<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="http://syndication.webwiz.co.uk/rss_namespace/">
 <channel>
  <title>Spam Filter ISP Forums : Virus question while real-time scanning on SpamFilter server</title>
  <link>https://www.logsat.com/spamfilter/forums/</link>
  <description><![CDATA[This is an XML content feed of; Spam Filter ISP Forums : Spam Filter ISP Support : Virus question while real-time scanning on SpamFilter server]]></description>
  <pubDate>Sun, 16 Aug 2026 15:14:54 +0000</pubDate>
  <lastBuildDate>Wed, 11 Aug 2004 18:12:00 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 11.04</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://www.logsat.com/spamfilter/forums/RSS_post_feed.asp?TID=4125</WebWizForums:feedURL>
  <image>
   <title><![CDATA[Spam Filter ISP Forums]]></title>
   <url>https://www.logsat.com/spamfilter/forums/forum_images/web_wiz_forums.png</url>
   <link>https://www.logsat.com/spamfilter/forums/</link>
  </image>
  <item>
   <title><![CDATA[Virus question while real-time scanning on SpamFilter server : We do block just about everything...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=4125&amp;PID=4131&amp;title=virus-question-while-realtime-scanning-on-spamfilter-server#4131</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=13">BigDog</a><br /><strong>Subject:</strong> 4125<br /><strong>Posted:</strong> 11 August 2004 at 6:12pm<br /><br /><P>We do block just about everything even&nbsp; including zip files (I take a beating on that! but my IT director backs me up 100%).</P><P>I now use three levels of "purifing" the bad email out of my system.</P><P>SpamFlter receives the messages, clears out spam, lots of viruses</P><P>NAI AV Client realtime scans the file I/O from the workings of Spamfilter catching 99% of all viruses.</P><P>NAI WebShield receives the message from SpamFilter, filters out all messages with zip and messages with macros.&nbsp; The blocked zip/macro messages directory is&nbsp;scanned from time to time and unwanted messages are discarded and the the good ones forwarded to the user.</P><P>In addtion to virus attachement type files all mutlimedia file are dis-allowed including mp3, mepg, avi, mov and such</P><P>Last year network had two virus infections which were completly contained to the workstation and both of those cases involved users who were checking outside email systems through webmail.&nbsp; We have just installed SurfControl web filtering and as of two weeks ago we block all outside webaccess and chat including&nbsp;messenging such as Yahoo chat.&nbsp;Last year all POP3 access to outside email system was closed.</P><P>I take all virus threats seriously as you can see!!&nbsp; :)</P><P>Yes, I am no longer seeing that virus now that AV signatures have been updated, all is well in Columbia Missouri!!</P><P>Oh and too, my users LOVE Spamfilter ISP !!!!</P>]]>
   </description>
   <pubDate>Wed, 11 Aug 2004 18:12:00 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=4125&amp;PID=4131&amp;title=virus-question-while-realtime-scanning-on-spamfilter-server#4131</guid>
  </item> 
  <item>
   <title><![CDATA[Virus question while real-time scanning on SpamFilter server : Why don&amp;#039;t you just drop any...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=4125&amp;PID=4130&amp;title=virus-question-while-realtime-scanning-on-spamfilter-server#4130</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=2">Guests</a><br /><strong>Subject:</strong> 4125<br /><strong>Posted:</strong> 11 August 2004 at 5:52pm<br /><br /><P>Why don't you just drop any attachment that can possibly carry an virus? It would be so much easier than running a virus scanning software.</P><P>&nbsp;</P>]]>
   </description>
   <pubDate>Wed, 11 Aug 2004 17:52:00 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=4125&amp;PID=4130&amp;title=virus-question-while-realtime-scanning-on-spamfilter-server#4130</guid>
  </item> 
  <item>
   <title><![CDATA[Virus question while real-time scanning on SpamFilter server : Wes, While we&amp;#039;re not in...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=4125&amp;PID=4128&amp;title=virus-question-while-realtime-scanning-on-spamfilter-server#4128</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 4125<br /><strong>Posted:</strong> 10 August 2004 at 11:19pm<br /><br /><P>Wes,</P><P>While we're not in the antivirus business (yet...) we are familiar with them as we deal with them every day. You'll want to double-check with your antivirus vendor, however we believe the&nbsp;<FONT face="Trebuchet MS" size=2>TROJ_ILLWILL.A</FONT> you are encountering is actually a variant of the BAGLE virus, specifically&nbsp;<A HREF="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_BAGLE.AC" CLASS="ASPForums" TITLE="WARNING: URL created by poster. ">TROJ_BAGLE.AC</A> that was discovered&nbsp;on Aug 9, and became very active. Some antivirus vendors (ex. Trend Micro) had initially classified the first virus strains as ILLWILL and then changed name.</P><P>You are probably seing real viruses being stopped. Please note that SpamFilter is "antivirus aware", meaning that if one of the temp files SpamFilter caches to drive suddently disappears, SpamFilter will assume antivirus software detected a virus and deleted the file. When this happens, SpamFilter will "understand" and will clean up after itself by deleting the other temp files related to that email and continue processing other messages. If some emails slip thru it is because the antivirus software was not fast enough in deecting the virus in the temp files before SpamFilter processes them (SpamFilter pauses for a few hundreds of a second after writing files to allow A/V software to scan them).</P><P>Roberto F.<BR>LogSat Software</P>]]>
   </description>
   <pubDate>Tue, 10 Aug 2004 23:19:00 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=4125&amp;PID=4128&amp;title=virus-question-while-realtime-scanning-on-spamfilter-server#4128</guid>
  </item> 
  <item>
   <title><![CDATA[Virus question while real-time scanning on SpamFilter server : I started real time virus scanning...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=4125&amp;PID=4125&amp;title=virus-question-while-realtime-scanning-on-spamfilter-server#4125</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=13">BigDog</a><br /><strong>Subject:</strong> 4125<br /><strong>Posted:</strong> 10 August 2004 at 10:54am<br /><br /><P>I started real time virus scanning a couple days ago as I had read here on the forum that it would remove the infected messages prior to actually being sent into my system (I am running Webshield SMTP in addtion to SpamFilter....</P><P>Odd thing is that I keep detecting a virus that I haven't seen before (from WebShield SMTP) which is JS/IIlWill&nbsp;&nbsp;from the SpamFilter in the temp directory.</P><P>Am I just getting a false-positive detection from the workings of SpamFilter or am I detecting an&nbsp; real occurance of the trojan virus?&nbsp; It's been a little disturbing as I had one call from user who indicated that they had received a reply back from a AV email gateway on the internet indicating a message had been recieved from their email address that was infected with this trogan.</P><P>Should I be panic'ing or is this something I can expect?&nbsp; Mind you this IllWill is being detected several every few minutes, the SpamFilter server is patched and up to date with MS OS updates and this trogan is at least a 3 year old virus.</P><P>&nbsp;</P>]]>
   </description>
   <pubDate>Tue, 10 Aug 2004 10:54:00 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=4125&amp;PID=4125&amp;title=virus-question-while-realtime-scanning-on-spamfilter-server#4125</guid>
  </item> 
 </channel>
</rss>