> Is it detecting them in an encrypted file? It may be that the virus is spreading in non-encrypted .ZIP
> files as well.
An email from <[EMAIL PROTECTED]>, addressed to <[EMAIL PROTECTED]> , with subject E-mail account disabling warning. was infected with the virus W32/[EMAIL PROTECTED] in attachment unknown. The infected attachment has been cleaned and quarantined.(from MAILRELAY IP 192.87.68.214 user SYSTEM running WebShield 4.5 MR1a '_')
Unfortunately, they aren't giving you enough information. There isn't any indication that this is one from an encrypted .ZIP file. So I would assume this is a standard Bagle.J in a non-encrypted file (such as a .PIF file).
-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask for a free 30-day evaluation.
--- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
--- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.