Hi everyone,

Further to my earlier message, the virus in question is [EMAIL PROTECTED] This
is a new variant that was first detected yesterday by SARC. Here's the
writeup from SARC:

---

"W32.Netsky.C is a mass-mailing worm that uses its own SMTP engine to send
itself to the email addresses it finds when scanning hard drives and mapped
drives. This worm also searches drives C through Z for the folder names
containing "Shar" and then copies itself to those folders.
"The Subject, Body, and email attachment vary."

---

To this I can add that the pattern so far seems to be a very short message -
usually three words or less. The payload is contained in an attachment that
takes many names and has several different extensions.

Dave Doherty
Skywaves, Inc.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.JunkMail mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.JunkMail".  The archives can be found
at http://www.mail-archive.com.

Reply via email to