9.006-5 pattern version 44587 2013:04:14-11:47:44 acka httpproxy[4256]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="saviscanner_log" file="saviscanner.c" line="153" message="Reloading SAVI threat data" 2013:04:14-11:47:56 acka httpproxy[4256]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="saviscanner_log" file="saviscanner.c" line="153" message="ERROR: Failed to load Sophos Anti-Virus threat data [0x8004022d]" 2013:04:14-11:47:56 acka httpproxy[4256]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="saviscanner_log" file="saviscanner.c" line="153" message="Reloading SAVI threat data finished, engine 3.41.0, threat data 4.87 from 13/3/2013 (4539783 detected threats)" 2013:04:14-11:53:18 acka httpproxy[4256]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0x137ff868" function="savi_scan" file="saviscanner.c" line="83" message="SAVI engine scan failed: Unknown SAVI error [0x8004022f] (-1)" 2013:04:14-11:53:18 acka httpproxy[4256]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0x137e9be0" function="savi_scan" file="saviscanner.c" line="83" message="SAVI engine scan failed: Unknown SAVI error [0x8004022f] (-1)" 2013:04:14-11:53:18 acka httpproxy[4256]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0x137ffcd0" function="savi_scan" file="saviscanner.c" line="83" message="SAVI engine scan failed: Unknown SAVI error [0x8004022f] (-1)" 2013:04:14-11:53:18 acka httpproxy[4256]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="GET" srcip="10.0.1.83" dstip="205.200.78.80" user="" statuscode="500" cached="0" profile="REF_DefaultHTTPProfile (Default Proxy)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="2679" request="0x137ffcd0" url="http://www.msftncsi.com/ncsi.txt" exceptions="" error="" category="105,175" reputation="neutral" categoryname="Business,Software/Hardware" content-type="text/plain" application="http" 2013:04:14-11:53:18 acka httpproxy[4256]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="GET" srcip="10.0.1.83" dstip="205.200.78.77" user="" statuscode="500" cached="0" profile="REF_DefaultHTTPProfile (Default Proxy)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="2723" request="0x137e9be0" url="http://www.manoramaonline.com/cgi-bin/MMOnline.dll/portal/ep/home.do?tabId=0" exceptions="" error="" category="134" reputation="neutral" categoryname="General News" content-type="text/html" application="http" 2013:04:14-11:53:18 acka httpproxy[4256]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="POST" srcip="10.0.1.83" dstip="" user="" statuscode="500" cached="0" profile="REF_DefaultHTTPProfile (Default Proxy)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="3033" request="0x137ff868" url="http://tools.google.com/service/update2?w=6:CXC-I6nqvI8CVh--XXFLP8khz7Vd9Cb07fAyLzxxibd_V4TZ56UkJpUopdvRpXLaT4YkrjDdHfXPcC6BW6KcdlbBjZuQnnEpAWl2xG-_aOYRI2kXpurBnXdZXJfstdi4u1XWJ3wCEo3MyG1MWKIlgZCUEF9gBZqm6lJj47Pdp_XBqGuqLjkCbPgd9XURnOFLuIMx-LdThYVz7Cmh3j7nROMkZ9rk2-Y6-vH1REW_8iuGUhHUqn_HwvOrPg3gdlJdiRho2RxVCQzZzIdlZ5K1gL4US6sm8y2i4vy2DllRIu8YekvoaoKoBON9UgewcZHOkDGat6qm2SK8bw_QDE3Mnw" exceptions="" error="" reputation="neutral" category="148" reputation="neutral" categoryname="Shareware/Freeware" 2013:04:14-11:53:27 acka httpproxy[4256]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0x137ff868" function="savi_scan" file="saviscanner.c" line="83" message="SAVI engine scan failed: Unknown SAVI error [0x8004022f] (-1)" 2013:04:14-11:54:21 acka httpproxy[4256]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0x1363fb00" function="savi_scan" file="saviscanner.c" line="83" message="SAVI engine scan failed: Unknown SAVI error [0x8004022f] (-1)" 2013:04:14-12:45:36 acka httpproxy[4272]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="scanner_init" file="saviscanner.c" line="171" message="SAVI init failed: One of the files in a split-virus data set has the wrong checksum [0x8004022f]" 2013:04:14-12:45:57 acka httpproxy[4272]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="main" file="httpproxy.c" line="302" message="finished startup" 2013:04:14-12:46:07 acka httpproxy[4272]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="confd_config_reload_func" file="confd-client.c" line="700" message="reloading config" 2013:04:14-12:46:29 acka httpproxy[4272]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="parse_address" file="util.c" line="567" message="getaddrinfo: passthrough.fw-notify.net: Temporary failure in name resolution" 2013:04:14-12:46:29 acka httpproxy[4272]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="confd_config_filter" file="confd-client.c" line="2509" message="failed to resolve passthrough.fw-notify.net, using 213.144.15.19" 2013:04:14-12:46:49 acka httpproxy[4272]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="parse_address" file="util.c" line="567" message="getaddrinfo: passthrough6.fw-notify.net: Temporary failure in name resolution" 2013:04:14-12:46:49 acka httpproxy[4272]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="confd_config_filter" file="confd-client.c" line="2513" message="failed to resolve passthrough6.fw-notify.net, using 2a01:198:200:680::8080" 2013:04:14-12:46:51 acka httpproxy[4272]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="confd_config_reload_func" file="confd-client.c" line="736" message="reloading config done, new version 3" 2013:04:14-12:47:43 acka httpproxy[4272]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="10.0.1.82" dstip="64.4.11.25" user="" statuscode="302" cached="0" profile="REF_DefaultHTTPProfile (Default Proxy)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="188" request="0x860c6c8" url="http://go.microsoft.com/fwlink/?LinkID=149408" exceptions="av,fileextension" error="" category="105,175" reputation="trusted" categoryname="Business,Software/Hardware" content-type="text/html" application="http" 2013:04:14-12:47:44 acka httpproxy[4272]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0x860cca8" function="savi_scan" file="saviscanner.c" line="51" message="failed to get SAVI instance: no saviglue context [0x00000000]" 2013:04:14-12:47:44 acka httpproxy[4272]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="POST" srcip="10.0.1.82" dstip="" user="" statuscode="500" cached="0" profile="REF_DefaultHTTPProfile (Default Proxy)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="2722" request="0x860cca8" url="http://services.wmdrm.windowsmedia.com/SecureClock/VISTA_RTM/?Time" exceptions="" error="" reputation="trusted" category="112" reputation="trusted" categoryname="Entertainment" 2013:04:14-12:48:47 acka httpproxy[4272]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="10.0.1.82" dstip="64.4.11.25" user="" statuscode="302" cached="0" profile="REF_DefaultHTTPProfile (Default Proxy)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="188" request="0x865c3a8" url="http://go.microsoft.com/fwlink/?LinkID=149408" exceptions="av,fileextension" error="" category="105,175" reputation="trusted" categoryname="Business,Software/Hardware" content-type="text/html" application="http" 2013:04:14-12:48:49 acka httpproxy[4272]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0x865c988" function="savi_scan" file="saviscanner.c" line="51" message="failed to get SAVI instance: no saviglue context [0x00000000]" 2013:04:14-12:48:49 acka httpproxy[4272]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="POST" srcip="10.0.1.82" dstip="" user="" statuscode="500" cached="0" profile="REF_DefaultHTTPProfile (Default Proxy)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="2722" request="0x865c988" url="http://services.wmdrm.windowsmedia.com/SecureClock/VISTA_RTM/?Time" exceptions="" error="" reputation="trusted" category="112" reputation="trusted" categoryname="Entertainment"