On Tue, Apr 20, 2004 at 11:36:56AM -0600, Lucas Albers said:
> I am detecting a new netsky variant that is detected by mcafee as a netsky
> variant but is not yet detected by name yet.
> 
> It is NOT detected by:
> clamav, or f-prot.
> 
> I am receiving upwards of 10-20 an hour so far.
> 
> I have submitted it to the f-prot/mcafee/clamav online virus submittal
> page for inclusion.
> You can see a copy of it here:
> http://www.cs.montana.edu/support/ENTIRE_MESSAGE.netsky-variant.04-20-04.zip.password-infected.zip

[EMAIL PROTECTED]:~$ clamscan --mbox 
ENTIRE_MESSAGE.netsky-variant.04-20-04.zip.password-infected.zip --block-encrypted
ENTIRE_MESSAGE.netsky-variant.04-20-04.zip.password-infected.zip: Encrypted.Zip FOUND

----------- SCAN SUMMARY -----------
Known viruses: 21159
Scanned directories: 0
Scanned files: 1
Infected files: 1
Data scanned: 0.00 MB
I/O buffer size: 131072 bytes
Time: 0.617 sec (0 m 0 s)

It looks like this is covered by the pseudo signature already.
-- 
 --------------------------------------------------------------------------
|  Stephen Gran                  | Laugh and the world thinks you're an    |
|  [EMAIL PROTECTED]             | idiot.                                  |
|  http://www.lobefin.net/~steve |                                         |
 --------------------------------------------------------------------------

Attachment: pgp00000.pgp
Description: PGP signature

Reply via email to