Problem with F-Secure Server version 7?

Julian Field MailScanner at ecs.soton.ac.uk
Thu May 1 15:42:31 IST 2008


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Sorry, no-one has ever given me anything newer than 5.54, so I have 
never had a chance to incorporate support for 7.0.
If you send me a fully-licenced copy of 7.0 (off-list, it will only be 
used for MailScanner development and won't leak out) I will try to write 
support for it for you.

Jules.

Henriks Maillists wrote:
> Does anyone have F-Secure Linux Server Security version 7.0 running 
> with MailScanner.
>
> MailScanner --lint detects the eicar virus with both F-Secure and 
> ClamAV. When I relay a message with virus it is not detected by F-Secure.
>
> MailScanner does not stop it. (ClamAV does not know the virus - have 
> submitted it)
>
> -------------------------------------------------------------------------------------------------------
> Testing from the commandline:
> F-Secure Security Platform version 2.00  build 7161
> Copyright (c) 1999-2008 F-Secure Corporation. All Rights Reserved.
> Scan started at Thu May  1 12:36:56 2008
> Database version: 2008-05-01_01
> [/root/certificado-2.25.rar] certificado-2.25.exe: Infected: 
> Trojan-Downloader.Win32.Banload.lpy [AVP]
> Scan ended at Thu May  1 12:36:56 2008
> 1 file scanned
> 1 file infected
>
> -------------------------------------------------------------------------------------------------------
> MailScanner --lint output this: (eset is not active!)
> MailScanner.conf says "Virus Scanners = f-secure clamavmodule"
> Found these virus scanners installed: clamavmodule, f-secure, esets
> ===========================================================================
> Virus and Content Scanning: Starting
> Found F-Secure version 2.00=2
> Scan ended at Thu May  1 12:35:52 2008
> 2 files scanned
> 1 file infected
> ProcessClamAVModOutput ClamAVModule
> ClamAVModule::INFECTED:: Eicar-Test-Signature:: ./1/
> ProcessClamAVModOutput ClamAVModule
> ProcessClamAVModOutput ClamAVModule
> ClamAVModule::INFECTED:: Eicar-Test-Signature:: ./1/eicar.com
> Virus Scanning: ClamAVModule found 2 infections
> Infected message 1 came from 10.1.1.1
> Virus Scanning: Found 2 viruses
> Filename Checks:  (1 eicar.com)
> Other Checks: Found 1 problems
> ===========================================================================
> Virus Scanner test reports:
> ClamAVModule said "eicar.com was infected: Eicar-Test-Signature"
> If any of your virus scanners (clamavmodule,f-secure,esets)
> are not listed there, you should check that they are installed correctly
> and that MailScanner is finding them correctly via its 
> virus.scanners.conf.

Jules

- -- 
Julian Field MEng CITP CEng
www.MailScanner.info
Buy the MailScanner book at www.MailScanner.info/store

Need help customising MailScanner?
Contact me!
Need help fixing or optimising your systems?
Contact me!
Need help getting you started solving new requirements from your boss?
Contact me!

PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654


-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.8.2 (Build 3005)
Comment: Use Enigmail to decrypt or check this message is legitimate
Charset: ISO-8859-1

wj8DBQFIGdbcEfZZRxQVtlQRAvEIAJ43zfmGMXGI1K0PaNq8mmo/U4Pv7ACePZy3
gmaIUmizpN208mgvy8FtRas=
=nQRh
-----END PGP SIGNATURE-----

-- 
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.



More information about the MailScanner mailing list