You could use banned file notification so that if a banned file gets held
that is not a known virus a notification is sent out.  We send these
notifications to the recipient, including enough information for them to
decide if the email is legit, and include a link to an ASP script that
requeues the file for delivery.  The user then just clicks the link if they
want to receive the email.

Works great for our users.

Note that we also use AVAFTERJM ON, so banned files that first fail spam
filtering do not send out these notifications, which cuts down significantly
on notifications resulting from new virus variants.

An/or you could spring for EVA Pro and ban files inside the zip, which
should lead to less legit banned files...at least for the time being.

Darin.


----- Original Message ----- 
From: "Rick Davidson" <[EMAIL PROTECTED]>
To: <[email protected]>
Sent: Tuesday, November 22, 2005 10:57 AM
Subject: Re: [Declude.Virus] New Virus Strain Pounding my systems


Point well taken... Problem is that prior to virus writers exploiting zip
files we pounded it into everyones head to use zip files... can't win for
losing. I will spend a day grabbing copies and see what that ramafications
of blocking zips would be. Main concern is avoiding getting screamed at for
holding up a million dollar real-estate deals.

Rick Davidson
National Systems Manager
North American Title Group

-
----- Original Message ----- 
From: "Kevin Bilbee" <[EMAIL PROTECTED]>
To: <[email protected]>
Sent: Monday, November 21, 2005 9:13 PM
Subject: RE: [Declude.Virus] New Virus Strain Pounding my systems


> This is not about executable formt is is about banning zips and encrypted
> zip files.
>
>
> Kevin Bilbee
>
>> -----Original Message-----
>> From: [EMAIL PROTECTED]
>> [mailto:[EMAIL PROTECTED] Behalf Of Rick Davidson
>> Sent: Monday, November 21, 2005 5:51 PM
>> To: [email protected]
>> Subject: Re: [Declude.Virus] New Virus Strain Pounding my systems
>>
>>
>> I would but my conundrum is that we receive alot of our loan packages in
>> executable format and the lenders could careless about what I have to say
>> about that... So I have to temporarily block them then have someone watch
>> for legit files and release them from quaratine as they come in.
>>
>> f-prot was right on top of it with a def release. kudos to them.
>>
>> John C that is hilarious!
>>
>> Rick Davidson
>> National Systems Manager
>> North American Title Group
>> -
>> ----- Original Message -----
>> From: "John T (Lists)" <[EMAIL PROTECTED]>
>> To: <[email protected]>
>> Sent: Monday, November 21, 2005 4:53 PM
>> Subject: RE: [Declude.Virus] New Virus Strain Pounding my systems
>>
>>
>> If you have Pro version you should be always blocking using
>> "BANZIPEXTS ON"
>> and "BANEZIPEXTS ON".
>>
>> John T
>> eServices For You
>>
>> > -----Original Message-----
>> > From: [EMAIL PROTECTED]
>> [mailto:[EMAIL PROTECTED]
>> > On Behalf Of Rick Davidson
>> > Sent: Monday, November 21, 2005 12:12 PM
>> > To: [email protected]
>> > Subject: Re: [Declude.Virus] New Virus Strain Pounding my systems
>> >
>> > It is coming in with alot of different zip file names and body
>> names now,
>> I
>> > blocked all zip files and submitted samples
>> >
>> > I am really getting hit hard
>> >
>> > Rick Davidson
>> > National Systems Manager
>> > North American Title Group
>> > 440-639-0607 - Office
>> > 951-233-6342 - Mobile
>> > [EMAIL PROTECTED]
>> > -
>> > ----- Original Message -----
>> > From: "Matt" <[EMAIL PROTECTED]>
>> > To: <[email protected]>
>> > Sent: Monday, November 21, 2005 2:51 PM
>> > Subject: Re: [Declude.Virus] New Virus Strain Pounding my systems
>> >
>> >
>> > > McAfee is detecting this currently as W32/[EMAIL PROTECTED]
>> F-Prot is still
>> > > missing it.  My first hit was at 2:08 p.m. EST, just 40
>> minutes ago and
>> > > McAfee seems to have had this one tagged prior to the
>> outbreak starting
>> > > since none have slipped through yet.
>> > >
>> > > Matt
>> > >
>> > >
>> > >
>> > > Rick Davidson wrote:
>> > >
>> > >> heads up folks, I am stopping a new zip virus with the following
>> junkmail
>> > >> rules, this is all I have seen so far. Contains an exacutable
>> > >> payload
>> > >> called File-packed_dataInfo.exe
>> > >>
>> > >> Rick Davidson
>> > >> National Systems Manager
>> > >> North American Title Group
>> > >> 440-639-0607 - Office
>> > >> 951-233-6342 - Mobile
>> > >> [EMAIL PROTECTED]
>> > >> -
>> > >> ---
>> > >> This E-mail came from the Declude.Virus mailing list.  To
>> > >> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
>> > >> type "unsubscribe Declude.Virus".    The archives can be found
>> > >> at http://www.mail-archive.com.
>> > >>
>> > >>
>> > > ---
>> > > This E-mail came from the Declude.Virus mailing list.  To
>> > > unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
>> > > type "unsubscribe Declude.Virus".    The archives can be found
>> > > at http://www.mail-archive.com.
>> > >
>> > >
>> >
>> > ---
>> > This E-mail came from the Declude.Virus mailing list.  To
>> > unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
>> > type "unsubscribe Declude.Virus".    The archives can be found
>> > at http://www.mail-archive.com.
>>
>> ---
>> This E-mail came from the Declude.Virus mailing list.  To
>> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
>> type "unsubscribe Declude.Virus".    The archives can be found
>> at http://www.mail-archive.com.
>>
>>
>> ---
>> This E-mail came from the Declude.Virus mailing list.  To
>> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
>> type "unsubscribe Declude.Virus".    The archives can be found
>> at http://www.mail-archive.com.
>> ---
>> [This E-mail scanned for viruses by Declude Virus]
>>
>>
>>
>
> ---
> [This E-mail scanned for viruses by Declude Virus]
>
> ---
> This E-mail came from the Declude.Virus mailing list.  To
> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
> type "unsubscribe Declude.Virus".    The archives can be found
> at http://www.mail-archive.com.
>
>

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to