Virus or not?

Joined
24 Sep 2005
Messages
6,345
Reaction score
268
Country
United Kingdom
I run NSW 2005.

IE set not open mail automatically and to read as text only.

For around a year or so I have occasionally marked 'dodgy' e-mails as 'read' and parked them in associated folders - paypal, BankOther etc

Carried out Kaspersky on-line check up.
Among my fifty or so presumed 'dodgy' mails it found some interesting stuff.
[code:1]Scan Statistics:
Total number of scanned objects: 44340
Number of viruses found: 7
Number of infected objects: 27 / 0
Number of suspicious objects: 0
Duration of the scan process: 00:55:46

eg.
html Infected: Trojan-Spy.HTML.Bankfraud.hs
html Infected: Trojan-Spy.HTML.Paylap.bj
html Infected: Trojan-Spy.HTML.Bayfraud.kl
Norton AntiVirus\Quarantine\130B4AFA.DOC/ThisDocument Infected: Virus.MSWord.Marker.kl
[/code:1]
All this from amongst the dodgy mail, apart from 1 file seen as a virus but already 'quarantined' by Norton.
All dodgy mails with 'attached files' had been caught by ZoneAlarm, which had appended extensions similar to Zl1, Zl2 etc ... Thus during an attempt to open the attachment, ZA intercepts with a warning, offering different methods for opening the files... Seems pretty safe !

So, Kaspersky lived up to it's claim of finding stuff other AV's miss.
I was surprised that NAV (rescanned email IE .DBX files) failed to find the stuff in the 'dodgy' e-mails... If, of course they actually were 'dodgy' and not just false positives.

Anyway, I found this site which will send the Eicar.com virus test file

http://shopping.declude.com/Articles.asp?ID=99

...There are lots of different ways that attachments can be sent through E-mail. Because of this, we have a number of different choices for sending the eicar.com file. Your anti-virus software should catch them all (except 'eicarprescan' and 'eicarclsid', which do not have to get caught). If your virus scanner does not detect some of these files, it may allow some viruses through!...

The AV results after using the site were quite surprising ... Even with a Kasp rescan.

BTW Of interest to users of IE and Outlook, I am sure someone was recently looking for the latter part of this info'..
http://www.ontrack.co.uk/restore/email-data.aspx

:confused:
 
Sponsored Links
Back
Top