Virus
The virus field is in most FortiMail log messages where type=statistics.
The field indicates the name of the virus that was detected, such as virus="W32/ZeroAccess.B!tr".
This field is empty if no virus was detected, or if the archive decompression limit or file size limit was exceeded and therefore the scan could not deliver a verdict about whether the attachment contained malware.