MS Word problems

Noisex noisex at apollo.lv
Tue Jun 14 13:39:55 IST 2011


Hi! I can't figure out where is the problem with Mailscanner configuration
or something else is wrong. So the problem is that recipients don't getting
e-mails at all where is attached Microsoft Word documents (*.doc, *.docx).

 

The sender receive answer from Mailserver:

 

 

Our virus detector failed to completely analyse a message you sent:-

  To: mail at domain.tld

  Subject: 

  Date: Sat Jun 11 02:42:45 2011

Any parts of the message that could not be analysed will not have been
delivered.

 

If you are using Microsoft Outlook, we strongly recommend you change your
outgoing message format from "Rich Text" to "HTML" or "Plain Text".

 

1) Click on the "Tools" menu and choose "Options..."

2) Go to the "Mail Format" tab

3) For message format, select "HTML" or "Plain text"

4) Click OK

 

The virus detector said this about the message:

Report: Report: MailScanner: Message attempted to kill MailScanner

 

 

--

MailScanner

Email Virus Scanner

Mail server

 

 

Besides mail is didn't send through MS Outlook J

 

MTA: Postfix + Courier + MailScanner + SA + Clamav

 

 

>From Maillog:

 

Jun 14 15:19:56 obelix postfix/smtpd[67189]: connect from
xxxx.xxxx.xx[xx.xx.xxx.xx]

Jun 14 15:19:56 obelix postfix/smtpd[67189]: C89706E0B7:
client=xxxx.xxxx.xx[xx.xx.xx.xx]

Jun 14 15:19:56 obelix postfix/cleanup[67193]: C89706E0B7: hold: header
Received: from xxxx at xxxx.xx (xxxxxxxxxxxxx [xx.xx.xx.xx])??by xxxxxxxxxxx
(Postfix) with ESMTP id C89706E0B7??for <yyyyy at yyyy.lv>; Tue, 14 Jun 2011
15:19:56 +0300 (EEST) from xxxxx.xxxx.xx[xx.xx.xx.xx]; from=<xxxx at xxxx.xx>
to=<yyyyy at yyyy.xx> proto=ESMTP helo=<xxxxx.xx>

Jun 14 15:19:56 obelix postfix/cleanup[67193]: C89706E0B7:
message-id=<001b01cc2a8d$6bfe3940$43faabc0$@lv>

Jun 14 15:19:56 obelix postfix/smtpd[67189]: disconnect from
xxxxx.xxxxx.xx[xx.xx.xx.xx]

Jun 14 15:19:58 obelix MailScanner[66707]: New Batch: Found 2 messages
waiting 

Jun 14 15:19:58 obelix MailScanner[66707]: New Batch: Scanning 1 messages,
61350 bytes 

Jun 14 15:19:59 obelix MailScanner[67199]: MailScanner E-Mail Virus Scanner
version 4.81.4 starting... 

Jun 14 15:19:59 obelix MailScanner[67199]: Reading configuration file
/usr/local/etc/MailScanner/MailScanner.conf 

Jun 14 15:19:59 obelix MailScanner[67199]: Read 865 hostnames from the
phishing whitelist 

Jun 14 15:19:59 obelix MailScanner[67199]: Read 5278 hostnames from the
phishing blacklists 

Jun 14 15:19:59 obelix MailScanner[67199]: Using SpamAssassin results cache 

Jun 14 15:19:59 obelix MailScanner[67199]: Connected to SpamAssassin cache
database 

Jun 14 15:19:59 obelix MailScanner[67199]: Enabling SpamAssassin
auto-whitelist functionality...

Jun 14 15:20:01 obelix MailScanner[66737]: Virus and Content Scanning:
Starting 

Jun 14 15:20:04 obelix MailScanner[67199]: Connected to Processing Attempts
Database 

Jun 14 15:20:04 obelix MailScanner[67199]: Found 2 messages in the
Processing Attempts Database 

Jun 14 15:20:04 obelix MailScanner[67199]: Using locktype = flock

..

 

 

MailScanner -V    

Running on

FreeBSD obelix.rdx.lv 8.0-RELEASE FreeBSD 8.0-RELEASE #0: Sat Nov 21
15:02:08 UTC 2009
root at mason.cse.buffalo.edu:/usr/obj/usr/src/sys/GENERIC  amd64

This is Perl version 5.010001 (5.10.1)

 

This is MailScanner version 4.81.4

Module versions are:

1.00    AnyDBM_File

1.30    Archive::Zip

0.23    bignum

1.11    Carp

2.02    Compress::Zlib

1.119   Convert::BinHex

0.17    Convert::TNEF

2.124   Data::Dumper

2.30    Date::Parse

1.03    DirHandle

1.06    Fcntl

2.77    File::Basename

2.14    File::Copy

2.02    FileHandle

2.07_03 File::Path

0.22    File::Temp

0.92    Filesys::Df

3.68    HTML::Entities

3.68    HTML::Parser

3.57    HTML::TokeParser

1.25    IO

1.14    IO::File

1.13    IO::Pipe

2.07    Mail::Header

1.89    Math::BigInt

0.22    Math::BigRat

3.08    MIME::Base64

5.428   MIME::Decoder

5.428   MIME::Decoder::UU

5.428   MIME::Head

5.428   MIME::Parser

3.08    MIME::QuotedPrint

5.428   MIME::Tools

0.14    Net::CIDR

1.25    Net::IP

0.19    OLE::Storage_Lite

1.04    Pod::Escapes

3.07    Pod::Simple

1.17    POSIX

1.21    Scalar::Util

1.82    Socket

2.21    Storable

1.4     Sys::Hostname::Long

0.27    Sys::Syslog

missing Test::Pod

0.96    Test::Simple

1.9719  Time::HiRes

1.02    Time::localtime

 

Optional module versions are:

1.52    Archive::Tar

0.23    bignum

missing Business::ISBN

missing Business::ISBN::Data

missing Data::Dump

1.82    DB_File

1.31    DBD::SQLite

1.615   DBI

1.16    Digest

1.02    Digest::HMAC

2.39    Digest::MD5

2.13    Digest::SHA1

1.01    Encode::Detect

missing Error

0.2703  ExtUtils::CBuilder

2.2203  ExtUtils::ParseXS

2.38    Getopt::Long

missing Inline

missing IO::String

1.09    IO::Zlib

2.27    IP::Country

missing Mail::ClamAV

3.003001        Mail::SpamAssassin

missing Mail::SPF

missing Mail::SPF::Query

0.3607  Module::Build

missing Net::CIDR::Lite

0.66    Net::DNS

missing Net::DNS::Resolver::Programmable

missing Net::LDAP

 4.028  NetAddr::IP

missing Parse::RecDescent

missing SAVI

3.17    Test::Harness

missing Test::Manifest

2.0.0   Text::Balanced

1.53    URI

0.77    version

missing YAML

 

Trying to setlogsock(unix)

 

Reading configuration file /usr/local/etc/MailScanner/MailScanner.conf

Read 865 hostnames from the phishing whitelist

Read 5278 hostnames from the phishing blacklists

 

Checking version numbers...

Version number in MailScanner.conf (4.81.4) is correct.

 

Your envelope_sender_header in spam.assassin.prefs.conf is correct.

MailScanner setting GID to  (125)

MailScanner setting UID to  (125)

 

Checking for SpamAssassin errors (if you use it)...

Using SpamAssassin results cache

Connected to SpamAssassin cache database

SpamAssassin reported no errors.

Connected to Processing Attempts Database

Created Processing Attempts Database successfully

There are 2 messages in the Processing Attempts Database

Using locktype = posix

MailScanner.conf says "Virus Scanners = clamd"

Found these virus scanners installed: clamd

===========================================================================

Filename Checks: Windows/DOS Executable (1 eicar.com)

Other Checks: Found 1 problems

Virus and Content Scanning: Starting

Clamd::INFECTED:: Eicar-Test-Signature :: ./1/eicar.com

Virus Scanning: Clamd found 1 infections

Infected message 1 came from 10.1.1.1

Virus Scanning: Found 1 viruses

===========================================================================

Virus Scanner test reports:

Clamd said "eicar.com was infected: Eicar-Test-Signature"

 

If any of your virus scanners (clamd)

are not listed there, you should check that they are installed correctly

and that MailScanner is finding them correctly via its virus.scanners.conf.

 

 

 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20110614/d8794393/attachment.html


More information about the MailScanner mailing list