> This is actually a virus: > > >FROM: "Microsoft Network Security Section" <[EMAIL PROTECTED]> > >TO: " " <[EMAIL PROTECTED]> > >SUBJECT: New Internet Security Pack > >Mime-Version: 1.0 > >Content-Type: multipart/mixed; boundary="gkxrxour" > >Message-Id: <[EMAIL PROTECTED]> > >Date: Mon, 6 Oct 2003 08:33:57 +1300 > > This appears to be W32/Harmony.A. > > -Scott
SWEN was such a hit, we've been seeing a number of these messages where another virus has infected the SWEN attachment and sent itself out. So far, CIH and FUNLOVE are winning as secondary infections here. Obviously, you can set up a rule to hold anything with "Microsoft Network Security" in the subject. Or, buy a decent A/V program, as you are always far behind with trying to stop viruses with mail rules (including attachment bans, as the latest, smarter attempts are using .zip, the only attachment that nearly everyone allows in and that many people don't scan inside). K --- [This E-mail scanned for viruses by Declude Virus] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.JunkMail mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.JunkMail". The archives can be found at http://www.mail-archive.com.
