Thanks for the reply Dennis. The 'virus' is actually a Phishing attempt from the 02/04 def update thats hitting on the logwatch email here is the line from the clamd.log
Thu Feb 7 10:27:47 2008 -> /var/spool/MailScanner/incoming/13948/29EC821AC463.28768.message: Email.Phishing.RB-2646 FOUND Is there any way to find out what that phishing item is hitting on? Thanks! On Feb 7, 2008 8:41 AM, Dennis Peterson <[EMAIL PROTECTED]> wrote: > > [EMAIL PROTECTED] wrote: > > Hello list, > > > > I run a small mail server with clamd used to scan the incoming and > > outgoing email. I recently noticed that I had stopped receiving my > > logwatch daily digest. I looked into it and clam is stopping it > > claiming its phishing. Is there any way to find out what part of the > > email may be triggering this so I can change it in the logwatch > > config? > > > > Sorry if this comes through as a dupe, the first I accidentally left > > html formatting on. > > > > Your clamd log should reveal the virus name found. Once you know that it > may be possible to decode the pattern to discover what is being found in > your logwatch mail. It may also be possible to instruct your system to > not scan mail from logwatch. > > dp > _______________________________________________ > Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net > http://lurker.clamav.net/list/clamav-users.html > -- Richard Ahlquist Systems Analyst http://www.patentlystupid.com _______________________________________________ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://lurker.clamav.net/list/clamav-users.html