From clamav-win32-bounces@lists.clamav.net  Sat Sep 17 15:45:26 2005
Return-Path: <clamav-win32-bounces@lists.clamav.net>
X-Original-To: list@krisma.oltrelinux.com
Delivered-To: list@krisma.oltrelinux.com
Received: from [127.0.0.1] (krisma [127.0.0.1])
	by mail.oltrelinux.com (Postfix) with ESMTP id F13C811AE6A;
	Sat, 17 Sep 2005 15:45:24 +0200 (CEST)
X-Original-To: clamav-win32@krisma.oltrelinux.com
Delivered-To: clamav-win32@krisma.oltrelinux.com
Received: from mail.powerviewsystems.com (mail.powerviewsystems.com
	[204.9.75.76])
	(using SSLv3 with cipher DHE-RSA-AES256-SHA (256/256 bits))
	(No client certificate requested)
	by mail.oltrelinux.com (Postfix) with ESMTP id 40D6111AE4D
	for <clamav-win32@lists.clamav.net>;
	Sat, 17 Sep 2005 15:45:18 +0200 (CEST)
Received: from pvsys ([68.1.141.202])
	by mail.powerviewsystems.com (Merak 8.2.9) with ASMTP id UWK99910
	for <clamav-win32@lists.clamav.net>; Sat, 17 Sep 2005 09:45:10 -0400
From: "Rob McEwen" <rob@powerviewsystems.com>
To: <clamav-win32@lists.clamav.net>
Date: Sat, 17 Sep 2005 09:45:11 -0400
Organization: PowerView Systems
Message-ID: <005701c5bb8e$066ec500$0100a80a@pvsys>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.6626
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2670
Importance: Normal
X-PVSYS-QDFDW: Y
Subject: [clamav-win32] 
	common text in all (non-phish) virus, worms, exploits
X-BeenThere: clamav-win32@lists.clamav.net
X-Mailman-Version: 2.1.5
Precedence: list
Reply-To: clamav-win32@lists.clamav.net
List-Id: clamav-win32.lists.clamav.net
List-Unsubscribe: <http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-win32>,
	<mailto:clamav-win32-request@lists.clamav.net?subject=unsubscribe>
List-Archive: <http://lists.clamav.net/pipermail/clamav-win32>
List-Post: <mailto:clamav-win32@lists.clamav.net>
List-Help: <mailto:clamav-win32-request@lists.clamav.net?subject=help>
List-Subscribe: <http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-win32>,
	<mailto:clamav-win32-request@lists.clamav.net?subject=subscribe>
Sender: clamav-win32-bounces@lists.clamav.net
Errors-To: clamav-win32-bounces@lists.clamav.net
X-Virus-Scanned: by amavisd-new-20030616-p10 (Debian) at krisma.oltrelinux.com
X-Spam-Status: No, hits=0.0 tagged_above=-999.0 required=6.0 tests=BAYES_50
X-Spam-Level: 
Status: O
Content-Length: 665
Lines: 24

RE: common text in all (non-phish) virus, worms, exploits

QUESTION:

Would it be safe to say that the term "filename" and/or "iframe" is =
going to
always appear in plain text in ALL (non-phish) virus, worms, exploits?

This is certainly the case with several days' worth of "catches" from my
ClamAV runs. But I wonder if it is really always true?

Are there ever any exceptions to this rule? Or, can the word "filename"
and/or "iframe" ever hidden in Base64 encoded text?

Thanks!

Rob McEwen
PowerView Systems
Rob@PowerViewSystems.com
(478) 475-9032


_______________________________________________
http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-win32

