{"id":3285,"date":"2005-03-20T02:19:00","date_gmt":"2005-03-20T07:19:00","guid":{"rendered":"https:\/\/wastinaway.net\/shortfatguy\/?p=3285"},"modified":"2021-06-06T02:26:23","modified_gmt":"2021-06-06T06:26:23","slug":"virus-scanning","status":"publish","type":"post","link":"https:\/\/wastinaway.net\/shortfatguy\/2005\/03\/20\/virus-scanning\/","title":{"rendered":"Virus Scanning"},"content":{"rendered":"\n<img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/wastinaway.net\/shortfatguy\/images\/techbug.gif?resize=65%2C20&#038;ssl=1\" width=\"65\" height=\"20\">&nbsp; &nbsp; Yes, I am quite aware how there are no viruses for Macs. However, Macs can get Windows viruses, although obviously those viruses have absolutely no effect on a Mac. Still, I like to be a good Internet citizen so I periodically scan my Library directory and my caches for viruses just so I don&#8217;t inadvertently pass something along in an e-mail. I guess I hadn&#8217;t checked my e-mail caches in a while, because I was alerted &#8220;Exploit.HTML.MHT-6&#8221; had been found in my main mailbox!<br>&nbsp; &nbsp; The only thing was there was no way to quarantine the virus. To do so would reportedly move my entire &#8220;mbox&#8221; cache.  Due to limitations in the <a href=\"http:\/\/www.clamxav.com\/\" >clamXav<\/a> software I was using I was not told which of the e-mails contained the virus, just that it was in there. I first skimmed through the mailbox, looking for anything suspicious. I moved these letters into a newly created folder called Questionable. I ran another virus scan and got the same result. I then skimmed through the mailbox again, deleting e-mails I didn&#8217;t need: old confirmations from Paypal, alerts from eBay, old newsletters; anything dated that I no longer needed. Another scan showed there was no change. I still had not found that one e-mail. The only thing was to start methodically searching. I moved everything from March into a separate folder and ran another search. Then February, then January, then December, onward. Fortunately I found out ahead of time that, <a href=\"http:\/\/www.versiontracker.com\/dyn\/moreinfo\/macosx\/24449&#038;mode=feedback\" >according to the application&#8217;s author<\/a>, &#8220;The important thing to remember if you&#8217;re using Apple&#8217;s Mail program is that the move from one mailbox to another doesn&#8217;t actually take effect until you quit the Mail program. Scanning with Mail open is just a huge waste of time\u2026not that I&#8217;ve ever done that of course\u2026never\u2026not me! &#59;-&#41;&#8221;.<br>&nbsp; &nbsp; I at least made some progress when I found out the virus dated from October 2004. I created new folders: &#8220;1 &#8211; 10&#8221; and &#8220;11 &#8211; 20&#8221; and &#8220;21 &#8211; 31&#8221; and moved the October e-mails accordingly. And I found the virus was inhabiting the &#8220;11 &#8211; 20&#8221; folder.  I created another set of folders: &#8220;11&#8221;, &#8220;12&#8221;, &#8220;13&#8221;, &#8220;14&#8221;, and &#8220;15&#8221;, for starters, and soon deduced that the virus had to have been sent October 13.<br>&nbsp; &nbsp; I checked the October 13 folder and was a tad concerned to find those e-mails were from legitimate sources. It was possible someone I knew or did business with might have been infected. But then, upon closer inspection, I was able to see exactly what the problem was and where the virus was. It was even helpfully in an e-mail called &#8220;Exploit&#8221;. It was back during the days when my IPowerWeb server had been continually attacked with Trojans. I had found a line of code being attached to my PHP and I&#8217;d copied the code and sent it to myself. The one line was not a Trojan, but I guess it linked to one, which was enough to set off alarms in both <a href=\"http:\/\/www.clamxav.com\/\" >clamXav<\/a> and <a href=\"http:\/\/www.apple.com\/support\/dotmac\/virex\/\" >Virex 7.5<\/a> \u2026 and which caused me to waste an hour and a half, as well as your time here, hunting down an e-mail I had sent <i>to myself<\/I>.\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; &nbsp; Yes, I am quite aware how there are no viruses for Macs. However, Macs can get Windows viruses, although obviously those viruses have absolutely no effect on a Mac. Still, I like to be a good Internet citizen &hellip; <a href=\"https:\/\/wastinaway.net\/shortfatguy\/2005\/03\/20\/virus-scanning\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"nf_dc_page":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[25,11],"tags":[],"class_list":["post-3285","post","type-post","status-publish","format-standard","hentry","category-apple","category-tech"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wastinaway.net\/shortfatguy\/wp-json\/wp\/v2\/posts\/3285","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wastinaway.net\/shortfatguy\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wastinaway.net\/shortfatguy\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wastinaway.net\/shortfatguy\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wastinaway.net\/shortfatguy\/wp-json\/wp\/v2\/comments?post=3285"}],"version-history":[{"count":1,"href":"https:\/\/wastinaway.net\/shortfatguy\/wp-json\/wp\/v2\/posts\/3285\/revisions"}],"predecessor-version":[{"id":3286,"href":"https:\/\/wastinaway.net\/shortfatguy\/wp-json\/wp\/v2\/posts\/3285\/revisions\/3286"}],"wp:attachment":[{"href":"https:\/\/wastinaway.net\/shortfatguy\/wp-json\/wp\/v2\/media?parent=3285"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wastinaway.net\/shortfatguy\/wp-json\/wp\/v2\/categories?post=3285"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wastinaway.net\/shortfatguy\/wp-json\/wp\/v2\/tags?post=3285"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}