Antivir and Clam patches

Julian Field mailscanner at ecs.soton.ac.uk
Fri Aug 13 19:35:53 IST 2004


<x-flowed>
It is often very difficult (as it is in this case) to attempt to extract
the virus name, sorry.

It 19:08 13/08/2004, you wrote:
>Hi there,
>
>another strange thing happening with these rar-files..
>
>as i do send the exact same file within a zip-file i do get this mail to
>the postmaster:
>
>Subject: Bad Filename Detected : Virus Detected
>Content:
>
>The following e-mails were found to have:Bad Filename Detected : Virus
>Detected
>
>     Sender: emailcheck-robot at ct.heise.de
>IP Address: 193.99.144.71
>  Recipient: marcel at irc-addicts.de
>    Subject: c't-Emailcheck: EICAR-ZIP (uiycctx)
>  MessageID: i7DI3lV9023794
>     Report: ClamAV: eicar.com contains Eicar-Test-Signature
>             AntiVir: ALERT: [Eicar-Test-Signatur virus]
>./i7DI3lV9023794/eicar.com
><<< Contains code of the Eicar-Test-Signatur virus
>             F-Prot:
>/var/spool/MailScanner/incoming/23395/i7DI3lV9023794/eicar.com
>Infection: EICAR_Test_File
>             MailScanner: Executable DOS/Windows programs are dangerous in
>email (eicar.com)
>     Report: ClamAV: eicar.zip contains Eicar-Test-Signature
>             AntiVir: ALERT: [Eicar-Test-Signatur virus]
>./i7DI3lV9023794/eicar.zip
>--> eicar.com <<< Contains code of the Eicar-Test-Signatur virus
>             F-Prot:
>/var/spool/MailScanner/incoming/23395/i7DI3lV9023794/eicar.zip->eicar.com
>Infection: EICAR_Test_File
>             ClamAV: eicar.com contains Eicar-Test-Signature
>             AntiVir: ALERT: [Eicar-Test-Signatur virus]
>./i7DI3lV9023794/eicar.com
><<< Contains code of the Eicar-Test-Signatur virus
>             F-Prot:
>/var/spool/MailScanner/incoming/23395/i7DI3lV9023794/eicar.com
>Infection: EICAR_Test_File
>             MailScanner: Executable DOS/Windows programs are dangerous in
>email (eicar.com)
>
>
>If i do send the same file within a rar-file, i do get this one:
>
>Subject: Virus Detected
>
>content:
>
>The following e-mails were found to have:Virus Detected
>
>     Sender: emailcheck-robot at ct.heise.de
>IP Address: 193.99.144.71
>  Recipient: marcel at irc-addicts.de
>    Subject: c't-Emailcheck: EICAR-RAR (qomobjz)
>  MessageID: i7DHuHV9023400
>     Report: ClamAV: eicar.rar contains a virus
>
>
>Ok..the virus did not get through..but within the logfile there is the
>entry what kind of virus it is..and it would be great for the user and the
>postmaster to see, what kind of virus tries to sneak in..
>
>in the past this worked fine..at least at my place :(
>
>or maybe i am a bit..over the edge?
>
>Greetings
>
>Marcel
>
>------------------------ MailScanner list ------------------------
>To unsubscribe, email jiscmail at jiscmail.ac.uk with the words:
>'leave mailscanner' in the body of the email.
>Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and
>the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html).

--
Julian Field
www.MailScanner.info
Professional Support Services at www.MailScanner.biz
MailScanner thanks transtec Computers for their support
PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654

------------------------ MailScanner list ------------------------
To unsubscribe, email jiscmail at jiscmail.ac.uk with the words:
'leave mailscanner' in the body of the email.
Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and
the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html).
</x-flowed>



More information about the MailScanner mailing list