Gee, I if I had provided a little more info my post might have made more
sense huh? I was reading on the Mcafee site about the W32/Sircam worm
and they said that it sends itself "using one of the following
extensions: .BAT, .COM, .EXE, .LNK, .PIF. This results in attachment
names having double-extensions." Sooo, I was suggesting... you may
want to add the .lnk extension to your system filters, and I was asking
if anyone else had a better idea?
Thanks,
-jm
mcafee link :
http://hq.mcafeeasap.com/dispVirus.asp?virus_k=99141