
3.16b here, but only 3 hits so far for this on a busy server, so it's not necessarily common.  I was able to capture one of these and it appears to be hitting at least E-mails generated in "Microsoft Word 11".
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii">
<meta name=Generator content="Microsoft Word 11 (filtered medium)">
<base href="" class="moz-txt-link-rfc2396E" href="file:///C:\Program%20Files\Common%20Files\Microsoft%20Shared\Stationery\">"file:///C:\Program%20Files\Common%20Files\Microsoft%20Shared\Stationery\">

I have no clue what the pattern is that it is hitting of course, but I assume that F-Prot just simply added an overbroad rule.  Most E-mail isn't constructed anything like what Microsoft Word creates.


Markus Gufler wrote:
Question: Have you all running the latest v3.16b ?

I can't see any appearance of "HTML/ObjData" in the entire current logfile,
but I've still running 3.16a


-----Original Message-----
[mailto:[EMAIL PROTECTED]] On Behalf Of John 
Tolmachoff (Lists)
Sent: Monday, May 02, 2005 7:47 PM
Subject: [Declude.Virus] F-Prot and HTML object exploit

It appears that something has updated on F-Prot in the last 
hour. Now, a lot of outbound HTML e-mails are being flagged  
by F-Prot as having the HTML object exploit. Running the file 
on shows clean.

Any one else seeing problems?

For now, as I am at a client, I have turned off F-Prot 
scanning relying on AVG.

John T
eServices For You

This E-mail came from the Declude.Virus mailing list.  To 
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found


This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found


MailPure custom filters for Declude JunkMail Pro.

Reply via email to