<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: “Here you have” Virus (aka W32/VBMania@MM) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45300#M33290</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if you're not seeing anything, you're doing it wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;type w32 , change type to virus, hit find, and see an enormous list.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 10 Sep 2010 15:39:26 GMT</pubDate>
    <dc:creator>grant_sturgis</dc:creator>
    <dc:date>2010-09-10T15:39:26Z</dc:date>
    <item>
      <title>“Here you have” Virus (aka W32/VBMania@MM)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45294#M33284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;New virus, described here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.avertlabs.com/research/blog/index.php/2010/09/09/widespread-reporting-of-here-you-have-virus/"&gt;http://www.avertlabs.com/research/blog/index.php/2010/09/09/widespread-reporting-of-here-you-have-virus/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this virus recognized by the PAN devices?&amp;nbsp; I'm not sure how to look that up, or I would do so myself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If not, any thoughts on mitigating risk?&amp;nbsp; I don't see .scr files in file blocking.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Grant&lt;/P&gt;&lt;P&gt;--------------&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Sep 2010 15:14:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45294#M33284</guid>
      <dc:creator>grant_sturgis</dc:creator>
      <dc:date>2010-09-10T15:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: “Here you have” Virus (aka W32/VBMania@MM)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45295#M33285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Palo Alto Web site&amp;nbsp; &amp;gt;&amp;nbsp; Support&amp;nbsp; &amp;gt;&amp;nbsp; Threat Database&lt;BR /&gt;drop down and select Virus.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was just there looking for the same thing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Sep 2010 15:21:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45295#M33285</guid>
      <dc:creator>blacksan</dc:creator>
      <dc:date>2010-09-10T15:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: “Here you have” Virus (aka W32/VBMania@MM)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45296#M33286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, it looks to me like it's not recognized. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts on mitigation?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Sep 2010 15:29:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45296#M33286</guid>
      <dc:creator>grant_sturgis</dc:creator>
      <dc:date>2010-09-10T15:29:19Z</dc:date>
    </item>
    <item>
      <title>Re: “Here you have” Virus (aka W32/VBMania@MM)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45297#M33287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It might be listed under a different name. Trend Micro recognizes it as &lt;A href="http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MEYLME.B"&gt;WORM_MEYLME.B&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Sep 2010 15:31:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45297#M33287</guid>
      <dc:creator>kbaldwin</dc:creator>
      <dc:date>2010-09-10T15:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: “Here you have” Virus (aka W32/VBMania@MM)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45298#M33288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't see anything on any virus. You would think you could just select from the drop down and hit enter and it would pull up a list, but I get nothing, even when I put something in there still nothing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Sep 2010 15:32:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45298#M33288</guid>
      <dc:creator>twilson</dc:creator>
      <dc:date>2010-09-10T15:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: “Here you have” Virus (aka W32/VBMania@MM)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45299#M33289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;unfortunately, no.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Sep 2010 15:38:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45299#M33289</guid>
      <dc:creator>grant_sturgis</dc:creator>
      <dc:date>2010-09-10T15:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: “Here you have” Virus (aka W32/VBMania@MM)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45300#M33290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if you're not seeing anything, you're doing it wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;type w32 , change type to virus, hit find, and see an enormous list.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Sep 2010 15:39:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45300#M33290</guid>
      <dc:creator>grant_sturgis</dc:creator>
      <dc:date>2010-09-10T15:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: “Here you have” Virus (aka W32/VBMania@MM)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45301#M33291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This was slated to be included in last night's emergency Threat/AV content release for PAN OS 3.1.x. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PAN OS 3.0.x will be addressed with next Tuesday's content release.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Sep 2010 15:48:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45301#M33291</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2010-09-10T15:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: “Here you have” Virus (aka W32/VBMania@MM)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45302#M33292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I still dont see this added into the threat database...is it known by a different name in Palo Alto land?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Sep 2010 08:24:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45302#M33292</guid>
      <dc:creator>KatanaNZ</dc:creator>
      <dc:date>2010-09-14T08:24:49Z</dc:date>
    </item>
    <item>
      <title>Re: “Here you have” Virus (aka W32/VBMania@MM)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45303#M33293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Coverage for "Here you have" virus is as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;STRONG&gt;3.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="p1"&gt;Virus Name: Trojan/Win32.swisyn.bofj&lt;/P&gt;&lt;P class="p1"&gt;Content release: 271 (daily content release)&lt;/P&gt;&lt;P class="p1"&gt;Release date: 5th August&lt;/P&gt;&lt;P class="p1"&gt;&lt;STRONG style="font-weight: normal; "&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="p1"&gt;Virus Name: Trojan/W32.swisyn.bxoh&lt;/P&gt;&lt;P class="p1"&gt;Content Release: 299-364 (Daily A/V content update)&lt;/P&gt;&lt;P class="p1"&gt;Release Date: 10th Sep&lt;/P&gt;&lt;P class="p2"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;STRONG&gt;3.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="p1"&gt;Virus Name: Trojan/Win32.swisyn.0804&lt;/P&gt;&lt;P class="p1"&gt;Content release: 203 (weekly content release)&lt;/P&gt;&lt;P class="p1"&gt;Release date: 25th August&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;Thanks,&lt;/P&gt;&lt;P class="p1"&gt;Sandeep&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Sep 2010 08:44:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45303#M33293</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2010-09-14T08:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: “Here you have” Virus (aka W32/VBMania@MM)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45304#M33294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What about the ability to block .scr files. It seems odd to me that there is a way to custmize nearly everything but not a way to add a file extention to the picklist???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is .scr going to be included in some future release? Or the ability for the end user to add his own file extensions for blocking?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Sep 2010 20:04:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45304#M33294</guid>
      <dc:creator>CWillms</dc:creator>
      <dc:date>2010-09-14T20:04:32Z</dc:date>
    </item>
    <item>
      <title>Re: “Here you have” Virus (aka W32/VBMania@MM)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45305#M33295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;.scr files are included in the category "Portable Executables" (aka PE).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on my firewall i created a file block rule for the PE filetype in both directions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: bpappas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Sep 2010 20:07:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45305#M33295</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2010-09-14T20:07:04Z</dc:date>
    </item>
    <item>
      <title>Re: “Here you have” Virus (aka W32/VBMania@MM)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45306#M33296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Apparently the PA support guy I talked to yesterday did not know this... Is this knowledge in a document somewhere?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Sep 2010 20:13:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45306#M33296</guid>
      <dc:creator>CWillms</dc:creator>
      <dc:date>2010-09-14T20:13:13Z</dc:date>
    </item>
    <item>
      <title>Re: “Here you have” Virus (aka W32/VBMania@MM)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45307#M33297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How do we search for this? looking for VBmania, or "here you have" comes up with no results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As much as vendors have their own names for malware, its pointless when we can't search for&lt;/P&gt;&lt;P&gt;it so we can let our customer know they're protected.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Sep 2010 20:43:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/here-you-have-virus-aka-w32-vbmania-mm/m-p/45307#M33297</guid>
      <dc:creator>KatanaNZ</dc:creator>
      <dc:date>2010-09-14T20:43:00Z</dc:date>
    </item>
  </channel>
</rss>

