<HTML>
<HEAD> <META http-equiv=Content-Type content="text/html; charset=iso-8859-1">
<STYLE title="table borders">.htmtableborders, .htmtableborders td,
.htmtableborders th {border : 1px dashed lightgrey ! important;} </STYLE>
<STYLE type=text/css>html, body { border: 0px; } span.macro, span.macro ul,
span.macro div, span.macro p {background : #CCCCCC;} </STYLE> <STYLE
type=text/css> p{margin-bottom: 0.15em;margin-top:
0.15em;}body{font-family:tahoma;font-size:10pt;}; </STYLE> </HEAD> <BODY>
<DIV>Does anyone have F-Secure Linux Server Security version 7.0 running
with MailScanner.</DIV> <DIV><BR>MailScanner --lint detects the eicar virus
with both F-Secure and ClamAV. When I relay a message with virus it is
not detected by F-Secure.</DIV> <DIV><BR>MailScanner does not stop it.
(ClamAV does not know the virus - have submitted it)</DIV> <DIV><BR>
-------------------------------------------------------------------------------------------------------<BR>
Testing from the commandline:</DIV> <DIV>F-Secure Security Platform version
2.00 build 7161<BR>Copyright (c) 1999-2008 F-Secure Corporation. All
Rights Reserved.</DIV> <DIV>Scan started at Thu May 1 12:36:56 2008<BR>
Database version: 2008-05-01_01</DIV> <DIV>[/root/certificado-2.25.rar]
certificado-2.25.exe: Infected: Trojan-Downloader.Win32.Banload.lpy
[AVP]</DIV> <DIV>Scan ended at Thu May 1 12:36:56 2008<BR>1 file
scanned<BR>1 file infected</DIV> <DIV><BR>
-------------------------------------------------------------------------------------------------------<BR>
MailScanner --lint output this: (eset is not active!)</DIV> <DIV>
MailScanner.conf says "Virus Scanners = f-secure clamavmodule"<BR>Found
these virus scanners installed: clamavmodule, f-secure, esets<BR>
===========================================================================<BR>
Virus and Content Scanning: Starting<BR>Found F-Secure version 2.00=2</DIV>
<DIV>Scan ended at Thu May 1 12:35:52 2008<BR>2 files scanned<BR>1
file infected<BR>ProcessClamAVModOutput ClamAVModule<BR>
ClamAVModule::INFECTED:: Eicar-Test-Signature:: ./1/<BR>
ProcessClamAVModOutput ClamAVModule<BR>ProcessClamAVModOutput
ClamAVModule<BR>ClamAVModule::INFECTED:: Eicar-Test-Signature::
./1/eicar.com<BR>Virus Scanning: ClamAVModule found 2 infections<BR>Infected
message 1 came from 10.1.1.1<BR>Virus Scanning: Found 2 viruses<BR>Filename
Checks: (1 eicar.com)<BR>Other Checks: Found 1 problems<BR>
===========================================================================<BR>
Virus Scanner test reports:<BR>ClamAVModule said "eicar.com was infected:
Eicar-Test-Signature"</DIV> <DIV>If any of your virus scanners
(clamavmodule,f-secure,esets)<BR>are not listed there, you should check that
they are installed correctly<BR>and that MailScanner is finding them
correctly via its virus.scanners.conf.</DIV></BODY>
</HTML>