Zoner Antivirus – The Latest Technology

The program core has a modern design, contains a state-of-the-art code emulator, and boasts a unique heuristic analyzer, designed precisely to meet the threats of today.

NAME

zavlmtp.conf - Zoner AntiVirus configuration file for ZAV LMTP module

DESCRIPTION

Zavlmtp.conf is the LMTP module configuration file for Zoner AntiVirus daemon (ZAVd). Be sure to read zavd.conf(5) for configuration file format, syntax and semantics. Reading the documentation for your MTA and LMTP filtering is recommended.

LMTP SERVER SETUP

This section configures module communication with the MTA and identification.
ZAVLMTP_HOSTNAME = [string]
The hostname, module will report when establishing LMTP communication.
ZAVLMTP_PORT = [int]
Port to listen on for incoming connections from the MTA using this module as its filter.
ZAVLMTP_RELAY = [string]
The hostname of MTA used to pass mails that are not discarded. Such MTA has to be configured correctly, i.e. must accept mails of at least the size that ZAV LMTP accepts and has to support 8BITMIME extension.
ZAVLMTP_RELAY_PORT = [int]
The port of the relay MTA for SMTP communication.
ZAVLMTP_MAX_SIZE = [size]
Maximal allowed size for incoming mails (will be reported in the LMTP greeting).
ZAVLMTP_HEADER = [string]
The text added to the mail header, e.g. 'X-VirusScan: Zoner AntiVirus'.
ZAVLMTP_FILE_TIMEOUT = [time]
The timeout for a single file, including the scanning time and the time spent waiting for a scanner to become available.

ACTIONS SETUP

This section specifies what to do with analyzed mail when a specific scan result is obtained. See zavcli(1) for the result types.
Possible actions:
PASS - send the mail through to be delivered
DROP - act like the mail has been delivered, but do not send it, the mail is effectively LOST!
REJECT - mark the mail as undeliverable, this will cause the MTA to send a DSN notice to the sender
ZAVLMTP_SCANERROR = [enum]
ZAVLMTP_CLEAN = [enum]
ZAVLMTP_INFECTED = [enum]
ZAVLMTP_PROBINFECTED = [enum]
ZAVLMTP_SUSPICIOUS = [enum]
ZAVLMTP_NONSTANDARD = [enum]
ZAVLMTP_UNKNOWN = [enum]
ZAVLMTP_TIMEOUT = [enum]

LOGGING SETUP

This section configures what to log on ZAV LMTP side (ZAVd can log the scan results per file, but knows nothing about mail delivery).
ZAVLMTP_LOG_DROP = [bool]
Print a log message if the mail has been dropped.
ZAVLMTP_LOG_REJECT = [bool]
Print a log message if the mail has been rejected.
ZAVLMTP_LOG_PASS = [bool]
Print a log message if the mail has been passed to the MTA.
ZAVLMTP_LOG_STATS = [bool]
Log scan statistics (scan time and scanned size).

SCANNING SETUP

This sections configures the scanning engine parameters that will override ZAVd's default settings. See zavd.conf(5) in SCANNING SETUP for description.
ZAVLMTP_SCAN_LEVEL = [enum]
ZAVLMTP_SCAN_FULL = [bool]
ZAVLMTP_SCAN_HEURISTICS = [bool]
ZAVLMTP_SCAN_EMULATION = [bool]
ZAVLMTP_SCAN_ARCHIVES = [bool]
ZAVLMTP_SCAN_PACKERS = [bool]
ZAVLMTP_SCAN_GDL = [bool]
ZAVLMTP_SCAN_PHISHING = [bool]
ZAVLMTP_SCAN_DEEP = [bool]
ZAVLMTP_SCAN_MAX_SIZE = [size]
ZAVLMTP_SCAN_MAX_FILES = [int]
ZAVLMTP_SCAN_RECURSION = [int]
ZAVLMTP_SCAN_TIMEOUT = [time]

AUTHOR

Written by Jaromir Smrcek.

BUGS

Report bugs to Jaromir Smrcek <jaromir.smrcek@zoner.com>. Start your 'Subject:' by 'ZAV' and please include the output of 'zavcli -V'.

SEE ALSO

zavd(8), zavd.conf(5), zavcli(1)

Zoner Antivirus Online Scanner

Current Virus Activity

Heuristics13.0%
I-Worm.Runouce.b7.7%
Dropper.Generic2.ANED7.3%
Trojan.Poison-14625.4%
Trojan.Injector.CK2.5%

Current Version

ZAV Core:
20120202-541
ZAV Database:
20120202-5947
Zoner Antivirus

Zoner Sandbox

If you suspect that a file might be infected and you thus want to determine what a given program is doing, you can send a file for us to analyze. We will evaluate the given program's behavior and send you back detailed results.