• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion

ClamAV & QscanQ - Deliver on Virus

D

DavidCollom

Guest
Hi,
I upgraded today to the latest release of ClamAV and since then I have had a number of problems with virus detection but this is the last problem for today.

Since upgrading i've found that all mail is been delivered even if it is a virus or not.

ive used the test service at http://www.gfi.com/emailsecuritytest/ and checked the logs. clamav is finding the virus' and possably disinfecting them but still delivering them.
Clamav.log shows the following:
Thu Feb 15 23:55:47 2007 -> /var/qmail/qscanq/root/scanq/@4000000045d4f30d0704da24.59e.1/work/.//msg: Eicar-Test-Signature FOUND
Thu Feb 15 23:55:47 2007 -> /var/qmail/qscanq/root/scanq/@4000000045d4f30d0704da24.59e.1/work/.//eicar.com: Eicar-Test-Signature FOUND
Thu Feb 15 23:55:48 2007 -> /var/qmail/qscanq/root/scanq/@4000000045d4f30e1c8cf7b4.59c.1/work/.//msg: Eicar-Test-Signature FOUND
Thu Feb 15 23:55:49 2007 -> /var/qmail/qscanq/root/scanq/@4000000045d4f30f325d3234.59e.1/work/.//msg: GFI.VBS.Test FOUND
Thu Feb 15 23:55:49 2007 -> /var/qmail/qscanq/root/scanq/@4000000045d4f30f325d3234.59e.1/work/.//textfile3: GFI.VBS.Test FOUND
Thu Feb 15 23:55:50 2007 -> /var/qmail/qscanq/root/scanq/@4000000045d4f3100030456c.59c.1/work/.//msg: GFI.VBS.Test FOUND

Maillog displays:
Feb 15 23:55:55 david-collom spamd[27818]: prefork: child states: BIII
Feb 15 23:55:55 david-collom spamd[27818]: spamd: handled cleanup of child pid 1556 due to SIGCHLD
Feb 15 23:55:55 david-collom spamd[27818]: prefork: child states: BII
Feb 15 23:55:57 david-collom spamd[453]: spamd: clean message (1.6/6.0) for [email protected]:110 in 3.1 seconds, 3576 bytes.
Feb 15 23:55:57 david-collom spamd[453]: spamd: result: . 1 - AWL,BAYES_00,DATE_IN_PAST_96_XX scantime=3.1,size=3576,[email protected],uid=110,required_score=6.0,rhost=localhost,raddr=127.0.0.1,rport=/tmp/spamd_full.sock,mid=<[email protected]>,bayes=4.79466466529743e-12,autolearn=no
Feb 15 23:55:57 david-collom spamd[27818]: prefork: child states: III
Feb 15 23:55:57 david-collom spamd[27818]: spamd: handled cleanup of child pid 1553 due to SIGCHLD
Feb 15 23:55:57 david-collom spamd[27818]: prefork: child states: II
Feb 15 23:55:57 david-collom qmail: 1171583757.204782 delivery 25: success: did_1+0+2/did_0+0+1/
Feb 15 23:55:57 david-collom qmail: 1171583757.204943 status: local 0/10 remote 0/20
Feb 15 23:55:57 david-collom qmail: 1171583757.204994 end msg 604000415

Please help!

EDIT:
forgot to add that:
/var/qmail/bin/qmail-inject -a root < /usr/local/qscanq/src/TEST-BAD
Returns:
qmail-inject: fatal: mail server permanently rejected message (#5.3.0)
 
Back
Top