Discussion:
What happened to RR virus scanning?
(too old to reply)
Kathy
2005-04-13 15:23:17 UTC
Permalink
Is something up with RR's Symantec virus scanning?

I just received my 6th email this morning with attached executable file
intact (2 batch files (.bat), 3 screen savers (.scr), and the latest a zip
file).

- Kathy
Damian
2005-04-13 15:39:59 UTC
Permalink
Post by Kathy
Is something up with RR's Symantec virus scanning?
I just received my 6th email this morning with attached executable
file intact (2 batch files (.bat), 3 screen savers (.scr), and the
latest a zip file).
- Kathy
You _DO_ realize that Roadrunner is AOL, don't you.

Think of "incompetent"!
Kathy
2005-04-13 16:21:06 UTC
Permalink
Three more just arrived, all of these are zip's, but they WERE scanned,

Maybe RR needs to update their definitions?

- Kathy

----------------------------------------

Return-path: <***@edmark.com>
Received: from ms-mta-02.socal.rr.com
(ms-mta-02-smtp.socal.rr.com [10.10.4.126]) by ms-mss-04.socal.rr.com
(iPlanet Messaging Server 5.2 HotFix 1.21 (built Sep 8 2003))
with ESMTP id <***@ms-mss-04.socal.rr.com> for ***@san.rr.com;
Wed, 13 Apr 2005 08:54:20 -0700 (PDT)
Received: from nymx04.mgw.rr.com (nymx04.mgw.rr.com [24.92.226.25])
by ms-mta-02.socal.rr.com
(iPlanet Messaging Server 5.2 HotFix 1.21 (built Sep 8 2003))
with ESMTP id <***@ms-mta-02.socal.rr.com> for ***@san.rr.com
(ORCPT ***@san.rr.com); Wed, 13 Apr 2005 08:54:19 -0700 (PDT)
Received: from hrndva-mx-03.mgw.rr.com (hrndva-mx-03.mgw.rr.com
[24.28.204.22])
by nymx04.mgw.rr.com (8.12.10/8.12.8) with ESMTP id j3DFpYXk010992 for
<***@san.rr.com>; Wed, 13 Apr 2005 11:54:16 -0400 (EDT)
Received: from m1.dnsix.com (63.251.171.164) by hrndva-mx-03.mgw.rr.com with
ESMTP; Wed, 13 Apr 2005 11:54:09 -0400
Received: from [69.162.227.235] (helo=edmark.com) by m1.dnsix.com with esmtp
(Exim 4.44) id 1DLkAq-000254-0Y for ***@xxxx.com; Wed,
13 Apr 2005 08:53:05 -0700
Date: Wed, 13 Apr 2005 11:53:16 -0400
From: ***@edmark.com
Subject: Server Report
To: ***@xxxx.com
Message-id: <3j20ih$***@hrndva-mx-03.mgw.rr.com>
MIME-version: 1.0
Content-type: multipart/mixed;
boundary="----=_NextPart_000_0011_7EFCD6AE.7BC7E1D4"
X-Priority: 3
X-MSMail-priority: Normal
X-Virus-Scanned: Symantec AntiVirus Scan Engine
Original-recipient: rfc822;***@san.rr.com

This is a multi-part message in MIME format.

------=_NextPart_000_0011_7EFCD6AE.7BC7E1D4
Content-Type: text/plain;
charset="Windows-1252"
Content-Transfer-Encoding: 7bit

The message cannot be represented in 7-bit ASCII encoding and has been sent
as a binary attachment.


------=_NextPart_000_0011_7EFCD6AE.7BC7E1D4
Content-Type: application/octet-stream;
name="readme.zip"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename="readme.zip"

----------------------------------------

Return-path: <***@wolfcreekinc.com>
Received: from ms-mta-02.socal.rr.com
(ms-mta-02-smtp.socal.rr.com [10.10.4.126]) by ms-mss-04.socal.rr.com
(iPlanet Messaging Server 5.2 HotFix 1.21 (built Sep 8 2003))
with ESMTP id <***@ms-mss-04.socal.rr.com> for ***@san.rr.com;
Wed, 13 Apr 2005 07:39:26 -0700 (PDT)
Received: from lamx02.mgw.rr.com (lamx02.mgw.rr.com [66.75.160.13])
by ms-mta-02.socal.rr.com
(iPlanet Messaging Server 5.2 HotFix 1.21 (built Sep 8 2003))
with ESMTP id <***@ms-mta-02.socal.rr.com> for ***@san.rr.com
(ORCPT ***@san.rr.com); Wed, 13 Apr 2005 07:39:26 -0700 (PDT)
Received: from clmboh-mx-03.mgw.rr.com (clmboh-mx-03.mgw.rr.com
[65.24.7.12])
by lamx02.mgw.rr.com (8.12.10/8.12.8) with ESMTP id j3DEYShX017862 for
<***@san.rr.com>; Wed, 13 Apr 2005 10:39:21 -0400 (EDT)
Received: from m1.dnsix.com (63.251.171.167) by clmboh-mx-03.mgw.rr.com with
ESMTP; Wed, 13 Apr 2005 10:39:14 -0400
Received: from [69.162.227.235] (helo=wolfcreekinc.com)
by m1.dnsix.com with esmtp (Exim 4.44) id 1DLj1I-0002Nh-Cx for
***@xxxx.com;
Wed, 13 Apr 2005 07:39:13 -0700
Date: Wed, 13 Apr 2005 10:39:20 -0400
From: ***@wolfcreekinc.com
Subject: Mail Transaction Failed
To: ***@xxxx.com
Message-id: <3r1fbb$***@clmboh-mx-03.mgw.rr.com>
MIME-version: 1.0
Content-type: multipart/mixed;
boundary="----=_NextPart_000_0001_05B0E72C.82C85458"
X-Priority: 3
X-MSMail-priority: Normal
X-Virus-Scanned: Symantec AntiVirus Scan Engine
Original-recipient: rfc822;***@san.rr.com

This is a multi-part message in MIME format.

------=_NextPart_000_0001_05B0E72C.82C85458
Content-Type: text/plain;
charset="Windows-1252"
Content-Transfer-Encoding: 7bit

The message contains Unicode characters and has been sent as a binary
attachment.


------=_NextPart_000_0001_05B0E72C.82C85458
Content-Type: application/octet-stream;
name="document.zip"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename="document.zip"

----------------------------------------

Return-path: <***@sc.rr.com>
Received: from ms-mta-01.socal.rr.com
(ms-mta-01-smtp.socal.rr.com [10.10.4.125]) by ms-mss-04.socal.rr.com
(iPlanet Messaging Server 5.2 HotFix 1.21 (built Sep 8 2003))
with ESMTP id <***@ms-mss-04.socal.rr.com> for ***@san.rr.com;
Wed, 13 Apr 2005 08:59:04 -0700 (PDT)
Received: from nycmx01.mgw.rr.com (nycmx01.mgw.rr.com [24.29.99.40])
by ms-mta-01.socal.rr.com
(iPlanet Messaging Server 5.2 HotFix 1.21 (built Sep 8 2003))
with ESMTP id <***@ms-mta-01.socal.rr.com> for ***@san.rr.com
(ORCPT ***@san.rr.com); Wed, 13 Apr 2005 08:59:04 -0700 (PDT)
Received: from hrndva-mx-03.mgw.rr.com (hrndva-mx-03.mgw.rr.com
[24.28.204.22])
by nycmx01.mgw.rr.com (8.12.10/8.12.8) with ESMTP id j3DFvRV4004606 for
<***@san.rr.com>; Wed, 13 Apr 2005 11:58:54 -0400 (EDT)
Received: from m1.dnsix.com (63.251.171.164) by hrndva-mx-03.mgw.rr.com with
ESMTP; Wed, 13 Apr 2005 11:58:35 -0400
Received: from [69.162.227.235] (helo=sc.rr.com) by m1.dnsix.com with esmtp
(Exim 4.44) id 1DLkFt-0004tM-4I for ***@xxxx.com; Wed,
13 Apr 2005 08:58:19 -0700
Date: Wed, 13 Apr 2005 11:58:29 -0400
From: ***@sc.rr.com
Subject: Good day
To: ***@xxxx.com
Message-id: <3j20ih$***@hrndva-mx-03.mgw.rr.com>
MIME-version: 1.0
Content-type: multipart/mixed;
boundary="----=_NextPart_000_0014_74031FA8.155D4BEE"
X-Priority: 3
X-MSMail-priority: Normal
X-Virus-Scanned: Symantec AntiVirus Scan Engine
Original-recipient: rfc822;***@san.rr.com


This is a multi-part message in MIME format.

------=_NextPart_000_0014_74031FA8.155D4BEE
Content-Type: text/plain;
charset="Windows-1252"
Content-Transfer-Encoding: 7bit

The message contains Unicode characters and has been sent as a binary
attachment.


------=_NextPart_000_0014_74031FA8.155D4BEE
Content-Type: application/octet-stream;
name="document.zip"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename="document.zip"
Frank ess
2005-04-13 16:42:27 UTC
Permalink
Post by Kathy
Is something up with RR's Symantec virus scanning?
I just received my 6th email this morning with attached executable
file intact (2 batch files (.bat), 3 screen savers (.scr), and the
latest a zip file).
- Kathy
I'm beginning to feel left out: no zips, no scrs, no if, ands, or bats.
Not even any Cyrilllic or kanji.

Where did I go wrong?
--
Frank ess
Kathy
2005-04-13 18:24:07 UTC
Permalink
Post by Frank ess
I'm beginning to feel left out: no zips, no scrs, no if, ands, or bats.
Not even any Cyrilllic or kanji.
Where did I go wrong?
If it would make you feel less left out, I'd be happy to forward mine to
you. I could even make it appear as if they came from Rangoon or somewhere
exotic :-)

- Kathy
relic
2005-04-13 17:23:16 UTC
Permalink
Post by Kathy
Is something up with RR's Symantec virus scanning?
I just received my 6th email this morning with attached executable
file intact (2 batch files (.bat), 3 screen savers (.scr), and the
latest a zip file).
Originally, they stated that it wouldn't be scanned when the system was too
busy. With all the spam they allow through, I would assume they have reached
the "too busy" stage.
--
If there is a Tourist Season, how come we can't shoot them?
Daniel Damouth
2005-04-13 19:01:39 UTC
Permalink
Post by relic
Post by Kathy
Is something up with RR's Symantec virus scanning?
I just received my 6th email this morning with attached
executable file intact (2 batch files (.bat), 3 screen savers
(.scr), and the latest a zip file).
Originally, they stated that it wouldn't be scanned when the
system was too busy. With all the spam they allow through, I would
assume they have reached the "too busy" stage.
All right! Now I can finally have my friends send me all those .bat
attachments I've been meaning to run without looking at.

Sweeeeeeeeeeeeeeeeeeeeet

-Dan Damouth
Kathy
2005-04-13 20:46:39 UTC
Permalink
OK, now it's PIF files, scanned by Symantec Antivirus.

I thought they stripped ALL executable files, but apparently not?

- Kathy


----------------------------------------

Return-path: <***@nisyndication.com>
Received: from ms-mta-02.socal.rr.com
(ms-mta-02-smtp.socal.rr.com [10.10.4.126]) by ms-mss-04.socal.rr.com
(iPlanet Messaging Server 5.2 HotFix 1.21 (built Sep 8 2003))
with ESMTP id <***@ms-mss-04.socal.rr.com> for ***@san.rr.com;
Wed, 13 Apr 2005 12:39:41 -0700 (PDT)
Received: from flmx04.mgw.rr.com (flmx04.mgw.rr.com [65.32.1.49])
by ms-mta-02.socal.rr.com
(iPlanet Messaging Server 5.2 HotFix 1.21 (built Sep 8 2003))
with ESMTP id <***@ms-mta-02.socal.rr.com> for ***@san.rr.com
(ORCPT ***@san.rr.com); Wed, 13 Apr 2005 12:39:41 -0700 (PDT)
Received: from clmboh-mx-01.mgw.rr.com (clmboh-mx-01.mgw.rr.com
[65.24.7.10])
by flmx04.mgw.rr.com (8.12.10/8.12.8) with ESMTP id j3DJcpSd000564 for
<***@san.rr.com>; Wed, 13 Apr 2005 15:39:34 -0400 (EDT)
Received: from m1.dnsix.com (63.251.171.164) by clmboh-mx-01.mgw.rr.com with
ESMTP; Wed, 13 Apr 2005 15:39:18 -0400
Received: from [69.162.227.235] (helo=nisyndication.com)
by m1.dnsix.com with esmtp (Exim 4.44) id 1DLnhf-00032w-E7 for
***@xxxx.com;
Wed, 13 Apr 2005 12:39:14 -0700
Date: Wed, 13 Apr 2005 15:39:23 -0400
From: ***@nisyndication.com
Subject: Good day
To: ***@xxxx.com
Message-id: <3r1dor$***@clmboh-mx-01.mgw.rr.com>
MIME-version: 1.0
Content-type: multipart/mixed;
boundary="----=_NextPart_000_0012_C5900FC7.46FBF12C"
X-Priority: 3
X-MSMail-priority: Normal
X-Virus-Scanned: Symantec AntiVirus Scan Engine
Original-recipient: rfc822;***@san.rr.com

This is a multi-part message in MIME format.

------=_NextPart_000_0012_C5900FC7.46FBF12C
Content-Type: text/plain;
charset="Windows-1252"
Content-Transfer-Encoding: 7bit

Mail transaction failed. Partial message is available.


------=_NextPart_000_0012_C5900FC7.46FBF12C
Content-Type: application/octet-stream;
name="document.pif"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename="document.pif"

----------------------------------------

Return-path: <***@bens-story.com>
Received: from ms-mta-03.socal.rr.com
(ms-mta-03-smtp.socal.rr.com [10.10.4.127]) by ms-mss-04.socal.rr.com
(iPlanet Messaging Server 5.2 HotFix 1.21 (built Sep 8 2003))
with ESMTP id <***@ms-mss-04.socal.rr.com> for ***@san.rr.com;
Wed, 13 Apr 2005 12:45:04 -0700 (PDT)
Received: from nymx01.mgw.rr.com (nymx01.mgw.rr.com [24.92.226.31])
by ms-mta-03.socal.rr.com
(iPlanet Messaging Server 5.2 HotFix 1.21 (built Sep 8 2003))
with ESMTP id <***@ms-mta-03.socal.rr.com> for ***@san.rr.com
(ORCPT ***@san.rr.com); Wed, 13 Apr 2005 12:45:04 -0700 (PDT)
Received: from clmboh-mx-03.mgw.rr.com (clmboh-mx-03.mgw.rr.com
[65.24.7.12])
by nymx01.mgw.rr.com (8.12.10/8.12.8) with ESMTP id j3DJgean007577 for
<***@san.rr.com>; Wed, 13 Apr 2005 15:45:01 -0400 (EDT)
Received: from m1.dnsix.com (63.251.171.164) by clmboh-mx-03.mgw.rr.com with
ESMTP; Wed, 13 Apr 2005 15:43:49 -0400
Received: from [69.162.227.235] (helo=bens-story.com)
by m1.dnsix.com with esmtp (Exim 4.44) id 1DLnm5-0005Bf-Ca for
***@xxxx.com;
Wed, 13 Apr 2005 12:43:48 -0700
Date: Wed, 13 Apr 2005 15:44:00 -0400
From: ***@bens-story.com
Subject: STATUS
To: ***@xxxx.com
Message-id: <3r1fbb$***@clmboh-mx-03.mgw.rr.com>
MIME-version: 1.0
Content-type: multipart/mixed;
boundary="----=_NextPart_000_0003_E681D41A.D032D5C9"
X-Priority: 3
X-MSMail-priority: Normal
X-Virus-Scanned: Symantec AntiVirus Scan Engine
Original-recipient: rfc822;***@san.rr.com

This is a multi-part message in MIME format.

------=_NextPart_000_0003_E681D41A.D032D5C9
Content-Type: text/plain;
charset="Windows-1252"
Content-Transfer-Encoding: 7bit

Mail transaction failed. Partial message is available.


------=_NextPart_000_0003_E681D41A.D032D5C9
Content-Type: application/octet-stream;
name="text.pif"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename="text.pif"
Kathy
2005-04-14 01:46:21 UTC
Permalink
Well, they're still flowing in in an endless stream, but now RR seems to be
catching about half of them, the other half are still getting through. I've
gotten over 100 today, it's ***@mm.

I suppose I should be happy about being slammed by something other than spam
for a change, I guess...

- Kathy

Loading...