Community Discussions and Support
Testing VirScan

Further to my previous posting, the latest version of Virscan has a separate option in Virscan.ini, called Enczip=  which can have two values Deny (which is default) or Skip 

Martin 

<p>Further to my previous posting, the latest version of Virscan has a separate option in Virscan.ini, called Enczip=  which can have two values Deny (which is default) or Skip </p><p>Martin </p>

On a Win 7 machine with Norton Internet Security (NIS), I installed PMail 4.70 and VirScan (VS).  To see if VS was properly configured, I created a test message, a .CNM file with the EICAR test file string in the message body, <http://www.eicar.org/>. When I opened the test message, NIS displayed the accompanying screen shot snip.  Disabled VS and got the same result. If I were to uninstall VS, am I any less protected?

KSQR

On a Win 7 machine with Norton Internet Security (NIS), I installed PMail 4.70 and VirScan (VS).&amp;nbsp; To see if VS was properly configured, I created a test message, a .CNM file with the EICAR test file string in the message body, &amp;lt;http://www.eicar.org/&amp;gt;. When I opened the test message, NIS displayed the accompanying screen shot snip.&amp;nbsp; Disabled VS and got the same result. If I were to uninstall VS, am I any less protected? KSQR

Virscan acts on attachments.  Read more on the download page

http://community.pmail.com/files/folders/pegadd/entry20083.aspx

as well as in the virscan.txt file included in the download.

&lt;p&gt;Virscan acts on attachments.&amp;nbsp; Read more on the download page &lt;/p&gt;&lt;p&gt;http://community.pmail.com/files/folders/pegadd/entry20083.aspx&lt;/p&gt;&lt;p&gt;as well as in the virscan.txt file included in the download. &lt;/p&gt;

[quote user="bfluet"]

Virscan acts on attachments.  Read more on the download page

http://community.pmail.com/files/folders/pegadd/entry20083.aspx

as well as in the virscan.txt file included in the download.

[/quote]

What is a good way to test to ensure that the Virscan.ini file is actually configured correctly?

KSQR

 

[quote user=&quot;bfluet&quot;]&lt;p&gt;Virscan acts on attachments.&amp;nbsp; Read more on the download page &lt;/p&gt;&lt;p&gt;http://community.pmail.com/files/folders/pegadd/entry20083.aspx&lt;/p&gt;&lt;p&gt;as well as in the virscan.txt file included in the download. &lt;/p&gt;&lt;p&gt;[/quote]&lt;/p&gt;&lt;p&gt;What is a good way to test to ensure that the Virscan.ini file is actually configured correctly? &lt;/p&gt;&lt;p&gt;KSQR &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;

I have used services in the past that email you an eicar attachment.  I did a quick websearch and found that Panda provides this service but they are not one I have used in the past. I didn't spend a lot of time reviewing the search results so there are probably other services.  I remember using one that could send eicar in numerous different file types.  I don't remember who provided that service though.

Here is the url of the Panda site I found.  You may want to tick the "I do not want to receive marketing information..." option at the bottom of the page. 

http://www.pandasecurity.com/usa/homeusers/security-info/protected/eicar-test/eicar3.htm

Keep in mind that the vircan.ini file is configurable to block files with certain

extensions and blocks some extensions by default.  I don't know what

extension Panda sends their test attachment as so be aware that it might

get blocked rather than scanned if the extension is in the virscan.ini

deny list.

Finally, I believe you can write the eicar string to a text file then rename it to a .com file to serve as a test attachment.

&lt;p&gt;I have used services in the past that email you an eicar attachment.&amp;nbsp; I did a quick websearch and found that Panda provides this service but they are not one I have used in the past. I didn&#039;t spend a lot of time reviewing the search results so there are probably other services.&amp;nbsp; I remember using one that could send eicar in numerous different file types.&amp;nbsp; I don&#039;t remember who provided that service though. &lt;/p&gt;&lt;p&gt;Here is the url of the Panda site I found.&amp;nbsp; You may want to tick the &quot;I do not want to receive marketing information...&quot; option at the bottom of the page.&amp;nbsp; &lt;/p&gt;&lt;p&gt;http://www.pandasecurity.com/usa/homeusers/security-info/protected/eicar-test/eicar3.htm&lt;/p&gt;&lt;p&gt;Keep in mind that the vircan.ini file is configurable to block files with certain extensions and blocks some extensions by default.&amp;nbsp; I don&#039;t know what extension Panda sends their test attachment as so be aware that it might get blocked rather than scanned if the extension is in the virscan.ini deny list.&lt;/p&gt;&lt;p&gt;Finally, I believe you can write the eicar string to a text file then rename it to a .com file to serve as a test attachment. &lt;/p&gt;

[quote user="bfluet"]

I have used services in the past that email you an eicar attachment.  I did a quick websearch and found that Panda provides this service but they are not one I have used in the past. I didn't spend a lot of time reviewing the search results so there are probably other services.  I remember using one that could send eicar in numerous different file types.  I don't remember who provided that service though.

Here is the url of the Panda site I found.  You may want to tick the "I do not want to receive marketing information..." option at the bottom of the page. 

http://www.pandasecurity.com/usa/homeusers/security-info/protected/eicar-test/eicar3.htm

[/quote]

Even though the page had a graphic promoting their 2012 products in lower left hand corner, I completed the form.  Panda sent me a message with a link.  Clicking the cited link returned a 404 with:

Server Error in '/Virus_info' Application.
The resource cannot be found.

KSQR

[quote user=&quot;bfluet&quot;]&lt;p&gt;I have used services in the past that email you an eicar attachment.&amp;nbsp; I did a quick websearch and found that Panda provides this service but they are not one I have used in the past. I didn&#039;t spend a lot of time reviewing the search results so there are probably other services.&amp;nbsp; I remember using one that could send eicar in numerous different file types.&amp;nbsp; I don&#039;t remember who provided that service though. &lt;/p&gt;&lt;p&gt;Here is the url of the Panda site I found.&amp;nbsp; You may want to tick the &quot;I do not want to receive marketing information...&quot; option at the bottom of the page.&amp;nbsp; &lt;/p&gt;&lt;p&gt;http://www.pandasecurity.com/usa/homeusers/security-info/protected/eicar-test/eicar3.htm&lt;/p&gt;&lt;p&gt;[/quote]&lt;/p&gt;&lt;p&gt;Even though the page had a graphic promoting their 2012 products in lower left hand corner, I completed the form.&amp;nbsp; Panda sent me a message with a link.&amp;nbsp; Clicking the cited link returned a 404 with:&lt;/p&gt;&lt;p&gt;Server Error in &#039;/Virus_info&#039; Application. The resource cannot be found. &lt;/p&gt;&lt;p&gt;KSQR &lt;/p&gt;

Try searching online for Eicar email test service or similar.

Try searching online for Eicar email test service or similar.

[quote user="caisson"]Try searching online for Eicar email test service or similar.
[/quote]

Have tried many services that say they send messages with attached EICAR type test files.  To date no such message has made it to my Inbox. Has anyone received such test messages recently?

KSQR
 

&lt;p&gt;[quote user=&quot;caisson&quot;]Try searching online for Eicar email test service or similar. [/quote]&lt;/p&gt;&lt;p&gt;Have tried many services that say they send messages with attached EICAR type test files.&amp;nbsp; To date no such message has made it to my Inbox. Has anyone received such test messages recently?&lt;/p&gt;&lt;p&gt;KSQR &amp;nbsp;&lt;/p&gt;

This one works but the messages may be blocked by your provider.

http://www.aleph-tec.com/eicar/

&lt;p&gt;This one works but the messages may be blocked by your provider. &lt;/p&gt;&lt;p&gt;http://www.aleph-tec.com/eicar/&lt;/p&gt;

And another:

http://www.emailsecuritycheck.net/

&lt;p&gt;And another: &lt;/p&gt;&lt;p&gt;http://www.emailsecuritycheck.net/&lt;/p&gt;

[quote user="caisson"]

This one works but the messages may be blocked by your provider.

http://www.aleph-tec.com/eicar/

[/quote]

Using a non-free email I got the Clean notification e-mail and only the two with password Zip files.  When I tried to look at the Zip files, a Virscan Stop graphic was displayed. 


 Now I know that VirScan (VS) is properly configured.

Is there a more convenient way to disable VS than renaming Virscn32.fff?

KSQR
 

[quote user=&quot;caisson&quot;]&lt;p&gt;This one works but the messages may be blocked by your provider. &lt;/p&gt;&lt;p&gt;http://www.aleph-tec.com/eicar/&lt;/p&gt;&lt;p&gt;[/quote]&lt;/p&gt;&lt;p&gt;Using a non-free email I got the Clean notification e-mail and only the two with password Zip files.&amp;nbsp; When I tried to look at the Zip files, a Virscan Stop graphic was displayed.&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img src=&quot;http://lafn.org/%7Ebi434/VirscanStop.gif&quot; height=&quot;140&quot; width=&quot;290&quot;&gt; &lt;/p&gt;&lt;p&gt;&amp;nbsp;Now I know that VirScan (VS) is properly configured. Is there a more convenient way to disable VS than renaming Virscn32.fff?&lt;/p&gt;&lt;p&gt;KSQR &amp;nbsp;&lt;/p&gt;

You can let zip files through the process by adding the extension zip to the SkipExtensions line in Virscan.ini  Your AV *should* examine the file when it is stored on your hard drive. However it will have to prompt for the password before starting to examine the content of the file.

this Virscan feature was introduced back in 2004 when bad guys got virus etc onto your hard drive by marking them as encrypted, knowing that a silent install would be allowed through. Since then the AV companies have learned a few things, and you should check your AV product documentation to see what it does when encountering this type of file.  The original bypass of this security check was to make the file transfer into either a web or FTP download. 

Martin 

 

 

&lt;p&gt;You can let zip files through the process by adding the extension zip to the SkipExtensions line in Virscan.ini &amp;nbsp;Your AV *should* examine the file when it is stored on your hard drive. However it will have to prompt for the password before starting to examine the content of the file.&lt;/p&gt;&lt;p&gt;this Virscan feature was introduced back in 2004 when bad guys got virus etc onto your hard drive by marking them as encrypted, knowing that a silent install would be allowed through. Since then the AV companies have learned a few things, and you should check your AV product documentation to see what it does when encountering this type of file. &amp;nbsp;The original bypass of this security check was to make the file transfer into either a web or FTP download.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Martin&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft