I would but my conundrum is that we receive alot of our loan packages in executable format and the lenders could careless about what I have to say about that... So I have to temporarily block them then have someone watch for legit files and release them from quaratine as they come in.

f-prot was right on top of it with a def release. kudos to them.

John C that is hilarious!

Rick Davidson
National Systems Manager
North American Title Group
-
----- Original Message ----- From: "John T (Lists)" <[EMAIL PROTECTED]>
To: <Declude.Virus@declude.com>
Sent: Monday, November 21, 2005 4:53 PM
Subject: RE: [Declude.Virus] New Virus Strain Pounding my systems


If you have Pro version you should be always blocking using "BANZIPEXTS ON"
and "BANEZIPEXTS ON".

John T
eServices For You

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]
On Behalf Of Rick Davidson
Sent: Monday, November 21, 2005 12:12 PM
To: Declude.Virus@declude.com
Subject: Re: [Declude.Virus] New Virus Strain Pounding my systems

It is coming in with alot of different zip file names and body names now,
I
blocked all zip files and submitted samples

I am really getting hit hard

Rick Davidson
National Systems Manager
North American Title Group
440-639-0607 - Office
951-233-6342 - Mobile
[EMAIL PROTECTED]
-
----- Original Message -----
From: "Matt" <[EMAIL PROTECTED]>
To: <Declude.Virus@declude.com>
Sent: Monday, November 21, 2005 2:51 PM
Subject: Re: [Declude.Virus] New Virus Strain Pounding my systems


> McAfee is detecting this currently as W32/[EMAIL PROTECTED]  F-Prot is still
> missing it.  My first hit was at 2:08 p.m. EST, just 40 minutes ago and
> McAfee seems to have had this one tagged prior to the outbreak starting
> since none have slipped through yet.
>
> Matt
>
>
>
> Rick Davidson wrote:
>
>> heads up folks, I am stopping a new zip virus with the following
junkmail
>> rules, this is all I have seen so far. Contains an exacutable payload
>> called File-packed_dataInfo.exe
>>
>> Rick Davidson
>> National Systems Manager
>> North American Title Group
>> 440-639-0607 - Office
>> 951-233-6342 - Mobile
>> [EMAIL PROTECTED]
>> -
>> ---
>> This E-mail came from the Declude.Virus mailing list.  To
>> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
>> type "unsubscribe Declude.Virus".    The archives can be found
>> at http://www.mail-archive.com.
>>
>>
> ---
> This E-mail came from the Declude.Virus mailing list.  To
> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
> type "unsubscribe Declude.Virus".    The archives can be found
> at http://www.mail-archive.com.
>
>

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.


---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to