Scott, Unfortunately (actually a good thing), all the virus e-mails I have left in the \virus directory are bounces from other servers. I don't have a Sobig.F attachment available to test. Once I receive one, I'll re-test.
Thanks, Bill > ---------- Original Message ---------------------------------- > From: "R. Scott Perry" <[EMAIL PROTECTED]> > Reply-To: [EMAIL PROTECTED] > Date: Thu, 21 Aug 2003 14:59:18 -0400 > > > >I did that with eicar and the On-Demand Scanner picked it > up. However, > >when I did it with Sobig.F, there was no attachment. Then I noticed > >that it was a bounced message from another server (not using > >SKIPIFVIRUSNAMEHAS). I'm now wondering if that is why McAfee > >On-Demand/Declude is not picking it up, because the virus is part of > >the bounced message and it appears to not be executable. However, > >F-Prot and McAfee On-Access both detect Sobig.F in the SMD file. ?? > > Most AV programs will not detect corrupt, non-viable > variants, which often > includes bounce messages (because those bounce messages are > usually truncated). > > -Scott > --- > Declude JunkMail: The advanced anti-spam solution for IMail > mailservers. Declude Virus: Catches known viruses and is the > leader in mailserver > vulnerability detection. > Find out what you have been missing: Ask for a free 30-day evaluation. > > --- > [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.
