McAfee could detect the bagle.f because I guess it had static
parameters.

Correct. All copies of Bagle.F have the same CRC, so AV programs can detect it with very high accuracy.


I assume Bagle.j is somewhat dynamic, so although McAfee say they can
detect is, mine hasn't, because it can only detect it once decrypted.

There are two versions of Bagle.J: "Bagle.J.encrypted" (ones that appear in encrypted .ZIP files) and "Bagle.J.unencrypted" (ones that appear elsewhere). All AV programs will detect "Bagle.J.unencrypted", but none so far appear to catch "Bagle.J.encrypted" (nor is it expected that they will, without also catching legitimate E-mail).


The page you refer to below states that only McAfee gateway products can
detect the encrypted zip (for variant w32/bagle.k). People using declude
will only be running the command line scanner, not the gateway product -
That's correct isn't it Scott?

If any AV program can detect "Bagle.J.encrypted", it will get caught with Declude Virus. However, it is not expected that any can or will, so we still recommend that everyone block encrypted .ZIP files.


-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask for a free 30-day evaluation.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to