I have HTM and HTML attachments banned. (No valid reason for them.) Yet one got 
through. Can some one help me on this as to why? And it was malicious 
containing Trojan.HTML.Phishing.GL

07/17/2015 06:45:41.804 002298363 Vulnerability flags = 93
07/17/2015 06:45:41.806 002298363 MIME file: [text/html][quoted-printable; 
Length=7429 Checksum=603288]
07/17/2015 06:45:41.816 002298363 MIME file: Invoice.html [base64; 
Length=299452 Checksum=21079305]
07/17/2015 06:45:41.816 002298363 Found potentially dangerous stuff in 
C:\Interceptor\Alligate\spool\proc\work\002298363.vir\0.html!
07/17/2015 06:45:51.183 002298363 Virus scanner 1 reports exit code of 0
07/17/2015 06:45:53.210 002298363 Virus scanner 2 reports exit code of 0
07/17/2015 06:45:53.216 002298363 Scanned: Virus Free [Prescan OK][MIME: 3 
307350]

Scanner1 is ClamAV
Scanner2 is ESET Endpoint Antivirus.

Checking on VirusTotal, neither ClamAV nor ESET catch this.

In the virus.cfg file directives relevant to this issue:

AVAFTERJM       ON
PRESCAN         ON
BANEXT  htm
BANEXT  html


John T
eServices For You


#############################################################
This message is sent to you because you are subscribed to
  the mailing list <[email protected]>.
To unsubscribe, E-mail to: <[email protected]>
To switch to the DIGEST mode, E-mail to <[email protected]>
To switch to the INDEX mode, E-mail to <[email protected]>
Send administrative queries to  <[email protected]>

Reply via email to