John,
        Did you add: Mydoom  or Mydoom.A or the full W32/[EMAIL PROTECTED] to your 
SKIP...
 
Keith

        -----Original Message----- 
        From: John Tolmachoff (Lists) [mailto:[EMAIL PROTECTED] 
        Sent: Mon 1/26/2004 6:32 PM 
        To: [EMAIL PROTECTED] 
        Cc: 
        Subject: RE: [Declude.Virus] New, fast-spreading virus: MyDoom
        
        

        I have now added this to the list of forging viruses in the virus.cfg and
        added SKIPIFVIRUSNAMEHAS in the recip.eml file.
        
        John Tolmachoff
        Engineer/Consultant/Owner
        eServices For You
        
        
        > -----Original Message-----
        > From: [EMAIL PROTECTED] [mailto:Declude.Virus-
        > [EMAIL PROTECTED] On Behalf Of John Tolmachoff (Lists)
        > Sent: Monday, January 26, 2004 3:19 PM
        > To: [EMAIL PROTECTED]
        > Subject: RE: [Declude.Virus] New, fast-spreading virus: MyDoom
        >
        > Confirmed here that F-Prot is now catching.
        >
        > 01/26/2004 15:16:56 Q9fe7039901d8f7c9 MIME file: readme.scr [base64;
        > Length=22528 Checksum=2535504]
        > 01/26/2004 15:16:56 Q9fe7039901d8f7c9 Banning file with scr extension
        > [application/octet-stream].
        > 01/26/2004 15:16:56 Q9fe7039901d8f7c9 Scanner 1: Virus=: W32/[EMAIL 
PROTECTED]
        > Attachment=readme.scr [11] O
        > 01/26/2004 15:16:56 Q9fe7039901d8f7c9 File(s) are INFECTED [:
        > W32/[EMAIL PROTECTED]: 3]
        > 01/26/2004 15:16:57 Q9fe7039901d8f7c9 Scanned: CONTAINS A VIRUS [MIME: 2
        > 22775]
        > 01/26/2004 15:16:57 Q9fe7039901d8f7c9 From: xxxxxxxxxxxxx To:
        > yyyyyyyyyyyyyy[outgoing from 12.124.150.50]
        > 01/26/2004 15:16:57 Q9fe7039901d8f7c9 Subject: TEST
        >
        > John Tolmachoff
        > Engineer/Consultant/Owner
        > eServices For You
        >
        >
        > > -----Original Message-----
        > > From: [EMAIL PROTECTED] [mailto:Declude.Virus-
        > > [EMAIL PROTECTED] On Behalf Of Andy Schmidt
        > > Sent: Monday, January 26, 2004 2:57 PM
        > > To: [EMAIL PROTECTED]
        > > Subject: RE: [Declude.Virus] New, fast-spreading virus: MyDoom
        > >
        > > Hi,
        > >
        > > >> would there be anyway to have declude be able to detect that a zip
        > file
        > > includes a .scr file inside and block it when you use the :banext scr"
        > > option in the virus.cfg file? <<
        > >
        > > Well - this warrants further disucssions.
        > >
        > > So far, we have been instructing/educating users that they SHOULD zip
        > > their
        > > SCR EXE and other banned file extensions into ZIP files.  If we now ban
        > > ZIP
        > > files because they contain the very files that we told customers to ZIP,
        > > then we have customers in a catch-22.
        > >
        > > Best Regards
        > > Andy Schmidt
        > >
        > > H&M Systems Software, Inc.
        > > 600 East Crescent Avenue, Suite 203
        > > Upper Saddle River, NJ 07458-1846
        > >
        > > Phone:  +1 201 934-3414 x20 (Business)
        > > Fax:    +1 201 934-9206
        > >
        > > http://www.HM-Software.com/
        > >
        > >
        > > ---
        > > [This E-mail was scanned for viruses by Declude Virus
        > > (http://www.declude.com)]
        > >
        > > ---
        > > This E-mail came from the Declude.Virus mailing list.  To
        > > unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
        > > type "unsubscribe Declude.Virus".    The archives can be found
        > > at http://www.mail-archive.com.
        >
        > ---
        > [This E-mail was scanned for viruses by Declude Virus
        > (http://www.declude.com)]
        >
        > ---
        > This E-mail came from the Declude.Virus mailing list.  To
        > unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
        > type "unsubscribe Declude.Virus".    The archives can be found
        > at http://www.mail-archive.com.
        
        ---
        [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
        
        ---
        This E-mail came from the Declude.Virus mailing list.  To
        unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
        type "unsubscribe Declude.Virus".    The archives can be found
        at http://www.mail-archive.com.
        

<<winmail.dat>>

Reply via email to