I would but my conundrum is that we receive alot of our loan packages in
executable format and the lenders could careless about what I have to say
about that... So I have to temporarily block them then have someone watch
for legit files and release them from quaratine as they come in.
f-prot was right on top of it with a def release. kudos to them.
John C that is hilarious!
Rick Davidson
National Systems Manager
North American Title Group
-
----- Original Message -----
From: "John T (Lists)" <[EMAIL PROTECTED]>
To: <Declude.Virus@declude.com>
Sent: Monday, November 21, 2005 4:53 PM
Subject: RE: [Declude.Virus] New Virus Strain Pounding my systems
If you have Pro version you should be always blocking using "BANZIPEXTS ON"
and "BANEZIPEXTS ON".
John T
eServices For You
-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]
On Behalf Of Rick Davidson
Sent: Monday, November 21, 2005 12:12 PM
To: Declude.Virus@declude.com
Subject: Re: [Declude.Virus] New Virus Strain Pounding my systems
It is coming in with alot of different zip file names and body names now,
I
blocked all zip files and submitted samples
I am really getting hit hard
Rick Davidson
National Systems Manager
North American Title Group
440-639-0607 - Office
951-233-6342 - Mobile
[EMAIL PROTECTED]
-
----- Original Message -----
From: "Matt" <[EMAIL PROTECTED]>
To: <Declude.Virus@declude.com>
Sent: Monday, November 21, 2005 2:51 PM
Subject: Re: [Declude.Virus] New Virus Strain Pounding my systems
> McAfee is detecting this currently as W32/[EMAIL PROTECTED] F-Prot is still
> missing it. My first hit was at 2:08 p.m. EST, just 40 minutes ago and
> McAfee seems to have had this one tagged prior to the outbreak starting
> since none have slipped through yet.
>
> Matt
>
>
>
> Rick Davidson wrote:
>
>> heads up folks, I am stopping a new zip virus with the following
junkmail
>> rules, this is all I have seen so far. Contains an exacutable payload
>> called File-packed_dataInfo.exe
>>
>> Rick Davidson
>> National Systems Manager
>> North American Title Group
>> 440-639-0607 - Office
>> 951-233-6342 - Mobile
>> [EMAIL PROTECTED]
>> -
>> ---
>> This E-mail came from the Declude.Virus mailing list. To
>> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
>> type "unsubscribe Declude.Virus". The archives can be found
>> at http://www.mail-archive.com.
>>
>>
> ---
> This E-mail came from the Declude.Virus mailing list. To
> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
> type "unsubscribe Declude.Virus". The archives can be found
> at http://www.mail-archive.com.
>
>
---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus". The archives can be found
at http://www.mail-archive.com.
---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus". The archives can be found
at http://www.mail-archive.com.
---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus". The archives can be found
at http://www.mail-archive.com.