Problem with F-Secure Server version 7?

Henriks Maillists hb.maillists at dfs.dk
Thu May 1 11:41:15 IST 2008


Does anyone have F-Secure Linux Server Security version 7.0 running with 
MailScanner.

MailScanner --lint detects the eicar virus with both F-Secure and ClamAV. 
When I relay a message with virus it is not detected by F-Secure.

MailScanner does not stop it. (ClamAV does not know the virus - have 
submitted it)

-------------------------------------------------------------------------------------------------------
Testing from the commandline:
F-Secure Security Platform version 2.00  build 7161
Copyright (c) 1999-2008 F-Secure Corporation. All Rights Reserved.
Scan started at Thu May  1 12:36:56 2008
Database version: 2008-05-01_01
[/root/certificado-2.25.rar] certificado-2.25.exe: Infected: 
Trojan-Downloader.Win32.Banload.lpy [AVP]
Scan ended at Thu May  1 12:36:56 2008
1 file scanned
1 file infected

-------------------------------------------------------------------------------------------------------
MailScanner --lint output this: (eset is not active!)
MailScanner.conf says "Virus Scanners = f-secure clamavmodule"
Found these virus scanners installed: clamavmodule, f-secure, esets
===========================================================================
Virus and Content Scanning: Starting
Found F-Secure version 2.00=2
Scan ended at Thu May  1 12:35:52 2008
2 files scanned
1 file infected
ProcessClamAVModOutput ClamAVModule
ClamAVModule::INFECTED:: Eicar-Test-Signature:: ./1/
ProcessClamAVModOutput ClamAVModule
ProcessClamAVModOutput ClamAVModule
ClamAVModule::INFECTED:: Eicar-Test-Signature:: ./1/eicar.com
Virus Scanning: ClamAVModule found 2 infections
Infected message 1 came from 10.1.1.1
Virus Scanning: Found 2 viruses
Filename Checks:  (1 eicar.com)
Other Checks: Found 1 problems
===========================================================================
Virus Scanner test reports:
ClamAVModule said "eicar.com was infected: Eicar-Test-Signature"
If any of your virus scanners (clamavmodule,f-secure,esets)
are not listed there, you should check that they are installed correctly
and that MailScanner is finding them correctly via its virus.scanners.conf.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20080501/3f07472d/attachment.html


More information about the MailScanner mailing list