I'm a bit confused, sometimes that's not hard to do. I'm running the ClamAv plugin with SpamAssassin and one spam was marked with the above virus. When saving just the infected attachment and running
[ch...@localhost Virus]$ clamdscan - <UPS_Label_512.zip fd[12]: OK ----------- SCAN SUMMARY ----------- Infected files: 0 Time: 0.187 sec (0 m 0 s) I get the same when running it against the .exe within the zip [ch...@localhost Virus]$ clamdscan - < UPS_Label_512.exe fd[12]: OK ----------- SCAN SUMMARY ----------- Infected files: 0 Time: 0.047 sec (0 m 0 s) However, if I save the complete spam message and run clamdscan against it [ch...@localhost Virus]$ clamdscan - <spam2.txt fd[12]: Email.Trojan.GZC FOUND ----------- SCAN SUMMARY ----------- Infected files: 1 Time: 0.191 sec (0 m 0 s) Is there a reason behind this? -- KeyID 0xE372A7DA98E6705C
signature.asc
Description: This is a digitally signed message part
_______________________________________________ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net http://www.clamav.net/support/ml