On Tue, Apr 20, 2004 at 11:36:56AM -0600, Lucas Albers said: > I am detecting a new netsky variant that is detected by mcafee as a netsky > variant but is not yet detected by name yet. > > It is NOT detected by: > clamav, or f-prot. > > I am receiving upwards of 10-20 an hour so far. > > I have submitted it to the f-prot/mcafee/clamav online virus submittal > page for inclusion. > You can see a copy of it here: > http://www.cs.montana.edu/support/ENTIRE_MESSAGE.netsky-variant.04-20-04.zip.password-infected.zip
[EMAIL PROTECTED]:~$ clamscan --mbox ENTIRE_MESSAGE.netsky-variant.04-20-04.zip.password-infected.zip --block-encrypted ENTIRE_MESSAGE.netsky-variant.04-20-04.zip.password-infected.zip: Encrypted.Zip FOUND ----------- SCAN SUMMARY ----------- Known viruses: 21159 Scanned directories: 0 Scanned files: 1 Infected files: 1 Data scanned: 0.00 MB I/O buffer size: 131072 bytes Time: 0.617 sec (0 m 0 s) It looks like this is covered by the pseudo signature already. -- -------------------------------------------------------------------------- | Stephen Gran | Laugh and the world thinks you're an | | [EMAIL PROTECTED] | idiot. | | http://www.lobefin.net/~steve | | --------------------------------------------------------------------------
pgp00000.pgp
Description: PGP signature