Mailing List Archive

false alarm
Hi,

I was trying to send out a mirc.exe. It is blocked by clamav. So i use
Norton. McAfee, Grisoft AVG, Panda and Sweep Sophos did not find anything.
Can please verify the sig?

thanks


----- Original Message -----
From: "System Anti-Virus Administrator" <nicholas@cyberaim.net>
To: <nicholas@ncmbox.net>
Sent: Monday, October 27, 2003 8:10 PM
Subject: virus found in sent message "test"


>
> Attention: nicholas@ncmbox.net
>
>
> A virus was found in an Email message you sent.
> This Email scanner intercepted it and stopped the entire message
> reaching its destination.
>
> The virus was reported to be:
>
> Trojan.Dropper.Senna
>
>
> Please update your virus scanner or contact your IT support
> personnel as soon as possible as you have a virus on your system.
>
>
> Your message was sent with the following envelope:
>
> MAIL FROM: nicholas@ncmbox.net
> RCPT TO: nicholas@nchost.net
>
> ... and with the following headers:
>
> ---
> MAILFROM: nicholas@ncmbox.net
> Received: from unknown (HELO dwms) (nicholas@ncmbox.net@210.193.27.63)
> by 0 with SMTP; 27 Oct 2003 12:08:54 -0000
> Message-ID: <06d301c39c83$48fec1d0$d31bc1d2@dwms>
> From: "Nicholas" <nicholas@ncmbox.net>
> To: <nicholas@nchost.net>
> Subject: test
> Date: Mon, 27 Oct 2003 20:10:15 +0800
> MIME-Version: 1.0
> Content-Type: multipart/mixed;
> boundary="----=_NextPart_000_06D0_01C39CC6.55CBC0A0"
> X-Priority: 3
> X-MSMail-Priority: Normal
> X-Mailer: Microsoft Outlook Express 6.00.2800.1158
> X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
>
>
> ---
>
RE: false alarm [ In reply to ]
> -----Original Message-----
> From: clamav-devel-admin@lists.sourceforge.net [mailto:clamav-devel-
> admin@lists.sourceforge.net] On Behalf Of Nicholas
> Sent: 27. oktober 2003 20:22
> To: clamav-devel@lists.sourceforge.net
> Subject: [Clamav-devel] false alarm
>
> Hi,
>
> I was trying to send out a mirc.exe. It is blocked by clamav. So i use
> Norton. McAfee, Grisoft AVG, Panda and Sweep Sophos did not find
anything.
> Can please verify the sig?
>
> thanks
>
>

If possible could you please submit false positive sample through
http://clamav.sourceforge.net/cgi-bin/sendvirus.cgi

Best regards,
Diego d'Ambra