RE: Possible New Virus?

2002-06-13 Thread Ken . Powell
: Possible New Virus? Yeh I looked at the small applianceand went round them bend with them on how they bundle itIt was pathetic the answers I got.. Boiled down to too much $$ for me and they where going to jam their hardware down my thought, and they wouldn't play nicedid sound cool...

RE: Possible New Virus?

2002-06-13 Thread Ken . Powell
) 397-6121 x4658 Fax: (360) 759-6001 -Original Message- From: Blunt, James H (Jim) [mailto:[EMAIL PROTECTED]] Sent: Thursday, June 13, 2002 8:21 AM To: Exchange 5.5 List Subject: RE: Possible New Virus? So far, we have stopped two instances of the Fretham.e variant of this virus. However

RE: Possible New Virus?

2002-06-13 Thread Mellott, Bill
I find it hit and miss.. had good... had bad... bill -Original Message- From: Hansen, Eric [mailto:[EMAIL PROTECTED]] Sent: Thursday, June 13, 2002 1:09 PM To: Exchange Discussions Subject: RE: Possible New Virus? Although their tech sup is terrifically stupid(imo) that webshield applian

RE: Possible New Virus?

2002-06-13 Thread Hansen, Eric
ymore we knew we were in trouble. -Original Message- From: Mellott, Bill [mailto:[EMAIL PROTECTED]] Sent: Thursday, June 13, 2002 10:58 AM To: Exchange Discussions Subject: RE: Possible New Virus? possible...But when I "talked with disgust.." a bit with NAI on the phone about W

RE: Possible New Virus?

2002-06-13 Thread Mellott, Bill
L PROTECTED] [mailto:[EMAIL PROTECTED]] Sent: Thursday, June 13, 2002 12:49 PM To: Exchange Discussions Subject: RE: Possible New Virus? I have believe that I have stopped FW:, FW:, FW: ,etc. before. I think that this is really the problem/danger with WS. It will work flawlessly on one installation

RE: Possible New Virus?

2002-06-13 Thread Ken . Powell
) Vancouver, Washington [EMAIL PROTECTED] Voice: (360) 397-6121 x4658 Fax: (360) 759-6001 -Original Message- From: Mellott, Bill [mailto:[EMAIL PROTECTED]] Sent: Wednesday, June 12, 2002 5:28 PM To: Exchange 5.5 List Subject: RE: Possible New Virus? Note do not assume the WS product will catch

RE: Possible New Virus?

2002-06-13 Thread Blunt, James H (Jim)
nd at http://securityresponse.symantec.com/avcenter/venc/data/pf/w32.frethem.e@mm. html Jim Blunt -Original Message- From: Mellott, Bill [mailto:[EMAIL PROTECTED]] Sent: Wednesday, June 12, 2002 5:29 PM To: Exchange Discussions Subject: RE: Possible New Virus? Note do not assume the WS product

RE: Possible New Virus?

2002-06-13 Thread John Steniger
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] > Sent: Wednesday, June 12, 2002 7:55 PM > To: Exchange Discussions > Subject: RE: Possible New Virus? > > > That may be true. > > Ken Powell > Systems Administrator > Clark County Office of Budget and Information Ser

RE: Possible New Virus?

2002-06-12 Thread Mellott, Bill
-) bill -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] Sent: Wednesday, June 12, 2002 7:22 PM To: Exchange Discussions Subject: RE: Possible New Virus? Webshield SMTP 4.51 MR1a with engine 4160. As far as DAT files, it has been catching it since as far back as the middle of la

RE: Possible New Virus?

2002-06-12 Thread Ken . Powell
, June 12, 2002 4:52 PM To: Exchange 5.5 List Subject: RE: Possible New Virus? But it couldn't be W32.Frethem.E@mm either, as that one was only discovered yesterday. I haven't seen nearly as many MIME Exploits as you have, but the ones I have seen can be identified as Klez by the distincti

RE: Possible New Virus?

2002-06-12 Thread Durkee, Peter
maybe they were Klezes that had their attachments removed by someone else's AV software, leaving the exploit still in place. -Peter -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] Sent: Wednesday, June 12, 2002 16:43 To: Exchange Discussions Subject: RE: Possible

RE: Possible New Virus?

2002-06-12 Thread Ken . Powell
-6001 -Original Message- From: Durkee, Peter [mailto:[EMAIL PROTECTED]] Sent: Wednesday, June 12, 2002 4:37 PM To: Exchange 5.5 List Subject: RE: Possible New Virus? I think any that you received before yesterday must've been from the klez virus, which uses the same exploit. I've

RE: Possible New Virus?

2002-06-12 Thread Durkee, Peter
iscussions Subject: RE: Possible New Virus? Webshield SMTP 4.51 MR1a with engine 4160. As far as DAT files, it has been catching it since as far back as the middle of last month (my ePO records do not go back any further.) Even if the engine and DAT files had not been up to date WS would have stopped

RE: Possible New Virus?

2002-06-12 Thread Ken . Powell
) 759-6001 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] Sent: Wednesday, June 12, 2002 8:55 AM To: Exchange 5.5 List Subject: RE: Possible New Virus? We have been seeing it for a couple of days. McAfee has been reporting it as Exploit-MIME.gen. I just got

RE: Possible New Virus?

2002-06-12 Thread Mellott, Bill
Original Message- From: Durkee, Peter [mailto:[EMAIL PROTECTED]] Sent: Wednesday, June 12, 2002 1:54 PM To: Exchange Discussions Subject: RE: Possible New Virus? No, I really meant which product. I have VirusScan on the desktops with the 4206 dats, and the NAI engine running under Ant

RE: Possible New Virus?

2002-06-12 Thread O'Conner, Jim
PROTECTED]] Sent: Wednesday, June 12, 2002 1:54 PM To: Exchange Discussions Subject: RE: Possible New Virus? No, I really meant which product. I have VirusScan on the desktops with the 4206 dats, and the NAI engine running under Antigen on the Exchange server, also with the 4206 dats, and neither of those

RE: Possible New Virus?

2002-06-12 Thread Durkee, Peter
o run it, nor did it run itself on those machines, so maybe VirusScan never had a chance to catch it. -Peter -Original Message- From: Mellott, Bill [mailto:[EMAIL PROTECTED]] Sent: Wednesday, June 12, 2002 10:42 To: Exchange Discussions Subject: RE: Possible New Virus? Your answer/que

RE: Possible New Virus?

2002-06-12 Thread Mellott, Bill
1:10 PM To: Exchange Discussions Subject: RE: Possible New Virus? Which McAfee product found it as Exploit-MIME? -Peter -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] Sent: Wednesday, June 12, 2002 8:54 To: Exchange Discussions Subject: RE: Possible New Virus? We

RE: Possible New Virus?

2002-06-12 Thread Durkee, Peter
Which McAfee product found it as Exploit-MIME? -Peter -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] Sent: Wednesday, June 12, 2002 8:54 To: Exchange Discussions Subject: RE: Possible New Virus? We have been seeing it for a couple of days. McAfee has been

RE: Possible New Virus?

2002-06-12 Thread Ken . Powell
Services (OBIS) Vancouver, Washington [EMAIL PROTECTED] Voice: (360) 397-6121 x4658 Fax: (360) 759-6001 -Original Message- From: John Steniger [mailto:[EMAIL PROTECTED]] Sent: Tuesday, June 11, 2002 10:23 AM To: Exchange 5.5 List Subject: RE: Possible New Virus? Appears to be a Frethem

RE: Possible New Virus?

2002-06-11 Thread John Steniger
Curses. Tack an "l" onto the end of that link and it oughta work. > -Original Message- > From: John Steniger [mailto:[EMAIL PROTECTED]] > Sent: Tuesday, June 11, 2002 1:24 PM > To: Exchange Discussions > Subject: RE: Possible New Virus? > > > A

RE: Possible New Virus?

2002-06-11 Thread Durkee, Peter
Yup, that's it, thanks. -Peter -Original Message- From: John Steniger [mailto:[EMAIL PROTECTED]] Sent: Tuesday, June 11, 2002 10:24 To: Exchange Discussions Subject: RE: Possible New Virus? Appears to be a Frethem Worm. From Norton: http:[EMAIL PROTECTED] l John J. Ste

RE: Possible New Virus?

2002-06-11 Thread John Steniger
> Sent: Tuesday, June 11, 2002 1:22 PM > To: Exchange Discussions > Subject: Possible New Virus? > > > Hi All, > I've seen several messages coming in this morning with the > subject line Re: Your Password!, an attachment named > decrypt-password.exe, and the same C

Possible New Virus?

2002-06-11 Thread Durkee, Peter
Hi All, I've seen several messages coming in this morning with the subject line Re: Your Password!, an attachment named decrypt-password.exe, and the same Content-Type: audio/x-midi that Klez uses to auto-run. The messages are 50k or so in size. Is anyone else seeing this? My usual virus info s