I also started catching them at 16:21 Eastern Time Scanner 1 is FPROT

05/02/2005 16:21:48 Q8BBB4614012AF05F Scanner 1: Virus= W32/[EMAIL PROTECTED]
Attachment=account_info.zip [2] O
05/02/2005 16:21:49 Q8BBB4614012AF05F Scanner 2: Virus= the
W32/[EMAIL PROTECTED] Attachment=account_info.zip [2] O

I have the same defs as Bonno

> SIGN.DEF 2-may-2005, 13:32
> SIGN2.DEF 2-may-2005, 16:46
> Using f-prot 3.16b 
 
 
     Goran Jovanovic
     The LAN Shoppe


> -----Original Message-----
> From: [EMAIL PROTECTED] [mailto:Declude.Virus-
> [EMAIL PROTECTED] On Behalf Of Chuck Schick
> Sent: Monday, May 02, 2005 3:36 PM
> To: [email protected]
> Subject: RE: [Declude.Virus] Viruses appearing to be getting
through...
> 
> F-Prot Seems to be catching it now as
> 
> X-Declude-Virus: Detected  W32/[EMAIL PROTECTED]
> 
> Chuck Schick
> Warp 8, Inc.
> (303)-421-5140
> www.warp8.com
> 
> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED] On Behalf Of John Tolmachoff
> (Lists)
> Sent: Monday, May 02, 2005 12:55 PM
> To: [email protected]
> Subject: RE: [Declude.Virus] Viruses appearing to be getting
through...
> 
> 
> Mine has the 01:32 PM time stamp and the last update time was at 10:00
AM
> which is after when I saw the problem, so I would have to say the
01:32
> time
> stamp is the problem one.
> 
> John T
> eServices For You
> 
> 
> > -----Original Message-----
> > From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]
> > On Behalf Of Colbeck, Andrew
> > Sent: Monday, May 02, 2005 11:38 AM
> > To: [email protected]
> > Subject: RE: [Declude.Virus] Viruses appearing to be getting
> > through...
> >
> > F-Prot may have already fixed their pattern file.  My current
sign.def
> > is timestamped:
> >
> > 05/02/2005  03:53 AM
> >
> > and checking their website and downloading the current version
> > manually shows that the current version is:
> >
> > 05/02/2005  01:32 PM
> >
> > Can anybody with the issue confirm which pattern file they are using
> > that has the problem?
> >
> > Andrew 8)
> >
> > -----Original Message-----
> > From: [EMAIL PROTECTED]
> > [mailto:[EMAIL PROTECTED] On Behalf Of Bill Landry
> > Sent: Monday, May 02, 2005 11:20 AM
> > To: [email protected]
> > Subject: Re: [Declude.Virus] Viruses appearing to be getting
> > through...
> >
> >
> > Yep, these are being detected by NAI (W32/[EMAIL PROTECTED]) and ClamAV
> > (Worm.Sober.P), but not yet being detected by TrendMicro or F-Prot
> > (although I have F-Prot updates disabled for now, until they get
there
> > problem with
> > HTML/[EMAIL PROTECTED] fixed).
> >
> > Bill
> > ----- Original Message -----
> > From: "John Tolmachoff (Lists)" <[EMAIL PROTECTED]>
> > To: <[email protected]>
> > Sent: Monday, May 02, 2005 11:11 AM
> > Subject: RE: [Declude.Virus] Viruses appearing to be getting
> > through...
> >
> >
> > >I saw a big bunch about 2 hours ago that were stopped by banned zip
> > >extensions.
> > >
> > > John T
> > > eServices For You
> > >
> > >
> > >> -----Original Message-----
> > >> From: [EMAIL PROTECTED]
> > > [mailto:[EMAIL PROTECTED]
> > >> On Behalf Of Chuck Schick
> > >> Sent: Monday, May 02, 2005 10:58 AM
> > >> To: Declude. Virus
> > >> Subject: [Declude.Virus] Viruses appearing to be getting
through...
> > >>
> > >> I am seeing several files getting through that appear to have
> > >> viruses
> >
> > >> attached as zip files.  I am running Declude with F-Prot.  We ban
> > > encrypted
> > >> zips and I have error code 8 included.  Anyone else seeing this
> > >> behavior? Here is part of the log.
> > >>
> > >>
> > >> 05/02/2005 10:34:20 Q568a382 MIME file: account_info-text.zip
> > >> [base64; Length=53728 Checksum=5837399] 05/02/2005 10:34:21
> > >> Q568a382
> > >> Scanned: Virus Free [MIME: 2 53979]
> > >>
> > >> Chuck Schick
> > >> Warp 8, Inc.
> > >> (303)-421-5140
> > >> www.warp8.com
> > >>
> > >> ---
> > >> This E-mail came from the Declude.Virus mailing list.  To
> > >> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
> > >> type "unsubscribe Declude.Virus".    The archives can be found
> > >> at http://www.mail-archive.com.
> > >
> > > ---
> > > This E-mail came from the Declude.Virus mailing list.  To
> > > unsubscribe,
> >
> > > just send an E-mail to [EMAIL PROTECTED], and
> > > type "unsubscribe Declude.Virus".    The archives can be found
> > > at http://www.mail-archive.com.
> > >
> >
> > ---
> > This E-mail came from the Declude.Virus mailing list.  To
unsubscribe,
> > just send an E-mail to [EMAIL PROTECTED], and
> > type "unsubscribe Declude.Virus".    The archives can be found
> > at http://www.mail-archive.com.
> > ---
> > This E-mail came from the Declude.Virus mailing list.  To
unsubscribe,
> > just send an E-mail to [EMAIL PROTECTED], and
> > type "unsubscribe Declude.Virus".    The archives can be found
> > at http://www.mail-archive.com.
> 
> ---
> This E-mail came from the Declude.Virus mailing list.  To unsubscribe,
> just
> send an E-mail to [EMAIL PROTECTED], and
> type "unsubscribe Declude.Virus".    The archives can be found
> at http://www.mail-archive.com.
> 
> ---
> This E-mail came from the Declude.Virus mailing list.  To
> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
> type "unsubscribe Declude.Virus".    The archives can be found
> at http://www.mail-archive.com.
---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to