One more reason to have a banned extension policy in place. Thanks for the heads up Scott.
John Tolmachoff IT Manager, Network Engineer RelianceSoft, Inc. Fullerton, CA 92835 www.reliancesoft.com -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] On Behalf Of R. Scott Perry Sent: Wednesday, June 12, 2002 5:52 AM To: [EMAIL PROTECTED] Subject: [Declude.Virus] W32/Frethem-Fam FYI, there is a new virus out, that Sophos has alerted us to, called W32/Fretham-Fam (no other AV companies that was get alerts from, including McAfee, have sent out alerts yet). This may be become widespread because of the "social engineering" aspect of it -- it pretends to have a Special Password attached, which it does -- but it supposedly needs to be decrypted with the attach file. The .EXE may run automatically in Outlook when the E-mail is viewed (not sure which OE vulnerability it uses). There are several variants of it already. More details can be found at http://www.sophos.com/virusinfo/analyses/w32frethemfam.html . The attached files are decrypt-password.exe and password.txt, and it has a subject of "Re: Your password!". -Scott --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com . --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com .