| Blackmal virus | 
| Post Reply   | 
| Author | |
| Clutcher   Guest Group   |  Post Options  Thanks(0)  Quote  Reply  Topic: Blackmal virus Posted: 19 January 2006 at 4:08am | 
| Did the new Blackmal (Small.KI) hit you? How could SF help to keep it out? I filter executables but there ones seem to be into a MIME attachment SF does not consider http://www.norman.com/Virus/Virus_descriptions/28031/it?show =default | |
|  | |
| Desperado   Senior Member     Joined: 27 January 2005 Location: United States Status: Offline Points: 1143 |  Post Options  Thanks(0)  Quote  Reply  Posted: 19 January 2006 at 8:44am | 
| Clutcher, Exactly what are you asking? Parsing 2 days of my SpamFilter Logs show that SpamFilter DID block the virus.  Virus Messages  Bytes  NOTE:  Sorry about the formatting ... the tables did not translate correctly.  das Edited by Desperado | |
| 
     The Desperado
 Dan Seligmann. Work: http://www.mags.net Personal: http://www.desperado.com | |
|  | |
| LogSat   Admin Group     Joined: 25 January 2005 Location: United States Status: Offline Points: 4106 |  Post Options  Thanks(0)  Quote  Reply  Posted: 19 January 2006 at 10:36pm | 
| 
   Clutcher, Are you using the anti-virus plugin? If not, please note that the attachment filter in SpamFilter can be fooled by some viruses. SpamFilter by itself can help to block a large number of viruses using its filters, but some will always slip thru. That is why antivirus software is really needed to ensure better protection. | |
|  | |
| Clutcher   Guest Group   |  Post Options  Thanks(0)  Quote  Reply  Posted: 20 January 2006 at 3:02am | 
| Yes, I'm using antivirus plugin that on 18th started detecting Text/Small.KI but on 17th several .hqx attachments passed Norman and SF Inside those encoded attachment there where .scr or .pif executables. (Just for the record, NAV on Domino started blocking them form the very start) I'm really thinking about asking for and implementing a white list for attachments. | |
|  | |
| LogSat   Admin Group     Joined: 25 January 2005 Location: United States Status: Offline Points: 4106 |  Post Options  Thanks(0)  Quote  Reply  Posted: 20 January 2006 at 4:10pm | 
| 
   Unfortunately if there is no pattern yet for a virus the plugin won't be able to stop it. Sometimes one company releases signatures before others, and sometimes it's the others who release them first. There will never be a winner...
    | |
|  | |
| Post Reply   | |
| Tweet | 
| Forum Jump | Forum Permissions  You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum | 
This page was generated in 0.078 seconds.
 
  
 
 
  
  
  
  Topic Options
 Topic Options