Re: [SAtalk] W32.Novarg.A@mm virus

2004-01-28 Thread Keith C. Ivey
Brook Humphrey <[EMAIL PROTECTED]> wrote: > On Tuesday 27 January 2004 10:20 am, Yackley, Matt wrote: > > Have you tried any of the Virus bounce rules?  These help stop > > the floods of stupid "You sent a virus" warnings from people > > that have not learned to shutdown auto-notifications > >

RE: [SAtalk] W32.Novarg.A@mm virus

2004-01-27 Thread Jerry Gaiser
On Tue, 2004-01-27 at 08:35, Smart,Dan wrote: > We are using the script by Nikos Kantarakias called "yet another virus > recipe" for Procmail. See http://agriroot.aua.gr/~nikant/nkvir/ > > Nikos added Novarg this morning. Wow.. Thanks for pointing this out. Quick to install, with one minor chan

Re: [SAtalk] W32.Novarg.A@mm virus

2004-01-27 Thread Brook Humphrey
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Tuesday 27 January 2004 02:41 am, Richard Beyer wrote: > We're seeing a lot of activity from the [EMAIL PROTECTED] virus > (http://securityresponse.symantec.com/avcenter/venc/data/[EMAIL PROTECTED] >m l) > > > > Could someone help me cobble together

Re: [SAtalk] W32.Novarg.A@mm virus

2004-01-27 Thread Brook Humphrey
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Tuesday 27 January 2004 10:20 am, Yackley, Matt wrote: > Have you tried any of the Virus bounce rules?  These help stop the floods > of stupid "You sent a virus" warnings from people that have not learned to > shutdown auto-notifications > http:

RE: [SAtalk] W32.Novarg.A@mm virus

2004-01-27 Thread Smart,Dan
We are using the script by Nikos Kantarakias called "yet another virus recipe" for Procmail. See http://agriroot.aua.gr/~nikant/nkvir/ Nikos added Novarg this morning. <> | -Original Message- | From: Jon [mailto:[EMAIL PROTECTED] | Sent: Tuesday, January 27, 2004 5:08 AM | To: Ric

RE: [SAtalk] W32.Novarg.A@mm virus

2004-01-27 Thread Yackley, Matt
> -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On > Behalf Of Brook Humphrey > Sent: Tuesday, January 27, 2004 11:15 AM > To: [EMAIL PROTECTED] > Subject: Re: [SAtalk] [EMAIL PROTECTED] virus > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > On Tuesd

Re: [SAtalk] W32.Novarg.A@mm virus

2004-01-27 Thread Brook Humphrey
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Tuesday 27 January 2004 06:38 am, Yackley, Matt wrote: > Could someone help me cobble together a rule quickly to > counteract the attachments it's using.  Something to catch test.zip, > readme.zip and body.zip (the most common ones it appear

RE: [SAtalk] W32.Novarg.A@mm virus

2004-01-27 Thread Yackley, Matt
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Richard Beyer Sent: Tuesday, January 27, 2004 4:41 AM To: [EMAIL PROTECTED] Subject: [SAtalk] [EMAIL PROTECTED] virus We're seeing a lot of

Re: [SAtalk] W32.Novarg.A@mm virus

2004-01-27 Thread Christopher X. Candreva
On Tue, 27 Jan 2004, Richard Beyer wrote: > Could someone help me cobble together a rule quickly to counteract the > attachments it's using. Something to catch test.zip, readme.zip and > body.zip (the most common ones it appears to be using at the moment). I suggest simply installing clamav and

Re: [SAtalk] W32.Novarg.A@mm virus

2004-01-27 Thread Jon
On Tue, 2004-01-27 at 02:41, Richard Beyer wrote: > Something to catch test.zip, readme.zip and body.zip (the most common > ones it appears to be using at the moment). > Symantec has a lot of information on the attachments it uses, although the message body might be easier to write accurate rules