> > Also, I have temporarily blocked all zip files, as I am seeing quite a few > > that are not being caught by banned extension or F-Prot or AVG. I am > > investigating these. > > The ones I am seeing appear to be virus laden but would require the > user to unzip them and to take additional action to activate. > > The unzipped file name is "domain.com ... many spaces ... .scr" > Once I get it unzipped then FPROT and CLAMAV recognize it as a > MyDoom variant. McAffee did not trigger on it so not sure about it.
BUT, if they are as you state end in a scr extension, then they should be caught by BANEXT scr, but they were not. I have temporarily disabled banning of zip files to see if they will be caught as SCR under BANZIPEXT. John Tolmachoff Engineer/Consultant/Owner eServices For You --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.