Hi Zhang,
For the debug log you requested, please see my reply (#6). #7 was a follow up to your earlier reply. Sorry, that might confused you.
Yes, I followed the tutorial in the link you provided. Anyway, this is the debug log (sending mail with .wsf ransomware script - So, that it's easier for you to check). Let me know if this is not the debug log that you require.
Thanks.
=======================================================================
Dec 27 14:18:15 mail amavis[1211]: starting. /usr/sbin/amavisd at mail.test.com amavisd-new-2.9.1 (20140627), Unicode aware, LANG="en_US.UTF-8"
Dec 27 14:18:17 mail amavis[1222]: Net::Server: Group Not Defined. Defaulting to EGID '496 496'
Dec 27 14:18:17 mail amavis[1222]: Net::Server: User Not Defined. Defaulting to EUID '496'
Dec 27 14:18:17 mail amavis[1222]: Module Amavis::Conf 2.321
Dec 27 14:18:17 mail amavis[1222]: Module Archive::Zip 1.30
Dec 27 14:18:17 mail amavis[1222]: Module BerkeleyDB 0.43
Dec 27 14:18:17 mail amavis[1222]: Module Compress::Raw::Zlib 2.021
Dec 27 14:18:17 mail amavis[1222]: Module Compress::Zlib 2.021
Dec 27 14:18:17 mail amavis[1222]: Module Crypt::OpenSSL::RSA 0.25
Dec 27 14:18:17 mail amavis[1222]: Module DBD::mysql 4.013
Dec 27 14:18:17 mail amavis[1222]: Module DBI 1.609
Dec 27 14:18:17 mail amavis[1222]: Module DB_File 1.82
Dec 27 14:18:17 mail amavis[1222]: Module Digest::MD5 2.39
Dec 27 14:18:17 mail amavis[1222]: Module Digest::SHA 5.47
Dec 27 14:18:17 mail amavis[1222]: Module Encode 2.35
Dec 27 14:18:17 mail amavis[1222]: Module File::Temp 0.22
Dec 27 14:18:17 mail amavis[1222]: Module IO::Socket::INET6 2.56
Dec 27 14:18:17 mail amavis[1222]: Module MIME::Entity 5.427
Dec 27 14:18:17 mail amavis[1222]: Module MIME::Parser 5.427
Dec 27 14:18:17 mail amavis[1222]: Module MIME::Tools 5.427
Dec 27 14:18:17 mail amavis[1222]: Module Mail::DKIM::Signer 0.37
Dec 27 14:18:17 mail amavis[1222]: Module Mail::DKIM::Verifier 0.37
Dec 27 14:18:17 mail amavis[1222]: Module Mail::Header 2.04
Dec 27 14:18:17 mail amavis[1222]: Module Mail::Internet 2.04
Dec 27 14:18:17 mail amavis[1222]: Module Mail::SPF v2.008
Dec 27 14:18:17 mail amavis[1222]: Module Mail::SpamAssassin 3.003001
Dec 27 14:18:17 mail amavis[1222]: Module Net::DNS 0.65
Dec 27 14:18:17 mail amavis[1222]: Module Net::Server 2.007
Dec 27 14:18:17 mail amavis[1222]: Module NetAddr::IP 4.027
Dec 27 14:18:17 mail amavis[1222]: Module Razor2::Client::Version 2.84
Dec 27 14:18:17 mail amavis[1222]: Module Scalar::Util 1.21
Dec 27 14:18:17 mail amavis[1222]: Module Socket 1.82
Dec 27 14:18:17 mail amavis[1222]: Module Socket6 0.23
Dec 27 14:18:17 mail amavis[1222]: Module Time::HiRes 1.9721
Dec 27 14:18:17 mail amavis[1222]: Module URI 1.40
Dec 27 14:18:17 mail amavis[1222]: Module Unix::Syslog 1.1
Dec 27 14:18:17 mail amavis[1222]: Amavis::ZMQ code NOT loaded
Dec 27 14:18:17 mail amavis[1222]: Amavis::DB code loaded
Dec 27 14:18:17 mail amavis[1222]: SQL base code loaded
Dec 27 14:18:17 mail amavis[1222]: SQL::Log code loaded
Dec 27 14:18:17 mail amavis[1222]: SQL::Quarantine loaded
Dec 27 14:18:17 mail amavis[1222]: Lookup::SQL code loaded
Dec 27 14:18:17 mail amavis[1222]: Lookup::LDAP code NOT loaded
Dec 27 14:18:17 mail amavis[1222]: AM.PDP-in proto code loaded
Dec 27 14:18:17 mail amavis[1222]: SMTP-in proto code loaded
Dec 27 14:18:17 mail amavis[1222]: Courier proto code NOT loaded
Dec 27 14:18:17 mail amavis[1222]: SMTP-out proto code loaded
Dec 27 14:18:17 mail amavis[1222]: Pipe-out proto code NOT loaded
Dec 27 14:18:17 mail amavis[1222]: BSMTP-out proto code NOT loaded
Dec 27 14:18:17 mail amavis[1222]: Local-out proto code NOT loaded
Dec 27 14:18:17 mail amavis[1222]: OS_Fingerprint code NOT loaded
Dec 27 14:18:17 mail amavis[1222]: ANTI-VIRUS code loaded
Dec 27 14:18:17 mail amavis[1222]: ANTI-SPAM code loaded
Dec 27 14:18:17 mail amavis[1222]: ANTI-SPAM-EXT code NOT loaded
Dec 27 14:18:17 mail amavis[1222]: ANTI-SPAM-C code NOT loaded
Dec 27 14:18:17 mail amavis[1222]: ANTI-SPAM-SA code loaded
Dec 27 14:18:17 mail amavis[1222]: Unpackers code loaded
Dec 27 14:18:17 mail amavis[1222]: DKIM code loaded
Dec 27 14:18:17 mail amavis[1222]: Tools code NOT loaded
Dec 27 14:18:17 mail amavis[1222]: Found $file at /usr/bin/file
Dec 27 14:18:17 mail amavis[1222]: Found $altermime at /usr/bin/altermime
Dec 27 14:18:17 mail amavis[1222]: Internal decoder for .mail
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .F at /usr/bin/unfreeze
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .Z at /usr/bin/gzip -d
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .gz at /usr/bin/gzip -d
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .bz2 at /usr/bin/bzip2 -d
Dec 27 14:18:17 mail amavis[1222]: No ext program for .xz, tried: xzdec, xz -dc, unxz -c, xzcat
Dec 27 14:18:17 mail amavis[1222]: No ext program for .lzma, tried: lzmadec, xz -dc --format=lzma, lzma -dc, unlzma -c, lzcat, lzmadec
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .lrz at /usr/bin/lrzip -q -k -d -o -
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .lzo at /usr/bin/lzop -d
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .rpm at /usr/bin/rpm2cpio
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .cpio at /usr/bin/pax
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .tar at /usr/bin/pax
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .deb at /usr/bin/ar
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .rar at /usr/bin/unrar
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .arj at /usr/bin/unarj
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .arc at /usr/bin/nomarch
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .zoo at /usr/bin/unzoo
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .cab at /usr/bin/cabextract
Dec 27 14:18:17 mail amavis[1222]: Internal decoder for .tnef
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .zip at /usr/bin/7za
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .kmz at /usr/bin/7za
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .7z at /usr/bin/7za
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .xz at /usr/bin/7z
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .lzma at /usr/bin/7z
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .jar at /usr/bin/7z
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .swf at /usr/bin/7z
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .lha at /usr/bin/7z
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .iso at /usr/bin/7z
Dec 27 14:18:17 mail amavis[1222]: Found decoder for .exe at /usr/bin/unrar; /usr/bin/unarj
Dec 27 14:18:17 mail amavis[1222]: Using primary internal av scanner code for ClamAV-clamd
Dec 27 14:18:17 mail amavis[1222]: Found secondary av scanner ClamAV-clamscan at /usr/bin/clamscan
Dec 27 14:18:17 mail amavis[1222]: Deleting db files __db.004,snmp.db,nanny.db,__db.001,__db.003,__db.002 in /var/spool/amavisd/db
Dec 27 14:18:17 mail amavis[1222]: Creating db in /var/spool/amavisd/db/; BerkeleyDB 0.43, libdb 4.7
Dec 27 14:18:20 mail postfix/postfix-script[1305]: starting the Postfix mail system
Dec 27 14:18:21 mail postfix/master[1306]: daemon started -- version 2.6.6, configuration /etc/postfix
Dec 27 14:20:17 mail amavis[1480]: starting. /usr/sbin/amavisd at mail.test.com amavisd-new-2.9.1 (20140627), Unicode aware, LANG="en_US.UTF-8"
Dec 27 14:20:17 mail amavis[1481]: Net::Server: Group Not Defined. Defaulting to EGID '496 496'
Dec 27 14:20:17 mail amavis[1481]: Net::Server: User Not Defined. Defaulting to EUID '496'
Dec 27 14:20:17 mail amavis[1481]: Module Amavis::Conf 2.321
Dec 27 14:20:17 mail amavis[1481]: Module Archive::Zip 1.30
Dec 27 14:20:17 mail amavis[1481]: Module BerkeleyDB 0.43
Dec 27 14:20:17 mail amavis[1481]: Module Compress::Raw::Zlib 2.021
Dec 27 14:20:17 mail amavis[1481]: Module Compress::Zlib 2.021
Dec 27 14:20:17 mail amavis[1481]: Module Crypt::OpenSSL::RSA 0.25
Dec 27 14:20:17 mail amavis[1481]: Module DBD::mysql 4.013
Dec 27 14:20:17 mail amavis[1481]: Module DBI 1.609
Dec 27 14:20:17 mail amavis[1481]: Module DB_File 1.82
Dec 27 14:20:17 mail amavis[1481]: Module Digest::MD5 2.39
Dec 27 14:20:17 mail amavis[1481]: Module Digest::SHA 5.47
Dec 27 14:20:17 mail amavis[1481]: Module Encode 2.35
Dec 27 14:20:17 mail amavis[1481]: Module File::Temp 0.22
Dec 27 14:20:17 mail amavis[1481]: Module IO::Socket::INET6 2.56
Dec 27 14:20:17 mail amavis[1481]: Module MIME::Entity 5.427
Dec 27 14:20:17 mail amavis[1481]: Module MIME::Parser 5.427
Dec 27 14:20:17 mail amavis[1481]: Module MIME::Tools 5.427
Dec 27 14:20:17 mail amavis[1481]: Module Mail::DKIM::Signer 0.37
Dec 27 14:20:17 mail amavis[1481]: Module Mail::DKIM::Verifier 0.37
Dec 27 14:20:17 mail amavis[1481]: Module Mail::Header 2.04
Dec 27 14:20:17 mail amavis[1481]: Module Mail::Internet 2.04
Dec 27 14:20:17 mail amavis[1481]: Module Mail::SPF v2.008
Dec 27 14:20:17 mail amavis[1481]: Module Mail::SpamAssassin 3.003001
Dec 27 14:20:17 mail amavis[1481]: Module Net::DNS 0.65
Dec 27 14:20:17 mail amavis[1481]: Module Net::Server 2.007
Dec 27 14:20:17 mail amavis[1481]: Module NetAddr::IP 4.027
Dec 27 14:20:17 mail amavis[1481]: Module Razor2::Client::Version 2.84
Dec 27 14:20:17 mail amavis[1481]: Module Scalar::Util 1.21
Dec 27 14:20:17 mail amavis[1481]: Module Socket 1.82
Dec 27 14:20:17 mail amavis[1481]: Module Socket6 0.23
Dec 27 14:20:17 mail amavis[1481]: Module Time::HiRes 1.9721
Dec 27 14:20:17 mail amavis[1481]: Module URI 1.40
Dec 27 14:20:17 mail amavis[1481]: Module Unix::Syslog 1.1
Dec 27 14:20:17 mail amavis[1481]: Amavis::ZMQ code NOT loaded
Dec 27 14:20:17 mail amavis[1481]: Amavis::DB code loaded
Dec 27 14:20:17 mail amavis[1481]: SQL base code loaded
Dec 27 14:20:17 mail amavis[1481]: SQL::Log code loaded
Dec 27 14:20:17 mail amavis[1481]: SQL::Quarantine loaded
Dec 27 14:20:17 mail amavis[1481]: Lookup::SQL code loaded
Dec 27 14:20:17 mail amavis[1481]: Lookup::LDAP code NOT loaded
Dec 27 14:20:17 mail amavis[1481]: AM.PDP-in proto code loaded
Dec 27 14:20:17 mail amavis[1481]: SMTP-in proto code loaded
Dec 27 14:20:17 mail amavis[1481]: Courier proto code NOT loaded
Dec 27 14:20:17 mail amavis[1481]: SMTP-out proto code loaded
Dec 27 14:20:17 mail amavis[1481]: Pipe-out proto code NOT loaded
Dec 27 14:20:17 mail amavis[1481]: BSMTP-out proto code NOT loaded
Dec 27 14:20:17 mail amavis[1481]: Local-out proto code NOT loaded
Dec 27 14:20:17 mail amavis[1481]: OS_Fingerprint code NOT loaded
Dec 27 14:20:17 mail amavis[1481]: ANTI-VIRUS code loaded
Dec 27 14:20:17 mail amavis[1481]: ANTI-SPAM code loaded
Dec 27 14:20:17 mail amavis[1481]: ANTI-SPAM-EXT code NOT loaded
Dec 27 14:20:17 mail amavis[1481]: ANTI-SPAM-C code NOT loaded
Dec 27 14:20:17 mail amavis[1481]: ANTI-SPAM-SA code loaded
Dec 27 14:20:17 mail amavis[1481]: Unpackers code loaded
Dec 27 14:20:17 mail amavis[1481]: DKIM code loaded
Dec 27 14:20:17 mail amavis[1481]: Tools code NOT loaded
Dec 27 14:20:17 mail amavis[1481]: Found $file at /usr/bin/file
Dec 27 14:20:17 mail amavis[1481]: Found $altermime at /usr/bin/altermime
Dec 27 14:20:17 mail amavis[1481]: Internal decoder for .mail
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .F at /usr/bin/unfreeze
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .Z at /usr/bin/gzip -d
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .gz at /usr/bin/gzip -d
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .bz2 at /usr/bin/bzip2 -d
Dec 27 14:20:17 mail amavis[1481]: No ext program for .xz, tried: xzdec, xz -dc, unxz -c, xzcat
Dec 27 14:20:17 mail amavis[1481]: No ext program for .lzma, tried: lzmadec, xz -dc --format=lzma, lzma -dc, unlzma -c, lzcat, lzmadec
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .lrz at /usr/bin/lrzip -q -k -d -o -
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .lzo at /usr/bin/lzop -d
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .rpm at /usr/bin/rpm2cpio
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .cpio at /usr/bin/pax
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .tar at /usr/bin/pax
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .deb at /usr/bin/ar
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .rar at /usr/bin/unrar
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .arj at /usr/bin/unarj
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .arc at /usr/bin/nomarch
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .zoo at /usr/bin/unzoo
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .cab at /usr/bin/cabextract
Dec 27 14:20:17 mail amavis[1481]: Internal decoder for .tnef
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .zip at /usr/bin/7za
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .kmz at /usr/bin/7za
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .7z at /usr/bin/7za
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .xz at /usr/bin/7z
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .lzma at /usr/bin/7z
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .jar at /usr/bin/7z
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .swf at /usr/bin/7z
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .lha at /usr/bin/7z
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .iso at /usr/bin/7z
Dec 27 14:20:17 mail amavis[1481]: Found decoder for .exe at /usr/bin/unrar; /usr/bin/unarj
Dec 27 14:20:17 mail amavis[1481]: Using primary internal av scanner code for ClamAV-clamd
Dec 27 14:20:17 mail amavis[1481]: Found secondary av scanner ClamAV-clamscan at /usr/bin/clamscan
Dec 27 14:20:17 mail amavis[1481]: Deleting db files __db.004,snmp.db,nanny.db,__db.001,__db.003,__db.002 in /var/spool/amavisd/db
Dec 27 14:20:17 mail amavis[1481]: Creating db in /var/spool/amavisd/db/; BerkeleyDB 0.43, libdb 4.7
Dec 27 14:33:33 mail postfix/submission/smtpd[1513]: connect from mail.test.com[127.0.0.1]
Dec 27 14:33:33 mail postfix/submission/smtpd[1513]: setting up TLS connection from mail.test.com[127.0.0.1]
Dec 27 14:33:33 mail postfix/submission/smtpd[1513]: Anonymous TLS connection established from mail.test.com[127.0.0.1]: TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)
Dec 27 14:33:34 mail postfix/submission/smtpd[1513]: BE26F40B5D: client=mail.test.com[127.0.0.1], sasl_method=LOGIN, sasl_username=mac@test.com
Dec 27 14:33:37 mail postfix/cleanup[1522]: BE26F40B5D: message-id=<264ef0034f22bcafb2092d03c0673ccb@test.com>
Dec 27 14:33:38 mail postfix/qmgr[1313]: BE26F40B5D: from=<mac@test.com>, size=1471, nrcpt=1 (queue active)
Dec 27 14:33:38 mail roundcube: <0huoj4rd> User mac@test.com [192.168.1.199]; Message for mike@test.com; 250: 2.0.0 Ok: queued as BE26F40B5D
Dec 27 14:33:41 mail postfix/submission/smtpd[1513]: disconnect from mail.test.com[127.0.0.1]
Dec 27 14:33:43 mail postfix/smtpd[1542]: connect from mail.test.com[127.0.0.1]
Dec 27 14:33:43 mail postfix/smtpd[1542]: EABE8411F0: client=mail.test.com[127.0.0.1]
Dec 27 14:33:43 mail postfix/cleanup[1522]: EABE8411F0: message-id=<264ef0034f22bcafb2092d03c0673ccb@test.com>
Dec 27 14:33:44 mail postfix/qmgr[1313]: EABE8411F0: from=<mac@test.com>, size=2546, nrcpt=1 (queue active)
Dec 27 14:33:44 mail postfix/smtpd[1542]: disconnect from mail.test.com[127.0.0.1]
Dec 27 14:33:44 mail amavis[1484]: (01484-01) Passed CLEAN {RelayedInternal}, ORIGINATING/MYNETS LOCAL [127.0.0.1]:33826 -> , Message-ID: , mail_id: Cspo5BgsY12G, Hits: -, size: 1471, queued_as: EABE8411F0, dkim_new=dkim:test.com, 5961 ms
Dec 27 14:33:44 mail postfix/smtp[1528]: BE26F40B5D: to=<mike@test.com>, relay=127.0.0.1[127.0.0.1]:10026, delay=11, delays=4/0.21/0.01/6.6, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as EABE8411F0)
Dec 27 14:33:44 mail postfix/qmgr[1313]: BE26F40B5D: removed
Dec 27 14:33:45 mail postfix/pipe[1545]: EABE8411F0: to=<mike@test.com>, relay=dovecot, delay=1.8, delays=0.24/0.55/0/1, dsn=2.0.0, status=sent (delivered via dovecot service)
Dec 27 14:33:45 mail postfix/qmgr[1313]: EABE8411F0: removed