> You haven't provided enough information to determine whether you are just
> as confused as everyone else, or whether you know what you are doing and
> have determined something very useful to know.

Confused yes, scared yes, pissed off at this whole situation YES.

Good -- I was worried I was the only one. :)


What I have determined is that Trend is actively blocking these encrypted zip
files.  And by checking the logs, I see that none are getting through right
now.

Have you actually confirmed that Trend blocked a "Bagle.J" that was in an encrypted .ZIP file? What evidence do you have? It is extremely unlikely that it did.


> Specifically, YOUR (and everyone else's) mailserver AV program will detect
> "static" viruses in encrypted .ZIP files.

This may be what is happening. I don't know how they are doing it.

That isn't the case with Bagle.J -- Bagle.J is dynamic, changing its name/size/CRC. All that Trend can do is either [1] run a password cracker (highly unlikely) or [2] block all encrypted files within .ZIP files that are between 11,000 and 12,000 bytes in length (lots of false positives).


> all detect viruses such as Bagle.J that appear in both non-encrypted files
> and in encrypted files, but will *only* detect them in the non-encrypted
files.

Are you saying the zip files have more than one file in them, and that one
is encrypted and the other is not and that is how Trend is catching it?

No. Trend is not catching the encrypted ones.


For example, someone who is infected with Bagle.J may send you 2 copies: one in "blah.pif", the other in an encrypted "blah.exe" file in "blah.zip". Trend (and everyone else) can detect the blah.pif file. Nobody can detect the blah.exe in the blah.zip file.

We have received a number of these and I have a password protected zip file
infected with the bagle.J virus.  The readme zip and the textfile zip.

That isn't Bagle.J -- Bagle.J, when in an encrypted .ZIP file, uses a random filename ("FKGIRLEL.exe", for example).


I don't bite, weah!

pass: 67158

This looks like Bagle.F(?) that was in static encrypted .ZIP files, and therefore could be caught.


-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask for a free 30-day evaluation.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to