Перейти к содержимому


Фото
- - - - -

Dr. Web Removing E-mail Attachments...


  • Please log in to reply
10 ответов в этой теме

#1 FEH

FEH

    Newbie

  • Posters
  • 8 Сообщений:

Отправлено 12 Апрель 2009 - 13:02

How do we get Dr. Web's e-mail scanning tool to stop *removing* our password-protected Word documents we are exchanging via e-mail[ sensored ]?

Kindly advise.

#2 Malex

Malex

    спасатель

  • Posters
  • 1 070 Сообщений:

Отправлено 12 Апрель 2009 - 13:45

It seems to me that they are infected.
Please, run Start -> Run
%USERPROFILE%\DoctorWeb

and attach here spiderml.log
Официальный сертифицированный пользователь ПАК:
PC3000 UDMA & Data Extractor (производитель НПП АСЕ), Raid Explorer (производитель СОФТ-ЦЕНТР), Flash Extractor & Image Explorer (производитель СОФТ-ЦЕНТР), Victoria Full version (автор Сергей Казанский), R-Studio Data Recovery (производитель R-Tools Technology Inc.), GetDataBack for FAT (производитель Runtime Software), GetDataBack for NTFS (производитель Runtime Software), собственные разработки.

#3 FEH

FEH

    Newbie

  • Posters
  • 8 Сообщений:

Отправлено 12 Апрель 2009 - 14:18

It seems to me that they are infected.
Please, run Start -> Run
%USERPROFILE%\DoctorWeb

and attach here spiderml.log

Unfortunately, I have uninstalled Dr. Web from this computer, due to the problem.

Note that password-protected documents are not accessible to Dr. Web, and therefore it treats them as "infected", but they are not.

Also, BitDefender does something different: When doing a full system check, it states that it is not able to scan them, but does *not* delete the files, nor states that they are infected when we open them!

Wouldn't it be pretty stupid to post the logs here on a public forum...

#4 Malex

Malex

    спасатель

  • Posters
  • 1 070 Сообщений:

Отправлено 12 Апрель 2009 - 14:26

1. Pity indeed
2. What do you mean "not accessible"?
3. The talk is here about Dr.Web, not BitDefender
4. No, it's not - the log i asked contains no personal information.
Официальный сертифицированный пользователь ПАК:
PC3000 UDMA & Data Extractor (производитель НПП АСЕ), Raid Explorer (производитель СОФТ-ЦЕНТР), Flash Extractor & Image Explorer (производитель СОФТ-ЦЕНТР), Victoria Full version (автор Сергей Казанский), R-Studio Data Recovery (производитель R-Tools Technology Inc.), GetDataBack for FAT (производитель Runtime Software), GetDataBack for NTFS (производитель Runtime Software), собственные разработки.

#5 Malex

Malex

    спасатель

  • Posters
  • 1 070 Сообщений:

Отправлено 12 Апрель 2009 - 14:30

BTW, you can try to post one of the "infected" protected messages to me. I'll answer is it a false or really infected.
Официальный сертифицированный пользователь ПАК:
PC3000 UDMA & Data Extractor (производитель НПП АСЕ), Raid Explorer (производитель СОФТ-ЦЕНТР), Flash Extractor & Image Explorer (производитель СОФТ-ЦЕНТР), Victoria Full version (автор Сергей Казанский), R-Studio Data Recovery (производитель R-Tools Technology Inc.), GetDataBack for FAT (производитель Runtime Software), GetDataBack for NTFS (производитель Runtime Software), собственные разработки.

#6 Eugeny Gladkih

Eugeny Gladkih

    the Spirit of the Enlightenment

  • Dr.Web Staff
  • 5 295 Сообщений:

Отправлено 12 Апрель 2009 - 16:49

Note that password-protected documents are not accessible to Dr. Web, and therefore it treats them as "infected", but they are not.


no, it doesn't. it's "unchecked messages", you may set a "pass" action for them

#7 FEH

FEH

    Newbie

  • Posters
  • 8 Сообщений:

Отправлено 12 Апрель 2009 - 20:50

Note that password-protected documents are not accessible to Dr. Web, and therefore it treats them as "infected", but they are not.


no, it doesn't. it's "unchecked messages", you may set a "pass" action for them

How?

#8 userr

userr

    Newbie

  • Members
  • 16 310 Сообщений:

Отправлено 12 Апрель 2009 - 21:23

Note that password-protected documents are not accessible to Dr. Web, and therefore it treats them as "infected", but they are not.

no, it doesn't. it's "unchecked messages", you may set a "pass" action for them

How?

Прикрепленный файл  spm.jpg   25,13К   126 Скачано раз
When you re-install Drweb attach here drweb32.ini file from main drweb folder, please.

#9 FEH

FEH

    Newbie

  • Posters
  • 8 Сообщений:

Отправлено 14 Апрель 2009 - 10:58

no, it doesn't. it's "unchecked messages", you may set a "pass" action for them

What if an "unchecked" message actually contains a virus then?

How can we identify and make sure that only password-protected documents are allowed through?

#10 Eugeny Gladkih

Eugeny Gladkih

    the Spirit of the Enlightenment

  • Dr.Web Staff
  • 5 295 Сообщений:

Отправлено 14 Апрель 2009 - 12:40

no, it doesn't. it's "unchecked messages", you may set a "pass" action for them

What if an "unchecked" message actually contains a virus then?

How can we identify and make sure that only password-protected documents are allowed through?


how could the AV be aware than password protected files are not infected?!

#11 FEH

FEH

    Newbie

  • Posters
  • 8 Сообщений:

Отправлено 14 Апрель 2009 - 12:48

how could the AV be aware than password protected files are not infected?!

I am simply asking why would one have to allow *all* files that cannot be scanned to be passed through?

Then, virus-authors/writers would use this method to get into machines, which then would allow them to be opened.

Could the AV recognize the type of file it is scanning, and only allow *.doc files that cannot be scanned through?

I know, this would then be the same problem, but at least we are limiting the type of file here, and normally Word requests an AV scan of a *.doc file when it opens it, correct?


Читают тему: 1

0 пользователей, 1 гостей, 0 скрытых