virus from 'support@microsoft.com' not blocked?

Craig Pratt craig at STRONG-BOX.NET
Tue May 27 22:23:17 IST 2003


On Tuesday, May 27, 2003, at 02:02  PM, Raymond Dijkxhoorn wrote:
> Hi!
>
>> RavAV's been catching it w/o issue:
>>
>> The following e-mail messages were found to have dangerous content:
>>
>>      Sender: support at microsoft.com
>> IP Address: 68.4.203.36
>>   Recipient: [chomp]
>>     Subject: Re: Movie
>>   MessageID: h4MJ12gC000237
>>      Report: ./h4MJ12gC000237/your_details.pif  Infected:
>> Win32/Sobig.B at mm
>> Shortcuts to MS-Dos programs are very dangerous in email
>> (your_details.pif)
>
> Sorry, there are various versions of this virus floating around. RAV
> dont
> pick them up all. Really. We have a open case by RAV for this. I have
> seen f-prot picking up them all, McAfee and RAV did pass some variants.
>
> Bye,
> Raymond.

Yikes - thanks for the heads-up! I'll keep an eye out for this.

I hope/presume the filename rule still blocked them?

Craig

---
Craig Pratt
Strongbox Network Services Inc.
mailto:craig at strong-box.net


--
This message checked for dangerous content by MailScanner on StrongBox.



More information about the MailScanner mailing list