Just writing the list to let Declude know that I've forwarded a suspicious file (report.zip). It was a zip file that contains a PIF file. Neither F-Prot on mail server nor NAV2k4 on client machine hit on this file. BANFILE EZIP is enabled within Declude.
Attached to this e-mail is a hex dump html page of the PIF file in question. Running Declude Standard so I'm unable to ban file names within ZIP files. Thanks..
I think this may be what McAfee is calling the Downloader-IU!zip trojan. Started noticing these come early this morning. Looks very similar.
-Russ
--- [This E-mail scanned for viruses by Declude Virus]
--- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
--- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.