<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=Content-Type content="text/html; charset=iso-8859-1">
<META content="MSHTML 6.00.2800.1400" name=GENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=#ffffff>
<DIV>
<DIV><FONT face=Arial size=2>System is RH / cpanel / exim /</FONT></DIV>
<DIV><FONT face=Arial size=2></FONT> </DIV>
<DIV><FONT face=Arial size=2>I just installed the new version of
MailScanner</FONT></DIV>
<DIV><FONT face=Arial size=2>as of right now</FONT></DIV>
<DIV><FONT face=Arial size=2>Virus Scanners = rav clamav f-prot f-secure
mcafee</FONT></DIV>
<DIV><FONT face=Arial size=2></FONT> </DIV>
<DIV><FONT face=Arial size=2>Rav (Works)</FONT></DIV>
<DIV><FONT face=Arial size=2>Clamav (Works)</FONT></DIV>
<DIV><FONT face=Arial size=2>F-prot (Trial) (Works)</FONT></DIV>
<DIV><FONT face=Arial size=2>Mcafee (Works)</FONT></DIV>
<DIV><FONT face=Arial size=2>F-secure (Seems Not To Work)</FONT></DIV>
<DIV><FONT face=Arial size=2></FONT> </DIV>
<DIV><FONT face=Arial size=2>i can do the command line for f-secure</FONT></DIV>
<DIV><FONT face=Arial size=2>/usr/lib/MailScanner/f-secure-wrapper
/opt/f-secure/fsav /tmp</FONT></DIV>
<DIV><FONT face=Arial size=2>-And that works</FONT></DIV>
<DIV><FONT face=Arial size=2>Database version: 2004-02-05_01</FONT></DIV>
<DIV><FONT face=Arial size=2>Scan started at Thu Feb 5 09:05:31
2004</FONT></DIV>
<DIV><FONT face=Arial size=2>Scan ended at Thu Feb 5 09:05:32 2004</DIV>
<DIV>11 files scanned</DIV>
<DIV> </DIV>
<DIV>But it is not catching any virus in incoming emails</DIV>
<DIV>---------------paste from email---------------------</DIV>
<DIV>MessageID: 1Aojlz-0002FM-LP<BR>Report: </DIV>
<DIV> Rav:
./1Aojlz-0002FM-LP/body.zip->body.txt .pif Infected: <A
href="mailto:Win32/Mydoom.A@mm">Win32/Mydoom.A@mm</A><BR>
ClamAV: body.zip contains Worm.SCO.A
<BR> F-Prot:
/var/spool/MailScanner/incoming/30908/1Aojlz-0002FM-LP/body.zip-body.txt Infection:
<A
href="mailto:W32/Mydoom.A@mm">W32/Mydoom.A@mm</A><BR>
McAfee: /1Aojlz-0002FM-LP/body.zip
Found the <A href="mailto:W32/Mydoom.a@MM">W32/Mydoom.a@MM</A> virus
!!!<BR>-----------------End Paste-------------------</DIV>
<DIV>I dont see any thing in any of the infected mails about f-secure</DIV>
<DIV> </DIV>
<DIV>----------paste from maillog---------------</DIV>
<DIV>Feb 5 09:01:07 srv1 update.virus.scanners: Found f-secure
installed<BR>Feb 5 09:01:07 srv1 update.virus.scanners: Running autoupdate
for f-secure</DIV>
<DIV>-------------End Paste-------------------------</DIV>
<DIV> </DIV>
<DIV>Mailscanner is seeing it..</DIV>
<DIV></FONT><FONT face=Arial size=2></FONT> </DIV></DIV></BODY></HTML>