Re: [Exim] Encrypted Viruii

Top Page
Delete this message
Reply to this message
Author: Ron McKeating
Date:  
To: Wakko Warner
CC: exim-users
Subject: Re: [Exim] Encrypted Viruii

On Wed, 2004-03-03 at 12:21, Wakko Warner wrote:
> >     Ron> As the anti virus software cannot open the zip it cannot find
> >     Ron> the virus, so what is the best approach. I was wondering if

> >
> > Surely that is not true - Trend Micro at least catches BAGLE.F/G which
> > are password protected zips, and clamav also caught the only BAGLE.F I
> > have seen at work. Presumably they have a way of testing for the virus
> > without opening it, don't ask me how though.
>
> The same as it traps any other virus I would assume.

If the attachment has been encrypted then there is no way the virus
scanner can see the virus inside it. I recieved 4 last night when
I save the attachement it is called "MoreInfo.zip".
If I run the virus scanner against this file then it comes up clean.
However if I try to unzip it it asks for a password, the password was
in the body of the message.

Are you saying your virus scanner can read data inside an encrypted file
???

> --
> Lab tests show that use of micro$oft causes cancer in lab animals
>
> --
>
> ## List details at http://www.exim.org/mailman/listinfo/exim-users Exim details at http://www.exim.org/ ##

--
Ron McKeating
Senior IT Services Specialist
Internet Services and Software Solutions
Loughborough University
01509 222329