Using the test virus sender on your website, the eicar plain file gets
caught as a virus, where the eicar in a .zip file gets caught as a  banned
extension.

That's because:


03/10/2004 08:42:40 Q295c000501aa26d2 Banning .ZIP file with encrypted COM extension.

It's not a standard .ZIP file, it is an encrypted .ZIP file.


On the site is mentions it should be caught as a virus.

That's referring to the fact that it should be caught, not necessarily as a virus. It's good if the AV program can detect it as a virus (since it is a static encrypted .ZIP file, not a dynamic one), but it doesn't need to (since all encrypted .ZIP files should be blocked).


FWIW, I'm not aware of any AV programs that detect the eicar.com file in encrypted .ZIP files yet.

-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask for a free 30-day evaluation.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to