i tried to look at the source, sadly no perl programmer that looks in general wrong because the process is postfix/cleanup since it relies on prgram names as it looks also my fake below is not recognized by change /etc/mail/clamav-milter.conf to: RejectMsg Virus found: "%v" elsif($prog eq 'clamav-milter') { if($text =~ /Intercepted/) { event($time, 'virus'); } } Aug 19 22:40:24 mail-gw postfix/cleanup[307]: 3hd3sh1SXpzyPX: milter-reject: END-OF-MESSAGE from *.*.*.*[*.*.*.*]: 5.7.1 Virus found: "Trojan.FakeTimer"; from=<**> to=<**> proto=ESMTP helo=<**>
*** This bug has been marked as a duplicate of bug 1133356 ***