<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Bug: Mail manager shows malware (antivirus engine error)</title><link>https://community.sophos.com/utm-firewall/unified-threat-management-beta/utm_94_beta/f/sophos-utm-9-4-public-beta/74794/bug-mail-manager-shows-malware-antivirus-engine-error</link><description>Hi there, 
 this a new Bug. Mail manager shows malware (antivirus engine error) for a normal newsletter mail. 
 In daily Quarantine Report this mail is shown with reason &amp;quot;SPAM&amp;quot;. If I release this mail over the embedded link. The mail comes for one account</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Bug: Mail manager shows malware (antivirus engine error)</title><link>https://community.sophos.com/thread/289412?ContentTypeID=1</link><pubDate>Fri, 04 Mar 2016 06:24:30 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:ca6eb596-c617-49fb-a763-d659e2f2f761</guid><dc:creator>mod2402</dc:creator><description>&lt;p&gt;great news :)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Bug: Mail manager shows malware (antivirus engine error)</title><link>https://community.sophos.com/thread/289408?ContentTypeID=1</link><pubDate>Fri, 04 Mar 2016 05:45:37 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:b05029de-2827-489a-947f-8b90867e0014</guid><dc:creator>Tamas Bajaki</dc:creator><description>&lt;p&gt;Hi mod,&lt;/p&gt;
&lt;p&gt;Thanks to the logs your provided, we managed to find out the cause of the error. The fix is already on the way. Thank you very much for the feedback!&lt;/p&gt;
&lt;p&gt;Niriel~&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Bug: Mail manager shows malware (antivirus engine error)</title><link>https://community.sophos.com/thread/289382?ContentTypeID=1</link><pubDate>Fri, 04 Mar 2016 02:45:40 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:5a08f0df-5c07-4072-aabb-ff965401f10f</guid><dc:creator>mod2402</dc:creator><description>&lt;p&gt;Hi Niriel,&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;here are the release log lines:&lt;/p&gt;
&lt;p&gt;smtp log:&lt;/p&gt;
&lt;pre&gt;2016:02:13-10:37:27 asg-1 smtpd[7052]: MASTER[7052]: (Re-)loading configuration from Confd
2016:02:13-10:37:27 asg-1 smtpd[7052]: MASTER[7052]: Past 07:00:00, QR status one set to &amp;#39;sent&amp;#39;
2016:02:13-10:37:27 asg-1 smtpd[7052]: MASTER[7052]: QR two disabled, status two set to &amp;#39;disabled&amp;#39;
2016:02:13-10:37:27 asg-1 exim-in[8770]: 2016-02-13 10:37:27 pid 8770: SIGHUP received: re-exec daemon
2016:02:13-10:37:27 asg-1 exim-in[8770]: 2016-02-13 10:37:27 exim 4.82_1-5b7a7c0-XX daemon started: pid=8770, no queue runs, listening for SMTP on port 25 (IPv4) port 587 (IPv4) and for SMTPS on port 465 (IPv4)
2016:02:13-10:37:30 asg-1 smtpd[7052]: MASTER[7052]: Action: scanning mail 1aUFuo-0004e1-GI after quarantine release request.
2016:02:13-10:37:30 asg-1 smtpd[7052]: MASTER[7052]: Action: replacing mail 1aUFuo-0004e1-GI back after scan because reason: av.
2016:02:13-10:37:30 asg-1 smtpd[7052]: MASTER[7052]: 1aUFuo-0004e1-GI Sending &amp;#39;Quarantine release failed&amp;#39; notification to klaus@localdomain.tld
2016:02:13-10:37:30 asg-1 exim-out[13439]: 2016-02-13 10:37:30 SMTP connection from MailerDaemon
2016:02:13-10:37:30 asg-1 exim-out[13439]: 2016-02-13 10:37:30 1aUWdu-0003Ul-1p &amp;lt;= &amp;lt;&amp;gt; R=1aUFuo-0004e1-GI U=MailerDaemon P=local-bsmtp S=1256&lt;br /&gt;&lt;br /&gt;fallback.log:&lt;/pre&gt;
&lt;pre&gt;2016:02:13-10:37:30 asg-1 [daemon:info] cssd[5631]:  [ 0x9c94d40] saviscanner_scan (saviscanner.c:159) Failed to open /var/chroot-smtp/spool/work/.eml: No such file or directory&lt;br /&gt;&lt;br /&gt;regards&lt;br /&gt;mod&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Bug: Mail manager shows malware (antivirus engine error)</title><link>https://community.sophos.com/thread/289335?ContentTypeID=1</link><pubDate>Thu, 03 Mar 2016 11:50:13 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:fd5eb448-8994-4c37-857a-a57391380594</guid><dc:creator>Tamas Bajaki</dc:creator><description>&lt;p&gt;Hi mod,&lt;/p&gt;
&lt;p&gt;This seems to be a simple case of spam mail according to the logs (ctasd identifies it as a bulk mail) and gets quarantined accordingly. When you try to release this mail, an AV scan will be run to see if it also contains a malware besides being a spam mail. Did I get right that the issue happens when you try to release it? If so, then there should be corresponding log lines for the release (and rescan) as well.&lt;/p&gt;
&lt;p&gt;Niriel~&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Bug: Mail manager shows malware (antivirus engine error)</title><link>https://community.sophos.com/thread/289329?ContentTypeID=1</link><pubDate>Thu, 03 Mar 2016 11:14:24 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:94c1cf09-4101-4e95-9397-f5081790280b</guid><dc:creator>mod2402</dc:creator><description>&lt;p&gt;Hi Niriel,&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Sandstorm is turned on. No smtpd_debug.log file from this time present. I can&amp;#39;t reproduce this issue at the moment. The fallback.log don&amp;#39;t show anything that is related to this issue.&lt;br /&gt;&lt;br /&gt;The related log lines from the smtp log:&lt;/p&gt;
&lt;pre&gt;2016:02:12-16:45:39 asg-1 exim-in[8770]: 2016-02-12 16:45:39 SMTP connection from [91.192.42.212]:45512 (TCP/IP connection count = 1)
2016:02:12-16:45:40 asg-1 exim-in[17820]: 2016-02-12 16:45:40 H=duounusduo.xi.ecm-cluster.com [91.192.42.212]:45512 Warning: localdomain.tld profile excludes SANDBOX scan
2016:02:12-16:45:40 asg-1 exim-in[17820]: 2016-02-12 16:45:40 [91.192.42.212] F=&amp;lt;g-2668693670-2838-1300938333-1455288436371@bounce.borussia-newsletter.de&amp;gt; R=&amp;lt;klaus@localdomain.tld&amp;gt; Verifying recipient address in Active Directory
2016:02:12-16:45:40 asg-1 exim-in[17820]: 2016-02-12 16:45:40 1aUFue-0004dQ-1A DKIM: d=borussia-newsletter.de s=ecm1 c=relaxed/relaxed a=rsa-sha256 t=1455288436 [verification succeeded]
2016:02:12-16:45:40 asg-1 exim-in[17820]: 2016-02-12 16:45:40 1aUFue-0004dQ-1A ctasd reports &amp;#39;Bulk&amp;#39; RefID:str=0001.0A0B0206.56BDF08B.0171,ss=3,sh,re=0.000,recu=0.000,reip=0.000,cl=3,cld=1,fgs=0
2016:02:12-16:45:40 asg-1 exim-in[17820]: 2016-02-12 16:45:40 1aUFue-0004dQ-1A Greylisting: Successful greylist retry from 91.192.42.212 (original host was 91.192.42.214/32)
2016:02:12-16:45:40 asg-1 exim-in[17820]: 2016-02-12 16:45:40 1aUFue-0004dQ-1A &amp;lt;= g-2668693670-2838-1300938333-1455288436371@bounce.borussia-newsletter.de H=duounusduo.xi.ecm-cluster.com [91.192.42.212]:45512 P=esmtp S=29170 id=wd0e0p.ikjt5s43713wj2t@borussia-newsletter.de
2016:02:12-16:45:42 asg-1 smtpd[8718]: QMGR[8718]: 1aUFue-0004dQ-1A moved to work queue
2016:02:12-16:45:46 asg-1 exim-in[17820]: 2016-02-12 16:45:46 SMTP connection from duounusduo.xi.ecm-cluster.com [91.192.42.212]:45512 lost
2016:02:12-16:45:50 asg-1 smtpd[17857]: SCANNER[17857]: 1aUFuo-0004e1-GI &amp;lt;= g-2668693670-2838-1300938333-1455288436371@bounce.borussia-newsletter.de R=1aUFue-0004dQ-1A P=INPUT S=26979
2016:02:12-16:45:51 asg-1 smtpd[17857]: SCANNER[17857]: id=&amp;quot;1001&amp;quot; severity=&amp;quot;info&amp;quot; sys=&amp;quot;SecureMail&amp;quot; sub=&amp;quot;smtp&amp;quot; name=&amp;quot;email quarantined&amp;quot; srcip=&amp;quot;91.192.42.212&amp;quot; from=&amp;quot;g-2668693670-2838-1300938333-1455288436371@bounce.borussia-newsletter.de&amp;quot; to=&amp;quot;klaus@localdomain.tld&amp;quot; subject=&amp;quot;Alle Infos: Der VfL zu Gast beim Hamburger SV.&amp;quot; queueid=&amp;quot;1aUFuo-0004e1-GI&amp;quot; size=&amp;quot;26979&amp;quot; reason=&amp;quot;as&amp;quot; extra=&amp;quot;&amp;quot;
2016:02:12-16:45:51 asg-1 smtpd[17857]: SCANNER[17857]: 1aUFue-0004dQ-1A =&amp;gt; work R=SCANNER T=SCANNER
2016:02:12-16:45:51 asg-1 smtpd[17857]: SCANNER[17857]: 1aUFue-0004dQ-1A Completed&lt;/pre&gt;
&lt;p&gt;regards&lt;/p&gt;
&lt;p&gt;mod&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Bug: Mail manager shows malware (antivirus engine error)</title><link>https://community.sophos.com/thread/289322?ContentTypeID=1</link><pubDate>Thu, 03 Mar 2016 10:31:19 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:c77b3d32-2afc-4ff6-bbd7-ac4d927d8529</guid><dc:creator>Tamas Bajaki</dc:creator><description>&lt;p&gt;Hi mod and quasar!&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;To help investigate this issue, please provide the following details:&lt;/p&gt;
&lt;p&gt;&amp;nbsp;- Is Sandstorm turned on?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;- Are there any log lines starting with &amp;quot;Failure from cssd: ...&amp;quot; in /var/chroot-smtp/tmp/smtpd_debug.log?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;- If you are able to reproduce this issue, please check /var/log/fallback.log for any entries when this happens and paste them here&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Kind regards,&lt;/p&gt;
&lt;p&gt;Niriel&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Bug: Mail manager shows malware (antivirus engine error)</title><link>https://community.sophos.com/thread/287989?ContentTypeID=1</link><pubDate>Fri, 19 Feb 2016 12:15:23 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:c4a8fc67-88b3-46d0-a9d5-179f009dec3a</guid><dc:creator>mod2402</dc:creator><description>Is this a beta forum or a user 2 user forum? Where are the sophos employes?&lt;br /&gt;
Do you want to know which bugs are present or is this all nonsens?&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Bug: Mail manager shows malware (antivirus engine error)</title><link>https://community.sophos.com/thread/287727?ContentTypeID=1</link><pubDate>Wed, 17 Feb 2016 10:05:04 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:e624f003-e22a-46b5-995b-5c59e9329d20</guid><dc:creator>quasar3c279</dc:creator><description>Hi,&lt;br /&gt;
&lt;br /&gt;
same here. Happens everytime when I release mails. No difference in releasing from mail manager or quarantine link.&lt;br /&gt;
&lt;br /&gt;
If you want to have a look it&amp;#39;s clearly reproducable...&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>