Virus Filter At Work.

  • Thread starter Adam A. Wanderer
  • Start date
A

Adam A. Wanderer

Too bad more mail servers don't have this sort of filter:

Dear User,

the message sent to you by (e-mail address removed) (may be forged) with
following
attributes has not been delivered, because contains an infected object.

--- Dr.Web report ---
Following virus(es) has been found:
infected with Win32.HLLM.Gibe.2


Dr.Web detailed report:
drweb.tmp.fTNJDZ - archive MAIL
drweb.tmp.fTNJDZ/[text:plain] - Ok
drweb.tmp.fTNJDZ/[text:html] - Ok
drweb.tmp.fTNJDZ/[image:gif] - Ok
drweb.tmp.fTNJDZ/[image:gif] - Ok
drweb.tmp.fTNJDZ/update142.exe infected with Win32.HLLM.Gibe.2

Dr.Web scanning statistic:
Evaluation key used !
Infected : 1

--- Dr.Web report ---

The original message was stored in archive record named:
drweb.quarantine.kxIrLv
In order to receive the original message, please send request to
<postmaster>, referring to the archive record name
given above.

---
Antivirus service provided by Dr.Web(R) Daemon for Unix
(http://www.drweb.ru, http://www.dials.ru/english)



----------------------------------------------------------------------------
----


õ×ÁÖÁÅÍÙÊ ðÏÌÕÞÁÔÅÌØ !

óÏÏÂÝÅÎÉÅ, ÐÏÓÌÁÎÎÏÅ ÷ÁÍ Ó ÁÄÒÅÓÁ (e-mail address removed) (×ÏÚÍÏÖÎÏ ÐÏÄÄÅÌÁÎ)
ÉÎÆÉÃÉÒÏ×ÁÎÏ É ÎÅ ÂÙÌÏ ÄÏÓÔÁ×ÌÅÎÏ.

--- Dr.Web report ---
îÁÊÄÅÎ(Ù) ÓÌÅÄÕÀÝÉÊ(Å) ×ÉÒÕÓ(Ù):
infected with Win32.HLLM.Gibe.2

äÅÔÁÌÉÚÉÒÏ×ÁÎÎÙÊ ÏÔÞÅÔ Dr.Web:
drweb.tmp.fTNJDZ - archive MAIL
drweb.tmp.fTNJDZ/[text:plain] - Ok
drweb.tmp.fTNJDZ/[text:html] - Ok
drweb.tmp.fTNJDZ/[image:gif] - Ok
drweb.tmp.fTNJDZ/[image:gif] - Ok
drweb.tmp.fTNJDZ/update142.exe infected with Win32.HLLM.Gibe.2

óÔÁÔÉÓÔÉËÁ ÓËÁÎÉÒÏ×ÁÎÉÑ Dr.Web:
Evaluation key used !
Infected : 1

--- Dr.Web report ---

óÏÏÂÝÅÎÉÅ ÓÏÈÒÁÎÅÎÏ × ËÁÒÁÎÔÉÎÅ ÐÏÄ ÉÍÅÎÅÍ:
drweb.quarantine.kxIrLv

þÔÏÂÙ ÐÏÌÕÞÉÔØ ÜÔÏ ÓÏÏÂÝÅÎÉÅ, ÏÂÒÁÔÉÔÅÓØ Ë ÁÄÍÉÎÉÓÔÒÁÔÏÒÕ
ÐÏ ÁÄÒÅÓÕ <postmaster>, ÕËÁÚÁ× ÉÍÑ, ÐÏÄ
ËÏÔÏÒÙÍ ÓÏÈÒÁÎÅÎÏ ÓÏÏÂÝÅÎÉÅ ÄÌÑ ÷ÁÓ.

---
áÎÔÉ×ÉÒÕÓÎÁÑ ÚÁÝÉÔÁ ÐÏÞÔÏ×ÙÈ ÓÅÒ×ÅÒÏ×
Dr.Web(R) Daemon for Unix (ÒÁÚÒÁÂÏÔÁÎ × Daniloff's Labs)
(http://www.drweb.ru, http://www.DialogNauka.ru)



----------------------------------------------------------------------------
----


Received: from unknown
by outpost.rada.cv.ua (Dr.WEB Sendmail filter 4.29.12f)
id ???; Wed, 01 Oct 2003 09:08:45 EEST
FROM: "Microsoft Corporation Customer Support" <[email protected]>
TO: "Commercial Client" <[email protected]>
SUBJECT: Net Patch
Mime-Version: 1.0
Content-Type: multipart/mixed; boundary="iufqueoxihaz"
 
A

Adam A. Wanderer

http://www.sald.com/

Adam A. Wanderer said:
Too bad more mail servers don't have this sort of filter:

Dear User,

the message sent to you by (e-mail address removed) (may be forged) with
following
attributes has not been delivered, because contains an infected object.

--- Dr.Web report ---
Following virus(es) has been found:
infected with Win32.HLLM.Gibe.2


Dr.Web detailed report:
drweb.tmp.fTNJDZ - archive MAIL
drweb.tmp.fTNJDZ/[text:plain] - Ok
drweb.tmp.fTNJDZ/[text:html] - Ok
drweb.tmp.fTNJDZ/[image:gif] - Ok
drweb.tmp.fTNJDZ/[image:gif] - Ok
drweb.tmp.fTNJDZ/update142.exe infected with Win32.HLLM.Gibe.2

Dr.Web scanning statistic:
Evaluation key used !
Infected : 1

--- Dr.Web report ---

The original message was stored in archive record named:
drweb.quarantine.kxIrLv
In order to receive the original message, please send request to
<postmaster>, referring to the archive record name
given above.

---
Antivirus service provided by Dr.Web(R) Daemon for Unix
(http://www.drweb.ru, http://www.dials.ru/english)



-------------------------------------------------------------------------- --
----


õ×ÁÖÁÅÍÙÊ ðÏÌÕÞÁÔÅÌØ !

óÏÏÂÝÅÎÉÅ, ÐÏÓÌÁÎÎÏÅ ÷ÁÍ Ó ÁÄÒÅÓÁ (e-mail address removed) (×ÏÚÍÏÖÎÏ ÐÏÄÄÅÌÁÎ)
ÉÎÆÉÃÉÒÏ×ÁÎÏ É ÎÅ ÂÙÌÏ ÄÏÓÔÁ×ÌÅÎÏ.

--- Dr.Web report ---
îÁÊÄÅÎ(Ù) ÓÌÅÄÕÀÝÉÊ(Å) ×ÉÒÕÓ(Ù):
infected with Win32.HLLM.Gibe.2

äÅÔÁÌÉÚÉÒÏ×ÁÎÎÙÊ ÏÔÞÅÔ Dr.Web:
drweb.tmp.fTNJDZ - archive MAIL
drweb.tmp.fTNJDZ/[text:plain] - Ok
drweb.tmp.fTNJDZ/[text:html] - Ok
drweb.tmp.fTNJDZ/[image:gif] - Ok
drweb.tmp.fTNJDZ/[image:gif] - Ok
drweb.tmp.fTNJDZ/update142.exe infected with Win32.HLLM.Gibe.2

óÔÁÔÉÓÔÉËÁ ÓËÁÎÉÒÏ×ÁÎÉÑ Dr.Web:
Evaluation key used !
Infected : 1

--- Dr.Web report ---

óÏÏÂÝÅÎÉÅ ÓÏÈÒÁÎÅÎÏ × ËÁÒÁÎÔÉÎÅ ÐÏÄ ÉÍÅÎÅÍ:
drweb.quarantine.kxIrLv

þÔÏÂÙ ÐÏÌÕÞÉÔØ ÜÔÏ ÓÏÏÂÝÅÎÉÅ, ÏÂÒÁÔÉÔÅÓØ Ë ÁÄÍÉÎÉÓÔÒÁÔÏÒÕ
ÐÏ ÁÄÒÅÓÕ <postmaster>, ÕËÁÚÁ× ÉÍÑ, ÐÏÄ
ËÏÔÏÒÙÍ ÓÏÈÒÁÎÅÎÏ ÓÏÏÂÝÅÎÉÅ ÄÌÑ ÷ÁÓ.

---
áÎÔÉ×ÉÒÕÓÎÁÑ ÚÁÝÉÔÁ ÐÏÞÔÏ×ÙÈ ÓÅÒ×ÅÒÏ×
Dr.Web(R) Daemon for Unix (ÒÁÚÒÁÂÏÔÁÎ × Daniloff's Labs)
(http://www.drweb.ru, http://www.DialogNauka.ru)



-------------------------------------------------------------------------- --
----


Received: from unknown
by outpost.rada.cv.ua (Dr.WEB Sendmail filter 4.29.12f)
id ???; Wed, 01 Oct 2003 09:08:45 EEST
FROM: "Microsoft Corporation Customer Support"
 
Top