Just wondering (i'm trying to understand), my CG Pro and ClamAV find the virus in the message correctly. The msg is discarded and put in Quarantine. Ok, so I tried a manual scan afterwards on this .msg file with clamscan (example below) but it can't find a virus. Is there a reasonable explanation for this or am I missing something?
Communigate Pro Log part: 17:35:40.09 4 ENQUEUERRULES [4033392] rule(cgpav) conditions met 17:35:40.09 4 EXTFILTER(cgpav) out(29): 40820 FILE Queue/4033392.msg\n 17:35:40.12 4 EXTFILTER(cgpav) inp(13): 40820 DISCARD 17:35:40.12 2 ENQUEUERRULES [4033392] rule(cgpav) action #0: message discarded with filter 17:35:40.12 2 ENQUEUER-37([4033392]) discarded by Rules
The output of clamscan (tried with and without --mbox, same result)
[EMAIL PROTECTED] root]# clamscan --mbox /var/CommuniGate/Quarantine/40820.msg /var/CommuniGate/Quarantine/40820.msg: OK
----------- SCAN SUMMARY ----------- Known viruses: 40423 Scanned directories: 0 Scanned files: 1 Infected files: 0 Data scanned: 0.03 MB I/O buffer size: 131072 bytes Time: 1.496 sec (0 m 1 s)
Any advice or wise words would be welcome :) System is Red Hat 9, running CgPro and cgpav-1.3 with clamav devel 20040128. (is it 'wise' to upgrade to newest devel?)
--
Best regards, Kristof
------------------------------------------------------- The SF.Net email is sponsored by EclipseCon 2004 Premiere Conference on Open Tools Development and Integration See the breadth of Eclipse activity. February 3-5 in Anaheim, CA. http://www.eclipsecon.org/osdn _______________________________________________ Clamav-users mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/clamav-users
