Author Topic: Outlook/Exchange Provider Reliability  (Read 3183 times)

0 Members and 1 Guest are viewing this topic.

Meanteam

  • Guest
Outlook/Exchange Provider Reliability
« on: February 03, 2006, 04:44:27 PM »
I had been a long time user of AVG however after reading some positive reviews of Avast, decided to give it a go.

On the whole I'm very pleased with it however I have one concern.

On the 31st Jan I received an e-mail claiming to be from The Guardian asking for my approval on a photograph they wanted to use. Attached was a zip file which contained an exe called Photo And Article.exe. The Avast provider screen appeared as Outlook loaded so I assumed it was protecting me.

Naturally I was weary of the exe and haven't run it as I assumed it was a virus. I thought I'd run the file through an online scanner just to check and it did find a virus in it. I then used the Avast shell extension to test and Avast too found a virus in it. So why didn't it find it in the e-mail?

I decided to forward the e-mail to myself. I temporarily turned off the provider, forwarded the e-mail and resumed the provider again. When the e-mail came in this time, Avast immediately warned me of a virus and offered me the choice of moving it to a safe place etc.

Could it simply be that this particular virus wasn't in my definitions the first time around? Avast has now detected it as: Photo and Article.exe (Win32:Breplibot-O [Trj]) was deleted from the message.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89033
  • No support PMs thanks
Re: Outlook/Exchange Provider Reliability
« Reply #1 on: February 03, 2006, 04:59:21 PM »
I haven't heard of anything like this in the forums, but I could have missed it as I'm not an MS Outlook user.

Possibly it was a recent inclusion you could check using the VPS History page avast! VPS Updates History

You are right to be suspicious of such emails using social engineering to make you curious enough to open the attachment. Outlook uses the same virus signatures so if it is picked up by say standard shield it should be picked up by the Outlook/Exchange plug-in unless it was somehow unable to scan, although I can't see why that would be.

If you saved the original attachment to your HDD it should have been scanned by standard as a newly created file. You could also check the offending/suspect file at: Jotti - Multi engine on-line virus scanner if any other scanners here detect them it is less likely to be a false positive.
Or VirusTotal - Multi engine on-line virus scanner
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

CharleyO

  • Guest
Re: Outlook/Exchange Provider Reliability
« Reply #2 on: February 03, 2006, 05:24:54 PM »
***

Welcome to the forums, Meanteam!    :)

Yes, that virus definition was recently added as can be seen at the link below. This is why it was detected when you later forwarded the email to yourself.

http://www.avast.com/eng/vps_history.html

This is an IRC-controlled backdoor trojan that allows unauthorized access to an affected machine. When executed, it copies itself to %System%\smszac32.exe and modifies the registry to ensure that it is run at each Windows start.


I hope this helps you.    :)


***
« Last Edit: February 04, 2006, 12:49:14 AM by CharleyO »

Meanteam

  • Guest
Re: Outlook/Exchange Provider Reliability
« Reply #3 on: February 03, 2006, 07:17:02 PM »
Thanks very much for the replies. Much appreciated!  :)

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89033
  • No support PMs thanks
Re: Outlook/Exchange Provider Reliability
« Reply #4 on: February 03, 2006, 07:20:12 PM »
No problem, welcome to the forums and the avast! family.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

electronikk

  • Guest
Re: Outlook/Exchange Provider Reliability
« Reply #5 on: February 04, 2006, 12:38:46 AM »
BTW: I remember a case where I received an e-mail which contained an infected file sometime late in 2005. The file extension was pdf.exe.  It slipped through the internet mail provider. I scanned the attachment manually with another scanner and it detected the virus immediately. (Both avast and the second scanner had the latest updates.)
These cases show why (the improvement of) reaction time on new threats is so important. (I addressed this issue in one of my previous posts.)

Just my two cents worth. Have a nice weekend! ;)
« Last Edit: February 04, 2006, 12:54:02 AM by electronikk »