On 25/11/2016 10:26, Paul Stead wrote:
On 25/11/16 10:18, geoff.sa_users_161...@alphaworks.co.uk wrote:
X-Antivirus: avast! (VPS 161124-7, 24/11/2016), Inbound message
X-Antivirus-Status: Infected
X-Attachment: INVOICE_<removed>.zip#1783656308|>HQ2s9y6f.js Virus:
JS:LockyDownloader [Trj] Deleted
Your AV correctly identified the bad attachment - generally these don't
even get as far as SA in my setup
This all depends on the glue used and ordering within your MTA and how
it reacts to malware attachments
I don't have a lot of control over my setup as it's a hosted VPS. The AV
is locally on my PC so comes late in the process...