"Ian.H [dS]" <ian.RemoveThis@WINDOZEdigiserv.net> wrote in message
news:pan.2003.09.17.23.09.19.621395@hybris.digiserv.net...
> On Wed, 17 Sep 2003 23:25:27 +0000, JP wrote:
>
> > Anyone know if there is a tool to scan a linux mailbox file?
> >
> > f-prot will scan the file as clean but when an attachment from an email
is
> > saved as a file f-prot will detect the Backdoor.Rado / W32/Tepora.A
> > trojan.
> >
> > I only ask because AVG and EZ did not pick up the trojan, only F-Prot
> > identified it.
> >
> > Cheers
> >
> > Jules
>
>
> f-prot scans my mail dir just fine.. what switches did you use? I use for
> example:
>
>
> f-prot /var/mail -archive -packed -collect -dumb
>
>
> It's detected sobig.f and a few others so far without issue.
Nope, didn't work
I even upgraded f-prot from 3.12 ro 4.2.1 and updated the signatures again.
Output posted below
<Scanning the mail file...>
# ./f-prot /var/spool/mail/jpar -archive -packed -collect -dumb
Virus scanning report - 18 September 2003 @ 8:54
F-PROT ANTIVIRUS
Program version: 4.2.1
Engine version: 3.13.4
VIRUS SIGNATURE FILES
SIGN.DEF created 17 September 2003
SIGN2.DEF created 17 September 2003
MACRO.DEF created 15 September 2003
Search: /var/spool/mail/
Action: Report only
Files: "Dumb" scan of all files
Switches: -ARCHIVE -PACKED -COLLECT
Results of virus scanning:
Files: 1
MBRs: 0
Boot sectors: 0
Objects scanned: 3
Time: 0:32
No viruses or suspicious files/boot sectors were found.
<Scanning a file extracted from the mail file...>
# f-prot DavidKelley.voice.pif -archive -packed -collect -dumb Virus
scanning report - 18 September 2003 @ 9:00
F-PROT ANTIVIRUS
Program version: 4.2.1
Engine version: 3.13.4
VIRUS SIGNATURE FILES
SIGN.DEF created 17 September 2003
SIGN2.DEF created 17 September 2003
MACRO.DEF created 15 September 2003
Search: DavidKelley.voice.pif
Action: Report only
Files: "Dumb" scan of all files
Switches: -ARCHIVE -PACKED -COLLECT
/home/guest/DavidKelley.voice.pif Infection: W32/Tepora.A (exact)
Results of virus scanning:
Files: 1
MBRs: 0
Boot sectors: 0
Objects scanned: 1
Infected: 1
Suspicious: 0
Disinfected: 0
Deleted: 0
Renamed: 0
Time: 0:00
#
Do I need the mail server version?
JP
>> Stay informed about: virus scanning linux mailbox files