Scott,

Unfortunately (actually a good thing), all the virus e-mails I have left in
the \virus directory are bounces from other servers. I don't have a Sobig.F
attachment available to test. Once I receive one, I'll re-test.

Thanks,

Bill

> ---------- Original Message ----------------------------------
> From: "R. Scott Perry" <[EMAIL PROTECTED]>
> Reply-To: [EMAIL PROTECTED]
> Date:  Thu, 21 Aug 2003 14:59:18 -0400
> 
> 
> >I did that with eicar and the On-Demand Scanner picked it 
> up. However, 
> >when I did it with Sobig.F, there was no attachment. Then I noticed 
> >that it was a bounced message from another server (not using 
> >SKIPIFVIRUSNAMEHAS). I'm now wondering if that is why McAfee 
> >On-Demand/Declude is not picking it up, because the virus is part of 
> >the bounced message and it appears to not be executable. However, 
> >F-Prot and McAfee On-Access both detect Sobig.F in the SMD file. ??
> 
> Most AV programs will not detect corrupt, non-viable 
> variants, which often 
> includes bounce messages (because those bounce messages are 
> usually truncated).
> 
>                                                     -Scott
> ---
> Declude JunkMail: The advanced anti-spam solution for IMail 
> mailservers. Declude Virus: Catches known viruses and is the 
> leader in mailserver 
> vulnerability detection.
> Find out what you have been missing: Ask for a free 30-day evaluation.
> 
> ---
> [This E-mail was scanned for viruses by Declude Virus 
(http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To unsubscribe, just
send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to