Yep, these are being detected by NAI (W32/[EMAIL PROTECTED]) and ClamAV (Worm.Sober.P), but not yet being detected by TrendMicro or F-Prot (although I have F-Prot updates disabled for now, until they get there problem with HTML/[EMAIL PROTECTED] fixed).

Bill
----- Original Message ----- From: "John Tolmachoff (Lists)" <[EMAIL PROTECTED]>
To: <[email protected]>
Sent: Monday, May 02, 2005 11:11 AM
Subject: RE: [Declude.Virus] Viruses appearing to be getting through...



I saw a big bunch about 2 hours ago that were stopped by banned zip
extensions.

John T
eServices For You


-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]
On Behalf Of Chuck Schick
Sent: Monday, May 02, 2005 10:58 AM
To: Declude. Virus
Subject: [Declude.Virus] Viruses appearing to be getting through...

I am seeing several files getting through that appear to have viruses
attached as zip files.  I am running Declude with F-Prot.  We ban
encrypted
zips and I have error code 8 included.  Anyone else seeing this behavior?
Here is part of the log.


05/02/2005 10:34:20 Q568a382 MIME file: account_info-text.zip [base64; Length=53728 Checksum=5837399] 05/02/2005 10:34:21 Q568a382 Scanned: Virus Free [MIME: 2 53979]

Chuck Schick
Warp 8, Inc.
(303)-421-5140
www.warp8.com

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

--- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.


--- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.

Reply via email to