• Plesk Uservoice will be deprecated by October. Moving forward, all product feature requests and improvement suggestions will be managed through our new platform Plesk Productboard.
    To continue sharing your ideas and feedback, please visit features.plesk.com

ClamAV & QscanQ - Deliver on Virus

D

DavidCollom

Guest
Hi,
I upgraded today to the latest release of ClamAV and since then I have had a number of problems with virus detection but this is the last problem for today.

Since upgrading i've found that all mail is been delivered even if it is a virus or not.

ive used the test service at http://www.gfi.com/emailsecuritytest/ and checked the logs. clamav is finding the virus' and possably disinfecting them but still delivering them.
Clamav.log shows the following:
Thu Feb 15 23:55:47 2007 -> /var/qmail/qscanq/root/scanq/@4000000045d4f30d0704da24.59e.1/work/.//msg: Eicar-Test-Signature FOUND
Thu Feb 15 23:55:47 2007 -> /var/qmail/qscanq/root/scanq/@4000000045d4f30d0704da24.59e.1/work/.//eicar.com: Eicar-Test-Signature FOUND
Thu Feb 15 23:55:48 2007 -> /var/qmail/qscanq/root/scanq/@4000000045d4f30e1c8cf7b4.59c.1/work/.//msg: Eicar-Test-Signature FOUND
Thu Feb 15 23:55:49 2007 -> /var/qmail/qscanq/root/scanq/@4000000045d4f30f325d3234.59e.1/work/.//msg: GFI.VBS.Test FOUND
Thu Feb 15 23:55:49 2007 -> /var/qmail/qscanq/root/scanq/@4000000045d4f30f325d3234.59e.1/work/.//textfile3: GFI.VBS.Test FOUND
Thu Feb 15 23:55:50 2007 -> /var/qmail/qscanq/root/scanq/@4000000045d4f3100030456c.59c.1/work/.//msg: GFI.VBS.Test FOUND

Maillog displays:
Feb 15 23:55:55 david-collom spamd[27818]: prefork: child states: BIII
Feb 15 23:55:55 david-collom spamd[27818]: spamd: handled cleanup of child pid 1556 due to SIGCHLD
Feb 15 23:55:55 david-collom spamd[27818]: prefork: child states: BII
Feb 15 23:55:57 david-collom spamd[453]: spamd: clean message (1.6/6.0) for [email protected]:110 in 3.1 seconds, 3576 bytes.
Feb 15 23:55:57 david-collom spamd[453]: spamd: result: . 1 - AWL,BAYES_00,DATE_IN_PAST_96_XX scantime=3.1,size=3576,[email protected],uid=110,required_score=6.0,rhost=localhost,raddr=127.0.0.1,rport=/tmp/spamd_full.sock,mid=<[email protected]>,bayes=4.79466466529743e-12,autolearn=no
Feb 15 23:55:57 david-collom spamd[27818]: prefork: child states: III
Feb 15 23:55:57 david-collom spamd[27818]: spamd: handled cleanup of child pid 1553 due to SIGCHLD
Feb 15 23:55:57 david-collom spamd[27818]: prefork: child states: II
Feb 15 23:55:57 david-collom qmail: 1171583757.204782 delivery 25: success: did_1+0+2/did_0+0+1/
Feb 15 23:55:57 david-collom qmail: 1171583757.204943 status: local 0/10 remote 0/20
Feb 15 23:55:57 david-collom qmail: 1171583757.204994 end msg 604000415

Please help!

EDIT:
forgot to add that:
/var/qmail/bin/qmail-inject -a root < /usr/local/qscanq/src/TEST-BAD
Returns:
qmail-inject: fatal: mail server permanently rejected message (#5.3.0)
 
Back
Top