I get 419 type messages with this subject periodically. When checked as they arrive they are not tagged by clamav, however, when running clamscan manually against them they are tagged by Steve's Email.Scam4.Gen260.Sanesecurity.06111302 FOUND
Would these headers have anything to do with it not being scanned when picked up? X-RocketYMUMID: AIsmvs4AAE4wRXFqywjtliQrJpw X-Apparently-To: [EMAIL PROTECTED] via 206.190.38.139; Sat, 02 Dec 2006 04:00:11 -0800 X-YahooFilteredBulk: 219.39.37.179 X-Originating-IP: [219.39.37.179] Return-Path: <[EMAIL PROTECTED]> Authentication-Results: mta543.mail.mud.yahoo.com from=TOKYO.UFJ.CO.JP; domainkeys=neutral (no sig) Received: from 219.39.37.179 (HELO mail.com) (219.39.37.179) by mta543.mail.mud.yahoo.com with SMTP; Sat, 02 Dec 2006 04:00:11 -0800 Reply-To: <[EMAIL PROTECTED]> From: "kobayashi" <[EMAIL PROTECTED]> Subject: KOBAYASHI AKIRA Date: Fri, 1 Dec 2006 20:59:49 -0800 MIME-Version: 1.0 Content-Type: text/plain; charset="Windows-1251" Content-Transfer-Encoding: 7bit X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2600.0000 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000 X-Antivirus: avast! (VPS 0652-6, 12/01/2006), Outbound message X-Antivirus-Status: Clean X-FetchYahoo: version 2.10.4 MsgId 5589_1170604_62670_1281_471_0_203899_-1_0 X-SenderIP: 219.39.37.179 X-ASN: ASN-17676 X-CIDR: 219.0.0.0/10 Clam is called via a spamassassin plugin if it matters. -- Chris http://learn.to/quote
pgpXYTWm2w4zF.pgp
Description: PGP signature
_______________________________________________ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://lurker.clamav.net/list/clamav-users.html