Some Mydoom infected mail passing through MailScanner

Plant, Dean dean.plant at ROKE.CO.UK
Tue Jan 27 11:00:40 GMT 2004

Hello list,

I have a problem with some copies of Mydoom infected mail still being
delivered even though MailScanner has correctly detected the virus. I am
using version 4.21-9 with sendmail, f-prot, clamav on Redhat 8. Is this a
bug that is fixed in a later version of MailScanner?

Below is a MailWatch report of one of the delivered infected mails.


Dean Plant. 

Received on: 27/01/04 09:41:19 
Received by: rsys001x 
Received from: ( - Check in OpenRBL  
ID: i0R9f8Ud006179 
Message Headers: Return-Path: <g>
Received: from ( [])
by (8.12.8/8.12.8) with ESMTP id i0R9f8Ud006179
for <xxx at>; Tue, 27 Jan 2004 09:41:08 GMT
Message-Id: <200401270941.i0R9f8Ud006179 at>
From: jose at
To: xxx at
Subject: Test
Date: Tue, 27 Jan 2004 09:41:08 +0000
MIME-Version: 1.0
Content-Type: multipart/mixed;
X-Priority: 3
X-MSMail-Priority: Normal 
From: jose at 
To: xxx at 
Subject: Test 
Size: 31.3Kb 
Virus:  Y  
Blocked File:  N  
Other Infection:  N  
Report: F-Prot:
txt Infection: W32/Mydoom.A at mm ClamAV: contains Worm.SCO.A 
Spam:  Y   Action(s): store, attachment, deliver 
High Scoring Spam:  N  
Listed in RBL:  N  
Whitelisted:  N  
SpamAssassin Spam:  Y  
SpamAssassin Score: 9.52 
Spam Report: -1.52 BAYES_01   
2.91 DCC_CHECK   
0.16 NO_REAL_NAME   
1.10 RAZOR2_CF_RANGE_51_100   

Registered Office: Roke Manor Research Ltd, Siemens House, Oldbury, Bracknell,
Berkshire. RG12 8FZ

The information contained in this e-mail and any attachments is confidential to
Roke Manor Research Ltd and must not be passed to any third party without
permission. This communication is for information only and shall not create or
change any contractual relationship.

More information about the MailScanner mailing list