So its a specially coded HTML page that can cause an attached virus to be run without user notification in un-patched versions of Outlook and Outlook Express. Klez and other similar viruses use the technique to help spread themselves.
----- Original Message ----- From: "Dave" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Sunday, July 14, 2002 7:21 PM Subject: Re: [JDEV] Per SSL 2.0, SSL 3.0, TLS 1.0, PCT 1.0. > What's Exploit.IFrame.FileDownload, some new breed of viruses for IE? > > - Dave > > > Richard Dobson wrote: > > > > It was a virus, my email server's virus scanner filtered it out, here my > > servers report: > > > > The following message had attachment(s) which contained the viruses: > > > > >From : [EMAIL PROTECTED] > > To : [EMAIL PROTECTED] > > Subject : [JDEV] Per SSL 2.0, SSL 3.0, TLS 1.0, PCT 1.0. > > Date : Wed, 3 Jul 2002 07:58:52 -0500 > > Message-ID: <[EMAIL PROTECTED]> > > > > Attachment Virus name Action taken > > -------------------------------------------------------------------------- -- > > -- > > cf2852313729.att Exploit.IFrame.FileDownloadRemoved > > Imk.pif I-Worm.Klez.h Removed > > > > ----- Original Message ----- > > From: "Dave" <[EMAIL PROTECTED]> > > To: <[EMAIL PROTECTED]> > > Sent: Wednesday, July 10, 2002 5:58 PM > > Subject: Re: [JDEV] Per SSL 2.0, SSL 3.0, TLS 1.0, PCT 1.0. > > > > > > > SPAM? > > > _______________________________________________ > > > jdev mailing list > > > [EMAIL PROTECTED] > > > http://mailman.jabber.org/listinfo/jdev > > > > > > > > > _______________________________________________ > > jdev mailing list > > [EMAIL PROTECTED] > > http://mailman.jabber.org/listinfo/jdev > > > > _______________________________________________ > jdev mailing list > [EMAIL PROTECTED] > http://mailman.jabber.org/listinfo/jdev > _______________________________________________ jdev mailing list [EMAIL PROTECTED] http://mailman.jabber.org/listinfo/jdev
