Discussion:
Don't rely on RR's Norton AV scan to clean your E-mail
(too old to reply)
relic
2005-04-22 19:00:29 UTC
Permalink
This came right through the Norton AV Scan done by Roadrunner... luckily, I
use NOD32.
Norton missed it, NOD32 caught it.


Return-path: <***@yahoo.com>
Received: from ms-mta-02.socal.rr.com ([10.10.4.126]) by
ms-mss-01.socal.rr.com
(iPlanet Messaging Server 5.2 HotFix 1.21 (built Sep 8 2003))
with ESMTP id <***@ms-mss-01.socal.rr.com> for
***@san.rr.com;
Fri, 22 Apr 2005 10:17:00 -0700 (PDT)
Received: from ncmx01.mgw.rr.com (ncmx01.mgw.rr.com [24.25.4.95])
by ms-mta-02.socal.rr.com
(iPlanet Messaging Server 5.2 HotFix 1.21 (built Sep 8 2003))
with ESMTP id <***@ms-mta-02.socal.rr.com> for
***@san.rr.com
(ORCPT ***@san.rr.com); Fri, 22 Apr 2005 10:16:58 -0700 (PDT)
Received: from hrndva-mx-04.mgw.rr.com (hrndva-mx-04.mgw.rr.com
[24.28.204.23])
by ncmx01.mgw.rr.com (8.12.10/8.12.8) with ESMTP id j3MHEe10020973 for
<***@san.rr.com>; Fri, 22 Apr 2005 13:16:56 -0400 (EDT)
Received: from unknown (HELO 24.28.204.23) (164.77.237.199)
by hrndva-mx-04.mgw.rr.com with SMTP; Fri, 22 Apr 2005 13:15:17 -0400
Date: Fri, 22 Apr 2005 11:09:14 -0700
From: Kristopher Cramer <***@yahoo.com>
Subject: [virus HTML/Phishing.gen trojan] re[20]:
To: ***@san.rr.com
Message-id: <3s6okj$***@hrndva-mx-04.mgw.rr.com>
MIME-version: 1.0
Content-type: multipart/related;
boundary=------------020406060907050502020009
X-Accept-Language: en-us, en
Fcc: mailbox://***@yahoo.com/Sent
X-Identity-Key: id1
X-Virus-Scanned: Symantec AntiVirus Scan Engine
Original-recipient: rfc822;***@san.rr.com
X-NOD32Result: Infected, HTML/Phishing.gen trojan
--
If there is a Tourist Season, how come we can't shoot them?
Paul
2005-05-05 07:55:05 UTC
Permalink
Post by relic
This came right through the Norton AV Scan done by Roadrunner... luckily, I
use NOD32.
Norton missed it, NOD32 caught it.
I was wondering something about the virus scanner that RR uses. I've set
up my email program to mark all mail with the following header:
-----

X-Virus-Scan-Result: Repaired

-----
If the message is from someone in my addressbook it stays in the Inbox,
otherwise it gets trashed. Lately I've been getting a whole lot of
trashed messages (500 just yesterday) and so I checked some of them.
Even though my mail program has marked them according to my rules, it
seems that RoadRunner marks them differently. The following is in two
different message bodies:
-----

*** AntiVirus: No Virus found
*** "SAN.RR" Anti-Virus

-----

*** Server-AntiVirus: No Virus (Clean)
*** "SAN.RR" Anti-Virus

-----
Does anyone else see this with their messages? I wonder because many
might take this at face value and actually look at the attachments.

Side note: What is the inbox size limit for RR? I read somewhere that it
was 20MB, but with all of these attachments, it quickly gets used up. I
know I'm hovering around 8MB, but I keep getting the Quota emails
telling me I'm passing the limit. So, what is the real quota, and when
does the email get sent out?

Loading...