PC Review


Reply
Thread Tools Rate Thread

Add "RAV AntiVirus has deleted this file" to mail filters, to keep swen "cleaned" mail from filling your inbox.

 
 
David W. Hodgins
Guest
Posts: n/a
 
      1st Nov 2003
I'm using Magic Mail Monitor, to delete email generated by the swen worm
from my mail server, avoiding having to download the complete 140+kb
messages.

I was surprised to see a 144kb message get through the filters, since the
from/to addresses made it clear it was swen (I'm filtering based on the
iframe or title, in the start of the body of the message).

When I looked at the message, it had "RAV AntiVirus has deleted this file
because it contained "dangerous code!".

Contrary to the statement, instead of deleting the file, it's contents had
been replaced with a short base64 encoded file called __warn.txt, with
the remaining 142kb (approx) containing nothing but spaces, up to the
boundary termination line.

I consider this to be just as bad as letting the virus flow. It still
clogs up the recipients inbox, and it prevents existing virus filters
or scanners, from deleting the message, before the end user has to
download it.

I larted the originating isp, asking them to fix their av configuration,
and copied support at ravantivirus.com.

I was amazed by the response from Rav, stating that the 142kb of spaces
was there because protocols require that they don't change the message
size. I responded that McAffee has no problem dropping virus generated
messages, and simply notifying the recipient that it has done so. I asked
them to cite the RFC they were getting their info from. Their response
was the "IMAP protocol" requires that they do not change the message size.

I'm tempted to filter out all email referencing RAV Antivirus, but for now,
will limit my filter to notifications of RAV "deleted" files. I suggest
others modify there filters accordingly. The actual lines from the RAV
generated messages are ...
===============================
RAV AntiVirus has deleted this file
because it contained dangerous code!


Tento subor odstraneny, nakolko obsahoval nebezpecny kod.

This file has been remo...
=================================
--
Change .invalid to .com to reply by email.
 
Reply With Quote
 
 
 
 
Santa Claus
Guest
Posts: n/a
 
      1st Nov 2003
<snip>
On Sat, 01 Nov 2003 05:26:42 GMT, "David W. Hodgins"
<(E-Mail Removed)> wrote:

>I'm using Magic Mail Monitor, to delete email generated by the swen worm
> from my mail server, avoiding having to download the complete 140+kb
>messages.
>
>I was surprised to see a 144kb message get through the filters, since the
>from/to addresses made it clear it was swen (I'm filtering based on the
>iframe or title, in the start of the body of the message).
>


>I'm tempted to filter out all email referencing RAV Antivirus, but for now,
>will limit my filter to notifications of RAV "deleted" files. I suggest
>others modify there filters accordingly. The actual lines from the RAV
>generated messages are ...
>===============================
>RAV AntiVirus has deleted this file
> because it contained dangerous code!
>
>
>Tento subor odstraneny, nakolko obsahoval nebezpecny kod.
>
>This file has been remo...
>=================================

<snip>

Use Mailwasher.
CHeck file sizes.



No Emails Please
 
Reply With Quote
 
Doug Jacobs
Guest
Posts: n/a
 
      2nd Nov 2003
In news.admin.net-abuse.email David W. Hodgins <(E-Mail Removed)> wrote:

> When I looked at the message, it had "RAV AntiVirus has deleted this file
> because it contained "dangerous code!".


> Contrary to the statement, instead of deleting the file, it's contents had
> been replaced with a short base64 encoded file called __warn.txt, with
> the remaining 142kb (approx) containing nothing but spaces, up to the
> boundary termination line.


Yep, RAV is an extremely buggy piece of crappy software. I tried looking
up who makes it, and it appears to have been discontinued. Still, the
fact that they convinced people to buy and install this thing is just
mindboggling.

Unfortunatly, the ISPs that I've seen using RAV don't seem to actually
have an abuse, postmaster, or any other sort of valid admin contact
address. This makes sense since only clueless morons would get conned
into buying such a borken piece of software.

> I consider this to be just as bad as letting the virus flow. It still
> clogs up the recipients inbox, and it prevents existing virus filters
> or scanners, from deleting the message, before the end user has to
> download it.


The copies I've gotten from RAV "infected" ISPs didn't even rename the
virus file - it let the original message with the payload intact through,
after stamping its "What a good proggie am I!"


 
Reply With Quote
 
Darwin
Guest
Posts: n/a
 
      2nd Nov 2003
On Sun, 02 Nov 2003 06:25:05 -0000, Doug Jacobs <(E-Mail Removed)>
wrote:

[..]
> Yep, RAV is an extremely buggy piece of crappy software. I tried looking
> up who makes it, and it appears to have been discontinued. Still, the
> fact that they convinced people to buy and install this thing is just
> mindboggling.
>
> Unfortunatly, the ISPs that I've seen using RAV don't seem to actually
> have an abuse, postmaster, or any other sort of valid admin contact
> address. This makes sense since only clueless morons would get conned
> into buying such a borken piece of software.

[..]


Spamcop.net is using RAV to filter its mail service.
AFAIK it is working well, I never got a piece of Swen since I started
using their services.

The problem with the dummy notifications is the ISP sending them, not the
software who makes them.
RAV obsiously has an option to turn they down, but they have choosed to
enable it.
Why, is a total mystery to me.

--
-darwin-

Using M2, Opera's revolutionary e-mail client: http://www.opera.com/m2/
 
Reply With Quote
 
w33zyrider
Guest
Posts: n/a
 
      2nd Nov 2003
Doug Jacobs wrote:
> In news.admin.net-abuse.email David W. Hodgins <(E-Mail Removed)> wrote:
>
>
>>When I looked at the message, it had "RAV AntiVirus has deleted this file
>>because it contained "dangerous code!".

>
>
>>Contrary to the statement, instead of deleting the file, it's contents had
>>been replaced with a short base64 encoded file called __warn.txt, with
>>the remaining 142kb (approx) containing nothing but spaces, up to the
>>boundary termination line.

>
>
> Yep, RAV is an extremely buggy piece of crappy software. I tried looking
> up who makes it, and it appears to have been discontinued. Still, the
> fact that they convinced people to buy and install this thing is just
> mindboggling.
>
> Unfortunatly, the ISPs that I've seen using RAV don't seem to actually
> have an abuse, postmaster, or any other sort of valid admin contact
> address. This makes sense since only clueless morons would get conned
> into buying such a borken piece of software.
>
>
>>I consider this to be just as bad as letting the virus flow. It still
>>clogs up the recipients inbox, and it prevents existing virus filters
>>or scanners, from deleting the message, before the end user has to
>>download it.

>
>
> The copies I've gotten from RAV "infected" ISPs didn't even rename the
> virus file - it let the original message with the payload intact through,
> after stamping its "What a good proggie am I!"
>
>

MS bought RAV last spring

 
Reply With Quote
 
Fridrik Skulason
Guest
Posts: n/a
 
      2nd Nov 2003
Doug Jacobs <(E-Mail Removed)> wrote in message news:<(E-Mail Removed)>...


> Yep, RAV is an extremely buggy piece of crappy software. I tried looking


> up who makes it, and it appears to have been discontinued. Still, the


> fact that they convinced people to buy and install this thing is just


> mindboggling.


>


> Unfortunatly, the ISPs that I've seen using RAV don't seem to actually


> have an abuse, postmaster, or any other sort of valid admin contact


> address. This makes sense since only clueless morons would get conned


> into buying such a borken piece of software.



Well, uhm....did you read
http://www.microsoft.com/presspass/p...-10GeCadPR.asp ?

-frisk
 
Reply With Quote
 
optikl
Guest
Posts: n/a
 
      2nd Nov 2003

"Doug Jacobs" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> In news.admin.net-abuse.email David W. Hodgins

<(E-Mail Removed)> wrote:
> Yep, RAV is an extremely buggy piece of crappy software. I tried looking
> up who makes it, and it appears to have been discontinued. Still, the
> fact that they convinced people to buy and install this thing is just
> mindboggling.
>
> The copies I've gotten from RAV "infected" ISPs didn't even rename the
> virus file - it let the original message with the payload intact through,
> after stamping its "What a good proggie am I!"
>
>


RAV was purchased recently by Microsoft from GeCad. It will be a component
of future M/S OSes.


 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
all incoming mail goes in"deleted " folder instead of "inbox" ? JoeS Microsoft Outlook Discussion 1 21st Jun 2008 12:12 AM
IMAP folders for "Deleted Items" and "Junk E-Mail" =?Utf-8?B?c3RldmU=?= Windows Vista Mail 3 23rd Sep 2007 02:42 AM
Replace "INBOX" with "CALENDAR" so mail not visible upon opening =?Utf-8?B?QnVkZHkncyBNb20=?= Microsoft Outlook Installation 1 7th Apr 2006 01:03 PM
When I empty the "trash" folder, my inbox mail is also deleted. =?Utf-8?B?Q2Fyb2w=?= Microsoft Outlook Discussion 2 30th Dec 2005 03:17 AM
How to move "Junk E-mail" to "Deleted Items" folder automatically? pwalker Microsoft Outlook 2 8th Nov 2003 07:32 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 06:24 PM.