Holger Isenberg
May 9th, 2006, 05:19 AM
Is this a known problem or maybe some configuration problem?
Multipart MIME messages with attachments look like being corrupted by NOD32 as the MIME boundary string after the last deleted attachment with virus is missing.
NOD32 replaces removed attachments correctly with the text message "X-Removed: Removed by NOD32 Antivirus System". However, the
MIME boundary string "--------XYZ..." is missing as you can see in this message:
Date: Mon, 08 May 2006 10:45:30 +0200
From: Test <test@local>
User-Agent: Mozilla Thunderbird 1.0.2 (X11/20051002)
X-Accept-Language: de-DE, de, en-us, en
MIME-Version: 1.0
To: "Test" <testother@local>
Subject: [NOD32: deleted] Virustest
Content-Type: multipart/mixed;
boundary="------------020306080503080309060903"
X-NOD32Result: deleted
This is a multi-part message in MIME format.
--------------020306080503080309060903
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
test
******************************************************
virus1.zip - Win32/TrojanDownloader.Small.COQ trojan - deleted
virus1.zip -> ZIP -> Telekom-Rechnung.pdf.exe - Win32/TrojanDownloader.Small.COQ trojan - quarantined - unable to cl
ean - error while Deleting - operation unavailable for this type of object - was a part of the deleted object
virus2.pif - Win32/Netsky.D worm - quarantined - unable to clean - deleted
--------------020306080503080309060903
Content-Type: text/plain
X-Removed: Removed by NOD32 Antivirus System
--------------020306080503080309060903
Content-Type: text/plain
X-Removed: Removed by NOD32 Antivirus System
Content-Type: application/msword;
name="test.doc"
Content-Transfer-Encoding: base64
Content-Disposition: inline;
filename="test.doc"
0M8R4KGxGuEAAAAAAAAAAAAAAAAAAAAAOwADAP7/CQAGAAAAAAAAAAAAAAACAAAAgwAAAAAA
AAAAEAAAAgAAAAEAAAD+////AAAAAAAAAACAAAAA////////////////////////////////////////////////////////////////////////////////////////////////////////
[...]
Added on May 10:
Mailserver: Linux Debian 3.1, Exim4
nod32d (lnod32ls) 2.51.6,
nod32d ist embedded into Exim4 like described in Chapter "5.2.2.6 Setting MTA Exim version 4"
Multipart MIME messages with attachments look like being corrupted by NOD32 as the MIME boundary string after the last deleted attachment with virus is missing.
NOD32 replaces removed attachments correctly with the text message "X-Removed: Removed by NOD32 Antivirus System". However, the
MIME boundary string "--------XYZ..." is missing as you can see in this message:
Date: Mon, 08 May 2006 10:45:30 +0200
From: Test <test@local>
User-Agent: Mozilla Thunderbird 1.0.2 (X11/20051002)
X-Accept-Language: de-DE, de, en-us, en
MIME-Version: 1.0
To: "Test" <testother@local>
Subject: [NOD32: deleted] Virustest
Content-Type: multipart/mixed;
boundary="------------020306080503080309060903"
X-NOD32Result: deleted
This is a multi-part message in MIME format.
--------------020306080503080309060903
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
test
******************************************************
virus1.zip - Win32/TrojanDownloader.Small.COQ trojan - deleted
virus1.zip -> ZIP -> Telekom-Rechnung.pdf.exe - Win32/TrojanDownloader.Small.COQ trojan - quarantined - unable to cl
ean - error while Deleting - operation unavailable for this type of object - was a part of the deleted object
virus2.pif - Win32/Netsky.D worm - quarantined - unable to clean - deleted
--------------020306080503080309060903
Content-Type: text/plain
X-Removed: Removed by NOD32 Antivirus System
--------------020306080503080309060903
Content-Type: text/plain
X-Removed: Removed by NOD32 Antivirus System
Content-Type: application/msword;
name="test.doc"
Content-Transfer-Encoding: base64
Content-Disposition: inline;
filename="test.doc"
0M8R4KGxGuEAAAAAAAAAAAAAAAAAAAAAOwADAP7/CQAGAAAAAAAAAAAAAAACAAAAgwAAAAAA
AAAAEAAAAgAAAAEAAAD+////AAAAAAAAAACAAAAA////////////////////////////////////////////////////////////////////////////////////////////////////////
[...]
Added on May 10:
Mailserver: Linux Debian 3.1, Exim4
nod32d (lnod32ls) 2.51.6,
nod32d ist embedded into Exim4 like described in Chapter "5.2.2.6 Setting MTA Exim version 4"