> > It's me again. Here is how Trend Micro's viruscan works. > If an email is infected, it tries to clean it, otherwise > deletes the attachment but still forwards the email to > the recipient but with no more attachment.
Semi-amusing cleaning story (happened today) We intercepted an email that had already been through an anti-virus gateway. The gateway product detected a viral component in the HTML part of the email, and duly cleaned and removed it. Now, this HTML part is actually a well known exploit (ms01-020), used by many viruses to run an attachment when reading or previewing the email. Unfortunately, the attachment in question was a new virus, so the gateway product did not detect it. The net result was that part of the virus was removed, but the rest (including the exe component of the virus) is then forwarded to the eventual recipient. Oops. Alex ________________________________________________________________________ This email has been scanned for all viruses by the MessageLabs SkyScan service. For more information on a proactive anti-virus service working around the clock, around the globe, visit http://www.messagelabs.com ________________________________________________________________________ _______________________________________________________________ Hundreds of nodes, one monster rendering program. Now that's a super model! Visit http://clustering.foundries.sf.net/ _______________________________________________ Qmail-scanner-general mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general