Jason Bennett wrote: > Hi everyone, > > We're using ClamAV on our mail gateway which is in front of our exchange > server. It's been running great for a long time and stops thousands of virus > per day for us. Lately however our McAfee which is installed on exchange > itself is picking up this virus: > > W32/Zhelatin.gen!eml > > It seems our ClamAV is not seeing it. We get a couple hundred of these a day > and they're all the same virus. > > Any ideas? > > Thanks for any help > > Jason
Zhelatin is the Email.Phishing.RB-1xxx If you are using amavisd-new you shoud give clamd with the full email message. @keep_decoded_original_maps = (new_RE( qr'^MAIL$', # retain full original message for virus checking )); _______________________________________________ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://lurker.clamav.net/list/clamav-users.html