Scan iSeries Mail for Viruses with StandGuard Anti-Virus
Thursday, September 18th, 2003RENO, Nevada—Bytware, Inc., announces the first electronic mail scanner for OS/400 mail. This significant enhancement to StandGuard Anti-Virus provides the ability to scan electronic mail messages passing through the OS/400 Mail Server Framework (MSF) for viruses and malicious programs. Companies using the iSeries to receive Internet e-mail can implement StandGuard Anti-Virus to perform virus scanning on e-mail messages before they reach the PC clients. StandGuard Anti-Virus’s mail scanning features include:
- Scans iSeries SMTP e-mail at the server
- Scans inside archive files such as .ZIP, .JAR, etc.
- Detects header exploits and malformed MIME
- Redirects infected or suspicious e-mail to an Administrator
Scans SMTP e-mail at the server
StandGuard Anti-Virus scans e-mail messages passing through the iSeries OS/400 Mail Server Framework, looking for known viruses as well as code that could be malicious. This means it can protect against known viruses, but most importantly, potentially against unknown viruses and/or malicious code. This is crucial as an unknown virus could be a one-off piece of code, developed specifically to break into your network.
Scans compressed and encoded messages
StandGuard Anti-Virus scans deep inside attachments to detect viruses buried in multiple levels of encoding and compression. StandGuard Anti-Virus decodes BINHEX, UUENCODE and XXENCODE, MIME (BASE64 and quoted-printable), TNEF, and IMC attachments. Files compressed with PKZIP, ZIP2EXE, ARJ, ARJ2EXE, JAR, LHA, LHA2EXE, TAR, GZIP, UNIX PACK, and MS compression methods are also effectively scanned. StandGuard Anti-Virus even scans files with multiple compression levels; for example, a ZIP file that has also been compressed with LZEXE and ARJ, then zipped again, and so on.
Detects header exploits and malformed MIME
MIME headers specify things such as the subject line, date, or filename. By specifying a well-crafted string, a skilled hacker could execute arbitrary code on the target machines. Such vulnerabilities are prone to exploitation for penetrating remote networks or for delivery of viruses and worms. This vulnerability allows attached executable files to be run when a message is simply viewed. Several common viruses make use of this exploit, including W32/Badtrans@MM, W32/Nimda.gen@MM, and W32/Klez.gen@MM. StandGuard Anti-Virus detects these header exploit tactics and blocks these messages from reaching your desktop clients such as Outlook Express where the virus is able to execute.
Redirects infected or suspicious e-mail to an Administrator
When a known virus, potentially malicious program, or an e-mail using a MIME header exploit is detected, StandGuard Anti-Virus can either redirect the mail to an administrator or simply delete the mail without forwarding. In either case, a message is logged to the AVMSGQ for real-time monitoring purposes and the AVJRN for a more permanent audit trail.
StandGuard Anti-Virus (Powered By McAfee) is a native iSeries virus detection solution designed to scan and clean viruses hiding in the OS/400 file system. StandGuard Anti-Virus incorporates the latest generation of McAfee’s scanning engine, in turn making StandGuard Anti-Virus a mature product backed by battle-tested technology, advanced heuristic analysis and generic detection, and cleaning.
Version 1.1 will be available October 1, 2003.
For more information on StandGuard Anti-Virus visit the main product page.
About McAfee Anti-Virus Security Products
McAfee anti-virus security products are a part of Network Associates McAfee Systems Protection Solutions family of products, which protect systems from security breaches, virus attacks and blended threats by providing comprehensive system and network protection. In addition to industry leading anti-virus, encryption, desktop firewall, intrusion detection, viral vulnerability assessment and online managed services, all McAfee Security products are backed by the world-leading anti-virus research organization, McAfee® AVERT(TM) (Anti-Virus and Vulnerability Emergency Response Team). McAfee AVERT is the team responsible for providing cures for major outbreaks like Mydoom, Netsky, Bagle, Blaster, Nachi and Lovsan. For more information, McAfee experts can be reached at 888-VIRUS-NO, and on the Internet at http://www.mcafeesecurity.com.

