Thanks for the reply Dennis. The 'virus' is actually a Phishing
attempt from the 02/04 def update thats hitting on the logwatch email
here is the line from the clamd.log

Thu Feb  7 10:27:47 2008 ->
/var/spool/MailScanner/incoming/13948/29EC821AC463.28768.message:
Email.Phishing.RB-2646 FOUND

Is there any way to find out what that phishing item is hitting on?

Thanks!

On Feb 7, 2008 8:41 AM, Dennis Peterson <[EMAIL PROTECTED]> wrote:
>
> [EMAIL PROTECTED] wrote:
> > Hello list,
> >
> > I run a small mail server with clamd used to scan the incoming and
> > outgoing email. I recently noticed that I had stopped receiving my
> > logwatch daily digest. I looked into it and clam is stopping it
> > claiming its phishing. Is there any way to find out what part of the
> > email may be triggering this so I can change it in the logwatch
> > config?
> >
> > Sorry if this comes through as a dupe, the first I accidentally left
> > html formatting on.
> >
>
> Your clamd log should reveal the virus name found. Once you know that it
> may be possible to decode the pattern to discover what is being found in
> your logwatch mail. It may also be possible to instruct your system to
> not scan mail from logwatch.
>
> dp
> _______________________________________________
> Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
> http://lurker.clamav.net/list/clamav-users.html
>



-- 
Richard Ahlquist
Systems Analyst
http://www.patentlystupid.com
_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://lurker.clamav.net/list/clamav-users.html

Reply via email to