Deze is echt helemaal prachtig, tranen in m'n ogen als ik de replies van techsupport lees:
---
Author: Ian Fisk
Date: 09:31 PM, Nov 07 PST
Subject: Email with virus remains on server
Product: Norton AntiVirus 2003
Vendor: Retail
Subscription Status: current
Supported operating system: Windows XP Home Edition
Internet connection: Phone Modem
When my ISP receives an email for me containing the W32.Yaha.F@mm
virus and I try to read my mail using Microsoft Outlook 2002 then NAV
2003 works correctly and deletes the infected file. However Outlook
gets an error message saying that the server connection has been
reset. The infected email remains on the server and is downloaded
again every time that I check for new email.
Is this an issue with NAV 2003 or should I check with my ISP?
I have the "Repair and then silently delete if unsuccessful" option
selected but the same thing seems to happen with the other email
options.
Author: Sunny
Date: 11:35 AM, Nov 08 PST
Subject: Re: Email with virus remains on server
Hi Ian,
Thank you for contacting Symantec Online Technical Support.
In your message you wrote:
>The infected email remains
Symantec no longer supports interactive virus removal help online. We
do have several resources that you can use to help you with your virus
related questions and needs.
Symantec has an extensive online knowledge base containing information
about Symantec products as well as documentation on specific virus,
trojan and worm removal at:
>Web URL:
http://www.symantec.com/techsupp/knowledge_base.html
If you wish to find information about a virus, trojan or worm, you can
visit our Security Response website at:
>Web URL:
http://www.sarc.com.
This site includes the latest information about virus threats, links
to removal tools, and Symantec's virus encyclopedia that contains the
latest information about viruses, trojan's and worm's.
Symantec offers online virus scanning from our Security Check website
at:
>Web URL:
http://security.norton.com/.
From this site you can scan your system for viruses and security
risks. Symantec Security Check is a free service designed to help you
understand your computer's exposure to online security intrusions and
virus threats.
If you need interactive assistance removing a virus, trojan or worm
from your computer system, Symantec offers fee based virus phone
consultations you can use for assistance:
Symantec virus removal consulting service
Consulting service is available 6 A.M. to 5 P.M. PST, Monday through
Friday.
* Standard Consultation:
877-832-2811 Standard Consultation is a managed, "do-it-yourself"
option that includes diagnosis and a plan of action.
* Premier Consultation:
877-832-2811 Premier Consultation is a full-service option that
includes a diagnosis and plan of action, plus step-by-step assistance
through the process.
* Per Minute Consultation:
900-646-0004 Access Premier Consultation services
For Norton AntiVirus for Macintosh, call 900-646-0034.
As a workaround, you can also contact your Internet Service
Provider(ISP).
Please feel free to contact us for further assistance.
Regards,
Sunil Prabhu
Symantec Authorized Technical Support
Author: Ian Fisk
Date: 03:29 PM, Nov 08 PST
Subject: Re: Email with virus remains on server
Product:
In your message you wrote:
>Symantec no longer supports interactive virus removal help online
I am not asking about how to remove a virus.
I have Norton AntiVirus 2003 installed, running and scanning my
email. The virus definition file is current (6 November 2002). I have
done a full scan of my system and it is not infected.
The sequence of events is:
1. An email infected with the W32.Yaha.F@mm virus arrives on my ISP's
POP3 server.
2. Outlook 2002 running on my PC tries to download the email.
3. NAV 2003 scans the email and finds that it is infected. It should
just delete the attachment which it does do for email infected with
other virus. In the virus alert log there is a note that the
Auto-Protect feature has automatically deleted an infected temporary
file.
4. Outlook is then told that the server connection has an error.
5. Outlook then does not remove the email from the server. When it
looks for mail the next time it will try to download the same
infected email. This will repeat forever or until I use a web based
mail client to delete the infected email.
I have noticed that when other virus are deleted the virus alert log
shows a different message.
For W32.Yaha.F@mm:
Feature=Auto-Protect
Source=C:\DOCUME~1\IANFIS~1.IAN\LOCALS~1\Temp\CCD8.tmp
There is no description.
For W32.Klez.H@mm:
Feature=Virus scanner
Source=width.exe
Description: The email attachment width.exe is infected with the
W32.Klez.H@mm virus
The description of W32.Yaha.F@mm at
http://securityresponse.s...r/venc/data/w32.yaha.f@mm
.html states that protection was added in the virus definition file
of June 19, 2002.
However it looks to me like the infected email is getting to Outlook.
Outlook then puts the attachment in a temporary file. NAV then
detects the virus in the temporary file and deletes it. This may
cause Outlook to think that the server connection has an error, i.e.
it downloaded the attachment from the server to a temporary file but
the file does not exist and so must not have been sent from the
server.
My conclusion is that W32.Klez.H@mm is in the definition file but it
only being used for file scanning. It needs to be enabled for email
scanning.
Ian Fisk
Author: Junaid
Date: 02:08 PM, Nov 11 PST
Subject: Re: Email with virus remains on server
Hi Ian,
Welcome back to Symantec Online Technical Support.
In your message you wrote:
>I have Norton AntiVirus 2003 installed, running and scanning my
>email. The virus definition file is current (6 November 2002). I have
>done a full scan of my system and it is not infected.
>The sequence of events is:
>1. An email infected with the W32.Yaha.F@mm virus arrives on my ISP's
>POP3 server.
>2. Outlook 2002 running on my PC tries to download the email.
>3. NAV 2003 scans the email and finds that it is infected. It should
>just delete the attachment which it does do for email infected with
>other virus. In the virus alert log there is a note that the
>Auto-Protect feature has automatically deleted an infected temporary
>file.
>4. Outlook is then told that the server connection has an error.
>5. Outlook then does not remove the email from the server. When it
>looks for mail the next time it will try to download the same
>infected email. This will repeat forever or until I use a web based
>mail client to delete the infected email.
Ian, Microsoft Outlook has an option to store a copy of the message on
the server. Because of this copy remaining on the server the infected
mail is downloaded again even after it has been detected and deleted
from your computer by Norton AntiVirus [NAV].
To resolve this issue, please follow the steps given below to uncheck
the option of leaving a copy of the message on the server:
1. Open Microsoft Outlook.
2. On the Tools menu, click Accounts.
3. Click the mail account, and then click Properties.
4. Click the Advanced tab, and then uncheck the option 'Leave a copy
of messages on server'.
Once you have completed these steps, I suggest that you contact you
Internet Service Provider [ISP] to delete the copy of the infected
mail that may remain on the server.
If you have further questions or concerns, please do not hesitate to
respond to this message.
Regards,
Junaid
Symantec Authorized Technical Support
Author: Ian Fisk
Date: 01:21 AM, Nov 14 PST
Subject: Re: Email with virus remains on server
Product:
Microsoft Outlook has the option 'Leave a copy
of messages on server' unchecked. This is the default that comes when
it is installed and I have never changed it.
It is only email infected with W32.Yaha.F@mm that remain on the
server.
It is only email infected with W32.Yaha.F@m that cause Outlook to say
that there was a connection error.
I repeat:
However it looks to me like the infected email is getting to Outlook.
Outlook then puts the attachment in a temporary file. NAV then
detects the virus in the temporary file and deletes it. This may
cause Outlook to think that the server connection has an error, i.e.
it downloaded the attachment from the server to a temporary file but
the file does not exist and so must not have been sent from the
server.
My conclusion is that W32.Klez.H@mm is in the definition file but it
only being used for file scanning. It needs to be enabled for email
scanning.
Author: Anu
Date: 12:14 PM, Nov 14 PST
Subject: Re: Email with virus remains on server
Hi Ian,
Welcome back to Symantec Online Technical Support.
I understand the inconvenience caused by this issue.
In your message you wrote:
>It is only email infected with W32.Yaha.F@mm that remain on the
>server.
Ian, in order to resolve this issue, I suggest you contact the
Internet Service Provider and inform them to delete this particular
file.
If you need further assistance, please do not hesitate to contact us.
Regards,
Anupama Bhat
Symantec Authorized Technical Support
Author: ianfisk
Date: 08:42 PM, Nov 14 PST
Subject: Re: Email with virus remains on server
Product:
What you are suggesting is that everytime that I receive an email
infected with the W32.Yaha.F@mm virus, I should "contact the
Internet Service Provider and inform them to delete this particular
file"?
What if I receive 100's of infected emails? This is unlikely but I
tend to get one every 3 days or so. I think that my ISP will get very
tired of my calls.
However as noted in my second reply I can "use a web based
mail client to delete the infected email."
Have you reported this bug in NAV 2003 to your development staff?
Do they have an idea when it will be fixed?
Author: Vinu
Date: 03:12 PM, Nov 15 PST
Subject: Re: Email with virus remains on server
Hi,
Thank you for contacting Symantec Online Technical Support.
From your post, I understand you have a concern with regard to
W32.Yaha.F@mm worm.
W32.Yaha.F@mm is a mass-mailing worm that sends itself to all email
addresses that exist in the Microsoft Windows Address Book, the MSN
Messenger List, the Yahoo Pager list, the ICQ list, and files that
have extensions that contain the letters ht. The worm randomly chooses
the subject and body of the email message. The attachment will have a
.bat, .pif or .scr file extension. Depending upon the name of the
Recycled folder, the worm either copies itself to that folder or to
the %Windows% folder.
The name of the file that the worm creates consists of four randomly
generated characters between c and y.
It also attempts to terminate antivirus and firewall processes.
If you need further information, Symantec has phone-based support for
these technical issues:
Consulting service is available 6 A.M. to 5 P.M. PST, Monday through
Friday.
Standard Consultation:
877-832-2811 Standard Consultation is a managed, "do-it-yourself"
option that includes diagnosis and a plan of action.
Premier Consultation:
877-832-2811 Premier Consultation is a full-service option that
includes a diagnosis and plan of action, plus step-by-step assistance
through the process.
Per Minute Consultation:
900-646-0004 Access Premier Consultation services.
If you need further assistance, please do not hesitate to contact us.
Regards,
Vinutha Lakshmi
Symantec Authorized Technical Support
Author: Ian Fisk
Date: 05:22 PM, Nov 15 PST
Subject: Re: Email with virus remains on server
Product: Norton AntiVirus 2003 for Windows 2000/Me/98/XP
Please read the rest of this discussion.
This is really nothing to do with the virus itself. I repeat for the
THIRD time:
NAV 2003 has a bug that allows the email with the infected
W32.Yaha.F@mm atachment to be read into Outlook. The attachment is
saved to the temporary directory. The Auto-Protect feature of NAV
then finds the virus, deletes the attachment file and tells me about
it. Outlook thinks that the attachment was not actually read from the
server and so there was an error with the connection. It then does
not delete the email from the server. Thus everytime that Outlook
reads email it always finds the infected email and I always get a
message from NAV.
Please report this to whoever looks after NAV 2003 and its virus
definition files.
Author: Rajeev
Date: 07:41 AM, Nov 17 PST
Subject: Re: Email with virus remains on server
Hi Ian,
Thank you for contacting Symantec Online Technical Support.
In your message you wrote:
>NAV 2003 has a bug that allows the email with the infected
>W32.Yaha.F@mm atachment to be read into Outlook. The attachment is
>saved to the temporary directory. The Auto-Protect feature of NAV
>then finds the virus, deletes the attachment file and tells me about
>it.
I suggest that you run LiveUpdate and download all the latest virus
definitions.
Please refer to the following document to run the LiveUpdate:
Title: 'How to run LiveUpdate'
Document ID: 1999121613163206
> Web URL:
http://service1.symantec....99121613163206?Open&src=w
After downloading the latest virus definitions, recreate the above
issue.
Also, I suggest that you run an Online Security Scan, which is
provided by Symantec. Since the Online Security Scan is run directly
from the Symantec server, it will have the latest virus updates. If
the Online Security Scan does not detect a virus, you can be rest
assured that your system is clean. If any virus is detected on your
system, you will be prompted to take appropriate steps.
To perform an Online Security Scan, please go through the link below:
>Web URL:
http://security.symantec.com
If the online scanner detects a virus, worm, or Trojan, then follow
these instructions:
a. Search for the name of the threat on the Symantec Security Response
Virus Encyclopedia Web site, and then follow the associated
instructions to remove the infection. Please click on the link below,
to look up the name of the threat on the Symantec Security Response
Virus Encyclopedia Web site:
>Web URL:
http://www.symantec.com/avcenter/vinfodb.html
b. If there is a removal utility available, then download and run the
utility to remove the virus.
I would like to bring to your notice that Symantec no longer supports
interactive virus removal help online. We do have several resources
that will assist you to troubleshoot the virus related issues.
Symantec has an extensive online knowledge base containing information
about Symantec products as well as documentation on specific virus,
trojan and worm removal at:
>Web URL:
http://www.symantec.com/techsupp/knowledge_base.html
If you wish to find information about a virus, trojan or worm, you can
visit our Security Response website at:
>Web URL:
http://www.sarc.com
This site includes the latest information about virus threats, links
to removal tools, and Symantec's virus encyclopedia that contains the
latest information about viruses, trojan's and worm's.
Symantec offers online virus scanning from our Security Check website
at:
>Web URL:
http://security.norton.com/.
From this site you can scan your system for viruses and security
risks. Symantec Security Check is a free service designed to help you
understand your computer's exposure to online security intrusions and
virus threats.
If you need interactive assistance removing a virus, trojan or worm
from your computer system, Symantec offers fee based virus phone
consultations you can use for assistance:
Symantec virus removal consulting service
Consulting service is available 6 A.M. to 5 P.M. PST, Monday through
Friday.
* Standard Consultation:
877-832-2811 Standard Consultation is a managed, "do-it-yourself"
option that includes diagnosis and a plan of action.
* Premier Consultation:
877-832-2811 Premier Consultation is a full-service option that
includes a diagnosis and plan of action, plus step-by-step assistance
through the process.
* Per Minute Consultation:
900-646-0004 Access Premier Consultation services.
For further feedback on this issue, please click on the link provided:
>Web URL:http://www.symantec.com/feedback/
If you have further questions or concerns, please do not hesitate to
respond to this message.
Regards,
Rajeev Kumar
Symantec Authorized Technical Support
Author: Ian Fisk
Date: 10:27 AM, Nov 17 PST
Subject: Re: Email with virus remains on server
Product:
I am NOT infected with a virus. NAV 2003's Auto-Protect feature
deletes the infected file. I have the latest virus definition file.
READ THE ISSUE!
Author: Shyam
Date: 04:03 AM, Nov 19 PST
Subject: Re: Email with virus remains on server
Hello Ian,
Welcome back. Thank you for contacting Symantec Online Technical
Support.
In your message you wrote:
>I am NOT infected with a virus. NAV 2003's Auto-Protect feature
>deletes the infected file. I have the latest virus definition file.
In order to resolve your issue, I suggest that you note down the
address from which the mails have been sent and contact your Internet
Service Provider (ISP) to block that particular address.
Note: Symantec is in the process of improving the way online support
messages are processed. Our goal is to provide you with a solution to
your question(s) in our first response. During this transition, should
you need additional information or assistance with your current
support request, please post a new inquiry to our support website.
The Symantec support Web site can be found at the following link:
http://www.symantec.com/techsupp/
If you need further assistance, please let us know. It will be a
pleasure to help you.
Regards,
Shyam Solaraju
Symantec Authorized Technical Support
---
Die support gasten komen echt van een andere planeet, ongelooflijk!!!