Author Topic: False positive warning on PGP/MIME-mails  (Read 3834 times)

0 Members and 1 Guest are viewing this topic.

Patrick Schoenbach

  • Guest
False positive warning on PGP/MIME-mails
« on: June 01, 2006, 07:54:05 PM »
Hi,

whenever I get an encrypted mail in PGP/MIME-format (retrieved via IMAP), avast! warns me of a potential thread in the attachment.

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11873
    • AVAST Software
Re: False positive warning on PGP/MIME-mails
« Reply #1 on: June 01, 2006, 07:55:37 PM »
What's the exact message?

Patrick Schoenbach

  • Guest
Re: False positive warning on PGP/MIME-mails
« Reply #2 on: June 01, 2006, 08:02:29 PM »
What's the exact message?


In German:
"Stark verdächtige Erweiterung im Attachment"

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11873
    • AVAST Software
Re: False positive warning on PGP/MIME-mails
« Reply #3 on: June 01, 2006, 08:10:28 PM »
Sounds like e-mail heuristics. Try to customize the settings in the respective provider (Internet Mail or Outlook).

Patrick Schoenbach

  • Guest
Re: False positive warning on PGP/MIME-mails
« Reply #4 on: June 01, 2006, 08:13:29 PM »
Sounds like e-mail heuristics. Try to customize the settings in the respective provider (Internet Mail or Outlook).

I did, but was not able to stop it.

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11873
    • AVAST Software
Re: False positive warning on PGP/MIME-mails
« Reply #5 on: June 01, 2006, 11:17:29 PM »
What e-mail client do you use, what provider did you configure - and how?

Patrick Schoenbach

  • Guest
Re: False positive warning on PGP/MIME-mails
« Reply #6 on: June 01, 2006, 11:25:26 PM »
What e-mail client do you use, what provider did you configure - and how?


Client: Thunderbird 1.5.0.3 using the enigmail extension

Provider:
Internet Mail, medium security. I also tried the custom heuristics with everything switched off. It still happens. Probably, because at least one message part is of type "application/octet-stream".

hron84

  • Guest
Re: False positive warning on PGP/MIME-mails
« Reply #7 on: December 29, 2009, 10:15:40 AM »
Sounds like e-mail heuristics. Try to customize the settings in the respective provider (Internet Mail or Outlook).
I think it isn't a solution. Please add recognition of PGP header (plaintext) to heuristic scanner. This is a very-very old bug in avast!.