<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.catug.org/w/index.php?action=history&amp;feed=atom&amp;title=Jotti%27s_malware_scan</id>
	<title>Jotti&#039;s malware scan - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.catug.org/w/index.php?action=history&amp;feed=atom&amp;title=Jotti%27s_malware_scan"/>
	<link rel="alternate" type="text/html" href="https://wiki.catug.org/w/index.php?title=Jotti%27s_malware_scan&amp;action=history"/>
	<updated>2026-05-01T09:09:04Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://wiki.catug.org/w/index.php?title=Jotti%27s_malware_scan&amp;diff=1408&amp;oldid=prev</id>
		<title>N Reid: clarify</title>
		<link rel="alternate" type="text/html" href="https://wiki.catug.org/w/index.php?title=Jotti%27s_malware_scan&amp;diff=1408&amp;oldid=prev"/>
		<updated>2014-06-28T10:07:16Z</updated>

		<summary type="html">&lt;p&gt;clarify&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 10:07, 28 June 2014&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;You may wish to obtain a second opinion about an email attachment, even if you have [[Anti-Virus Software for Macintosh]] and it does not report an infection.  &lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;You may wish to obtain a second opinion about an email attachment, even if you have [[Anti-Virus Software for Macintosh]] and it does not report an infection.  &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[http://virusscan.jotti.org/en Jotti&amp;#039;s malware scan] will &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;upload &lt;/del&gt;the file &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;and run it &lt;/del&gt;through several scanners.   &lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Upload it to &lt;/ins&gt;[http://virusscan.jotti.org/en Jotti&amp;#039;s malware scan]&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;. This website &lt;/ins&gt;will &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;run &lt;/ins&gt;the file through several scanners &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;and show the results of them all&lt;/ins&gt;.   &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=Case study=&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=Case study=&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>N Reid</name></author>
	</entry>
	<entry>
		<id>https://wiki.catug.org/w/index.php?title=Jotti%27s_malware_scan&amp;diff=1404&amp;oldid=prev</id>
		<title>N Reid: /* Case study */ image</title>
		<link rel="alternate" type="text/html" href="https://wiki.catug.org/w/index.php?title=Jotti%27s_malware_scan&amp;diff=1404&amp;oldid=prev"/>
		<updated>2014-06-23T11:31:54Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Case study: &lt;/span&gt; image&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 11:31, 23 June 2014&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l17&quot;&gt;Line 17:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 17:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Attached to the email was a Zip file, containing an EXE file.  So it was obviously not a letter.  Now normally I would simply delete an email like this and go along my merry way, but I happened to have a few minutes to satisfy my curiosity as to the actual contents of this likely malicious message.  So I fired up Kaspersky, which came free with Parallels last year.  Scanned the file, both zipped and unzipped with no infection found.  Slightly incredulous, I then launched ClamXav and repeated the scans with the same negative result.  Refusing to disbelieve my instinct that this was one of the millions of malicious emails circulated to unwitting Windows users daily, I found a great, simple website called Jotti&amp;#039;s Malware Scan.  &lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Attached to the email was a Zip file, containing an EXE file.  So it was obviously not a letter.  Now normally I would simply delete an email like this and go along my merry way, but I happened to have a few minutes to satisfy my curiosity as to the actual contents of this likely malicious message.  So I fired up Kaspersky, which came free with Parallels last year.  Scanned the file, both zipped and unzipped with no infection found.  Slightly incredulous, I then launched ClamXav and repeated the scans with the same negative result.  Refusing to disbelieve my instinct that this was one of the millions of malicious emails circulated to unwitting Windows users daily, I found a great, simple website called Jotti&amp;#039;s Malware Scan.  &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Here was the result of their scan of the unzipped file...&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Here was the result of their scan of the unzipped file...&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;br/&amp;gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[File:Jotti&amp;#039;s malware scan.jpeg|alt=Screen capture showing scan result]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;So, just fyi, don&amp;#039;t ignore your instincts, and don&amp;#039;t necessarily trust a clean virus scan.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;So, just fyi, don&amp;#039;t ignore your instincts, and don&amp;#039;t necessarily trust a clean virus scan.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>N Reid</name></author>
	</entry>
	<entry>
		<id>https://wiki.catug.org/w/index.php?title=Jotti%27s_malware_scan&amp;diff=1402&amp;oldid=prev</id>
		<title>N Reid: create article from Man-Min</title>
		<link rel="alternate" type="text/html" href="https://wiki.catug.org/w/index.php?title=Jotti%27s_malware_scan&amp;diff=1402&amp;oldid=prev"/>
		<updated>2014-06-23T11:27:41Z</updated>

		<summary type="html">&lt;p&gt;create article from Man-Min&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;You may wish to obtain a second opinion about an email attachment, even if you have [[Anti-Virus Software for Macintosh]] and it does not report an infection. &lt;br /&gt;
&lt;br /&gt;
[http://virusscan.jotti.org/en Jotti&amp;#039;s malware scan] will upload the file and run it through several scanners.  &lt;br /&gt;
&lt;br /&gt;
=Case study=&lt;br /&gt;
Hello folks,&lt;br /&gt;
&lt;br /&gt;
I&amp;#039;m passing this along for educational value.  I received, last night, and email with the following message: &lt;br /&gt;
&lt;br /&gt;
&amp;quot;Notice to appear in court,&lt;br /&gt;
&lt;br /&gt;
You may find the detailed pretrial notice attached to this letter.&lt;br /&gt;
&lt;br /&gt;
Recording secretary,&lt;br /&gt;
Diana Mason&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Attached to the email was a Zip file, containing an EXE file.  So it was obviously not a letter.  Now normally I would simply delete an email like this and go along my merry way, but I happened to have a few minutes to satisfy my curiosity as to the actual contents of this likely malicious message.  So I fired up Kaspersky, which came free with Parallels last year.  Scanned the file, both zipped and unzipped with no infection found.  Slightly incredulous, I then launched ClamXav and repeated the scans with the same negative result.  Refusing to disbelieve my instinct that this was one of the millions of malicious emails circulated to unwitting Windows users daily, I found a great, simple website called Jotti&amp;#039;s Malware Scan. &lt;br /&gt;
&lt;br /&gt;
Here was the result of their scan of the unzipped file...&lt;br /&gt;
&lt;br /&gt;
So, just fyi, don&amp;#039;t ignore your instincts, and don&amp;#039;t necessarily trust a clean virus scan.&lt;br /&gt;
&lt;br /&gt;
in His service,&lt;br /&gt;
David Burke&lt;br /&gt;
&lt;br /&gt;
=External links=&lt;br /&gt;
* http://virusscan.jotti.org/en&lt;br /&gt;
&lt;br /&gt;
=Credits=&lt;br /&gt;
Recommended on the [[Mac-Ministry List]] by David Burke in June 2014&lt;br /&gt;
&lt;br /&gt;
[[Category:Websites]]&lt;/div&gt;</summary>
		<author><name>N Reid</name></author>
	</entry>
</feed>