>From /var/log/mail: Jun 30 03:38:28 diomedes clamav-milter[60071]: j5U0cN65081507: /var/tmp/clamav/msg.G8CVC4: HTML.Phishing.Bank-1 Intercepted virus from <[EMAIL PROTECTED]> to <[EMAIL PROTECTED]> Jun 30 03:38:28 diomedes clamav-milter[60071]: File quarantined as /var/tmp/clamav/050630/j5U0cN65081507.HTML.Phishing.Bank-1 Jun 30 03:38:28 diomedes clamav-milter[60071]: Quarantined infected mail as /var/tmp/clamav/050630/j5U0cN65081507.HTML.Phishing.Bank-1
The last two log lines provide the same more or less information, right? Or am I missing something? Tech-details follow, we are running ClamAV version 0.86.1, clamav-milter version 0.86 and clamav_milter_flags="-enNqd -m 75 -U /var/tmp/clamav" using clamd.conf: LogFile /var/log/clamav/clamd.log LogFileMaxSize 0 LogTime LogSyslog LogFacility LOG_MAIL PidFile /var/run/clamav/clamd.pid TemporaryDirectory /var/tmp/clamav-tmp DatabaseDirectory /var/db/clamav LocalSocket /var/run/clamav/clamd FixStaleSocket TCPAddr 127.0.0.1 MaxConnectionQueueLength 50 MaxThreads 30 User clamav AllowSupplementaryGroups ScanPE ScanOLE2 ScanMail ScanHTML ScanArchive ArchiveMaxCompressionRatio 1500 Regards, Panagiotis _______________________________________________ http://lurker.clamav.net/list/clamav-users.html