Matt, are you saying the attachment as Declude would see it is B64, UU, UUE, MIM, MME, BHX and HQX? If that is so, what harm would be in blocking those for now?
John T eServices For You
"Seek, and ye shall find!"
-----Original Message-----
Someone just reported to me that MyWife.d
(McAfee)/Kapser.A (F-Prot)/Blackmal.E (Symantec)/etc., has a 3rd of the month
payload that will overwrite a bunch of files. It's really nasty.
More can be found at these links: 01/16/2006 05:36:49 Q7741EFB6011C4F95 MIME file: [text/html][7bit; Length=1953 Checksum=154023] There was no mention about the payload inside of it,
and there almost definitely was. The same attachment name with the same
length was repeatedly detected as a virus later on that day. This likely
was a PIF file inside, though it could also have been a JPG according the notes
on this virus. I, like most of us here, don't allow PIF's to be sent
through our system, but when the PIF is encoded in at least BinHex format, it
gets past this type of protection. |
- [Declude.Virus] Encoded viruses...worried Matt
- RE: [Declude.Virus] Encoded viruses...worried John T \(Lists\)
- RE: [Declude.Virus] Encoded viruses...worried John T \(Lists\)
- RE: [Declude.Virus] Encoded viruses...worried Mark Reimer
- RE: [Declude.Virus] Encoded viruses...worrie... John T \(Lists\)
- Re: [Declude.Virus] Encoded viruses...worrie... Matt
- RE: [Declude.Virus] Encoded viruses...wo... Mark Reimer
- Re: [Declude.Virus] Encoded viruses...worried Scott Fisher
- RE: [Declude.Virus] Encoded viruses...worried Markus Gufler
- RE: [Declude.Virus] Encoded viruses...worried Colbeck, Andrew
- RE: [Declude.Virus] Encoded viruses...worried Colbeck, Andrew
- RE: [Declude.Virus] Encoded viruses...worried John T \(Lists\)