I have two mail servers. One is used by users sending mail, the other receives mail. When a user sends me mail it goes through both servers. Both are running sendmail with clamav-milter and clamav. Normally I see the following header elements in such mail:

X-Virus-Scanned: clamd / ClamAV version 0.75.1, clamav-milter version 0.75c on zoon.lafn.org
X-Virus-Scanned: clamd / ClamAV version 0.75.1, clamav-milter version 0.75c on zoot.lafn.org


I have one user who has been trying for days to send me a message. He has not been able to tell me the error message he gets accuratly so I had no idea whtat was happening. However, today he got one through to me. It contains a virus, CHRISTM3.EXE. Now I know why he was having a hard time sending to me. However, he eventually succeeded. The message has the virus and no clamav headers from either system. There is quite a bit of time lag between when it was accepted by the send server and when it was accepted by the receive server so the send server must have kept trying over and over again till it managed to get it through. The lack of messages indicates that somehow it got through without invoking clam-milter. Any ideas how that could have occurred? I see no evidence of any significant mail loads during that time. The actual volume of mail was very low at that time. No system error were generated and no other evidence of other mail slipping through. Every message I check around them show the clamav headers and check messages in maillog.



-------------------------------------------------------
SF.Net email is sponsored by Shop4tech.com-Lowest price on Blank Media
100pk Sonic DVD-R 4x for only $29 -100pk Sonic DVD+R for only $33
Save 50% off Retail on Ink & Toner - Free Shipping and Free Gift.
http://www.shop4tech.com/z/Inkjet_Cartridges/9_108_r285
_______________________________________________
Clamav-users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/clamav-users

Reply via email to