[Mimedefang] Repeated $VirusScannerMessages?
Ashley M. Kirchner
ashley at pcraft.com
Sat Feb 16 03:03:12 EST 2002
I've been testing the openantivirus scanner and I can't figure this out. I've grabbed the distribution high-risk-filter, done as little as only changing the reference from NAI to sophos since that's what I'm using. Every test I made, both messages (both the one delivered to the recipient, as well as the one sent back to the $Sender) contain the $VirusScannerMessages repeated a few times:
An e-mail you sent with message-id
<0202160105030.31435-201000 at speedy.pcraft.com>
was modified.
The recipients were: <kirash at gemini.pcraft.com>
Here are the details of the modification:
The attachment 'eicar.com' was deleted. It contains
a known virus.
Here is the output from the virus scanner:
>>> Virus 'EICAR-AV-Test' found in file ./Work/msg-31261-2.com
>>> Virus 'W32/Magistr-B' found in file ./Work/msg-31261-3.exe
>>> Virus 'EICAR-AV-Test' found in file Work/msg-31261-2.com
The attachment 'kSELECT.exe' was deleted. It contains
a known virus.
Here is the output from the virus scanner:
>>> Virus 'EICAR-AV-Test' found in file ./Work/msg-31261-2.com
>>> Virus 'W32/Magistr-B' found in file ./Work/msg-31261-3.exe
>>> Virus 'EICAR-AV-Test' found in file Work/msg-31261-2.com
>>> Virus 'W32/Magistr-B' found in file Work/msg-31261-3.exe
At first I thought maybe it was something I did to my filter, but when it did the same thing with the distribution file, I gave up. Is anyone else having this problem?
--
H | "Life is the art of drawing without an eraser." - John Gardner
+--------------------------------------------------------------------
Ashley M. Kirchner <mailto:ashley at pcraft.com> . 303.442.6410 x130
Director of Internet Operations / SysAdmin . 800.441.3873 x130
Photo Craft Laboratories, Inc. . 3550 Arapahoe Ave, #6
http://www.pcraft.com ..... . . . Boulder, CO 80303, U.S.A.
More information about the MIMEDefang
mailing list