Welcome Guest!
 Grapevine
 Previous Message All Messages Next Message 
Re: malware email - Sobig  jsampson+indexes
 Oct 23, 2003 12:43 PDT 

Hello -

I do run Zone Alarm, so thanks for the suggestion. In that case filtering
on '.zlo' wouldn't work!

Regards

_John Sampson_

At 12:25 23/10/03 +0100, you wrote:
 That sounds as though Zone Alarm has 'quarantined' the attachment by
changing its file extension. I recently had an .msi file that ZA
renamed to .zlk. Try Zone Alarm help for how to change it back again,
assuming that you want to - which you almost certainly don't!

Phil

jsampson+indexes <jsam-@indexes.u-net.com> wrote:
 Hello -

The ones coming here have all had '.zlo' file endings. I
don't know what legitimate application uses/produces files
with that ending. If I had a filter that zapped email with
'.zlo' attachments I would have my answer.

But in any case, when would a legitimate 'bounce'
notification have an attachment?

Regards

_John Sampson_


 The name of the attachment will vary: your_document.pif,
document_all.pif, thank_you.pif, etc. There is a common
theme, though -- Sobig-F's infections all arrive as ".pif"
or ".scr" files.

-----
	
 Previous Message All Messages Next Message 
  Check It Out!

  Topica Channels
 Best of Topica
 Art & Design
 Books, Movies & TV
 Developers
 Food & Drink
 Health & Fitness
 Internet
 Music
 News & Information
 Personal Finance
 Personal Technology
 Small Business
 Software
 Sports
 Travel & Leisure
 Women & Family

  Start Your Own List!
Email lists are great for debating issues or publishing your views.
Start a List Today!

© 2001 Topica Inc. TFMB
Concerned about privacy? Topica is TrustE certified.
See our Privacy Policy.