Hi,
heuristic analysis works in different way from classic scan, which compares important parts of scanned object with VPS (database of known viruses). Heuristic analysis tries to find unknown viruses (not known yet). So when classic scan doesn't catch anything and heuristic analysis warns you, it's OK. BUT! You should configure heuristic settings according your "style of work" to avoid false alarms. Problem you described is, I think, that you are sending attachment with extension which is on the blacklist (dangerous file extensions - e.g. EXE, COM, ...). It's true?
thanks,
pavels