ClamAV is happily scanning all my incoming mail. However, it never finds a virus. I have tested it with known viruses, I have scanned suspect mail that arrived with a local virus scanner on my Mac and found viruses that slipped by and I have used on-line virus tests to send test files. Everything gets by. Here are the logs for the last virus that got by:

15:56:33.41 2 SMTPI-09049([142.167.32.168]) [490316] received, 18460 bytes
15:56:33.42 2 QUEUE([490316]) from <[EMAIL PROTECTED]>, 18460 bytes (<[EMAIL PROTECTED]>)
15:56:33.42 2 ENQUEUERRULES [490316] rule(ClamAV) action #0: added header 'X-VirusScan-2: SUBMITTED'
15:56:33.42 4 EXTFILTER(cgpav) out(26): 128 FILE Queue/490316.msg\n
15:56:33.44 4 EXTFILTER(cgpav) inp(6): 128 OK
15:56:33.44 4 EXTFILTER(PolluStop) out(26): 168 FILE Queue/490316.msg\n
15:56:33.45 4 EXTFILTER(PolluStop) inp(163): 168 ADDHEADER "X-PolluStop-Diagnostic: \eX-PolluStop-Score: 0.00\eX-PolluStop: Scanned with Niversoft PolluStop 2.0 public RC3, http://www.niversoft.com/po
15:56:33.45 4 EXTFILTER(PolluStop) [490316] header added: X-PolluStop-Diagnostic: \nX-PolluStop-Score: 0.00\nX-PolluStop: Scanned with Niversoft PolluStop 2.0 public RC3, http://www.niversoft.com/poll
15:56:33.45 4 EXTFILTER(FindAttach) out(26): 261 FILE Queue/490316.msg\n
15:56:33.46 4 EXTFILTER(FindAttach) inp(76): 261 ADDHEADER "X-AttachExt: pif\eX-ExtScanner: Niversoft's Find_Attachments"
15:56:33.46 4 EXTFILTER(FindAttach) [490316] header added: X-AttachExt: pif\nX-ExtScanner: Niversoft's Find_Attachments
15:56:33.46 2 ENQUEUER-01([490316]) enqueued
15:56:33.46 2 LOCALRULES(chad) [490316] rule(Dangerous Attachment) action #0: added header 'X-Attachment: POTENTIALLY DANGEROUS'
15:56:33.46 2 LOCALRULES(chad) [490316] rule(Dangerous Attachment) action #1: added header 'X-Color: red'
15:56:33.48 2 MAILBOX(chad/Suspicious Extensions) {23} appended: 18633(313) bytes, 272 lines
15:56:33.48 2 MAILBOX(chad/Suspicious Extensions) [490316] stored as 23
15:56:33.48 2 LOCALRULES(chad) [490316] rule(Dangerous Attachment) message stored in 'Suspicious Extensions'
15:56:33.49 2 LOCALRULES(chad) [490316] rule 'Dangerous Attachment'(React) -> [490312]
15:56:33.49 2 LOCALRULES(chad) [490316] rule(Dangerous Attachment) discarded the message
15:56:33.49 2 ACCOUNT(chad) [490316] delivered
15:56:33.49 2 DEQUEUER [490316] LOCAL(chad) delivered



However, when I have Clamscan test the install directory for clamav for virus, it find the 6 or so test files that are supposed to show up as infected. I do not think I have .pif listed specifically as an extension in the clamav.conf settings files but do I need to list each potential extension there or should it scan all files anyway?




-------------------------------------------------------
This SF.Net email is sponsored by The 2004 JavaOne(SM) Conference
Learn from the experts at JavaOne(SM), Sun's Worldwide Java Developer
Conference, June 28 - July 1 at the Moscone Center in San Francisco, CA
REGISTER AND SAVE! http://java.sun.com/javaone/sf Priority Code NWMGYKND
_______________________________________________
Clamav-users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/clamav-users

Reply via email to