On Mon, 16 Dec 2002, Mark_Saunders wrote:

> It would probably be wise to add the "ceo" extension to the poisoned
> list.
> http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_WINEVAR.A&VSect=T

I don't think that's necessary. The .CEO extension is only executable
if the active HTML in the message is able to create a registry mapping
for that extension, and I expect the HTML defanger will disable that
part of the attack.

Also, if the worm writer had his head screwed on straight, he would
have written the worm to randomly generate the extension on every
attack message, which would put us in the position of mangling *all*

