I'm a bit confused, sometimes that's not hard to do. I'm running the
ClamAv plugin with SpamAssassin and one spam was marked with the above
virus. When saving just the infected attachment and running

[ch...@localhost Virus]$ clamdscan - <UPS_Label_512.zip
fd[12]: OK

----------- SCAN SUMMARY -----------
Infected files: 0
Time: 0.187 sec (0 m 0 s)

I get the same when running it against the .exe within the zip

[ch...@localhost Virus]$ clamdscan - < UPS_Label_512.exe
fd[12]: OK

----------- SCAN SUMMARY -----------
Infected files: 0
Time: 0.047 sec (0 m 0 s)

However, if I save the complete spam message and run clamdscan against
it

[ch...@localhost Virus]$ clamdscan - <spam2.txt
fd[12]: Email.Trojan.GZC FOUND

----------- SCAN SUMMARY -----------
Infected files: 1
Time: 0.191 sec (0 m 0 s)

Is there a reason behind this?

-- 
KeyID 0xE372A7DA98E6705C

Attachment: signature.asc
Description: This is a digitally signed message part

_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml

Reply via email to