tons of infected files getting though???

Chris Yuzik chris at FRACTALWEB.COM
Tue Jan 27 19:22:38 GMT 2004

Hi everyone,

I was having a hard look through my logs and such and also looking
though MailWatch. I see quite a few emails that definitely contain the
virus that were only tagged as spam. I can see nothing in
/var/log/maillog that indicates why this message would not have been
marked as infected. I've even forwarded a couple of them to myself and
there's no doubt about's the SCO.A or Navarg or whatever. If I
save the attachment, then scp it to my mailserver and run clamscan on
it, everything works great and ClamAV correctly identifies the virus.

For yesterday alone, my system saw 106 messages that it found infected
with the virus, and an additional 80 that slipped by. WTF???

Is it possible that MailScanner isn't getting clamav to scan all the
attachments? How do I go about troubleshooting this? Urgent help would
be appreciated.


