Which AV is right :) ?

Jay Ehrhart yoloits at ycoe.org
Thu Aug 12 17:44:48 IST 2004


<x-html>
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=Content-Type content="text/html; charset=iso-8859-1">
<META content="MSHTML 6.00.2800.1458" name=GENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY>
<DIV>I have found just the opposite.&nbsp; I run Calmav and F-prot both check 
for updates every hour.&nbsp; Clamav frequently finds viruses that F-prot hasn't 
been updated to see.&nbsp; For example:</DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=Arial size=2>MessageID: i79K0kEA006340<BR>&nbsp;&nbsp;&nbsp; 
Report: ClamAV: price_new.zip contains Trojan.JS.RunMe 
<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ClamAV: 
price.exe contains Worm.Bagle.AI 
<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 
MailScanner: Executable DOS/Windows programs are dangerous in email 
(price.exe)<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 
ClamAV: price.html contains Trojan.JS.RunMe <BR>&nbsp;&nbsp;&nbsp; Report: 
ClamAV: price.exe contains Worm.Bagle.AI 
<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 
MailScanner: Executable DOS/Windows programs are dangerous in email 
(price.exe)<BR>&nbsp;&nbsp;&nbsp; Report: ClamAV: price.html contains 
Trojan.JS.RunMe </FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=Arial size=2>And</FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=Arial size=2>MessageID: i7CFYJdv011960<BR>&nbsp;&nbsp;&nbsp; 
Report: MailScanner: Message contained password-protected 
archive<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 
ClamAV: text_document.zip contains Worm.Bagle.Gen-zippwd </FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=Arial size=2>This what it looks like when both catch a 
virus:</FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=Arial size=2>MessageID: i7BFvmfe013859<BR>&nbsp;&nbsp;&nbsp; 
Report: F-Prot: 
/var/spool/MailScanner/incoming/5595/i7BFvmfe013859/your_picture.pif&nbsp; 
Infection: <A 
href="mailto:W32/Netsky.D at mm">W32/Netsky.D at mm</A><BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 
ClamAV: your_picture.pif contains Worm.SomeFool.Gen-1 
<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 
MailScanner: Shortcuts to MS-Dos programs are very dangerous in email 
(your_picture.pif)<BR></FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV>&nbsp;</DIV>
<DIV>&nbsp;</DIV>
<DIV>----- Original Message ----- 
<DIV>From: "Christiaan den Besten" &lt;<A 
href="mailto:chris at scorpion.nl">chris at scorpion.nl</A>&gt;</DIV>
<DIV>To: &lt;<A 
href="mailto:MAILSCANNER at JISCMAIL.AC.UK">MAILSCANNER at JISCMAIL.AC.UK</A>&gt;</DIV>
<DIV>Sent: Thursday, August 12, 2004 5:16 AM</DIV>
<DIV>Subject: Which AV is right :) ?</DIV></DIV>
<DIV><BR></DIV>&gt; Hi !<BR>&gt; <BR>&gt; Just completed a small test to see if 
F-Prot finds viruses Clam passed as<BR>&gt; virusfree ..... and yes .. it 
did.<BR>&gt; <BR>&gt; But: I am not yet convinced if F-Prot is doing the 'Right 
thing TM :)"<BR>&gt; <BR>&gt; Scenario:<BR>&gt; 
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; - 1. An email containing a virus as 
an attachment is send to a<BR>&gt; foreign mailserver.<BR>&gt; 
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; - 2. Foreign mailserver bounces the 
message attaching the complete<BR>&gt; message in mbox format in de message 
body.<BR>&gt; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; - 3. Clam scans the 
messages -&gt; No virus found<BR>&gt; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 
- 4. F-Prot scans the message -&gt; Zafi.B found ....<BR>&gt; <BR>&gt; - The 
actual virus is in de mbox formatted body ... this is not executable<BR>&gt; by 
a normal user if he/she receives it ?<BR>&gt; - "Clamscan --mbox [body of msg]" 
does find the Zafi.B virus.<BR>&gt; <BR>&gt; Should MailScanner do a double 
check ?.. one with and one without de mbox<BR>&gt; parameter, or is F-Prot just 
to paranoid ?<BR>&gt; <BR>&gt; Which is right ?<BR>&gt; <BR>&gt; bye,<BR>&gt; 
Chrs<BR>&gt; <BR>&gt; ------------------------ MailScanner list 
------------------------<BR>&gt; To unsubscribe, email <A 
href="mailto:jiscmail at jiscmail.ac.uk">jiscmail at jiscmail.ac.uk</A> with the 
words:<BR>&gt; 'leave mailscanner' in the body of the email.<BR>&gt; Before 
posting, read the MAQ (<A 
href="http://www.mailscanner.biz/maq/">http://www.mailscanner.biz/maq/</A>) 
and<BR>&gt; the archives (<A 
href="http://www.jiscmail.ac.uk/lists/mailscanner.html">http://www.jiscmail.ac.uk/lists/mailscanner.html</A>).</BODY></HTML>
------------------------ MailScanner list ------------------------
To unsubscribe, email <a href="jiscmail at jiscmail.ac.uk">jiscmail at jiscmail.ac.uk</a>
with the words:<br>
'leave mailscanner' in the body of the email.<br>
Before posting, read the MAQ (<a href="http://www.mailscanner.biz/maq/">http://www.mailscanner.biz/maq/</a>)<br>and
the archives (<a href="http://www.jiscmail.ac.uk/lists/mailscanner.html">http://www.jiscmail.ac.uk/lists/mailscanner.html</a>).
</x-html>



More information about the MailScanner mailing list