice.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Name of Program: VIRSCAN: Virus Scanning Extension for Pegasus Mail&amp;nbsp;&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;Location/Filename &amp;lt;URL:mailto:irelam@telus.net?Subject=send_virscan&amp;gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;&amp;lt;URL:http://www3.telus.net/public/irelam/&amp;gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;Author/email contact: Martin Ireland &amp;lt;irelam@telus.net&amp;gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;Status: Freeware&amp;nbsp;&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;Documentation: Included in zip file.&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;Features: Extension to invoke virus scanning program of user choice when Pegasus Mail saves or views mail message attachments.&amp;nbsp;&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;Defaults to NAI&#039;s VirusScan engine. Multi-language support included. &amp;nbsp;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt; &lt;/div&gt;
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft