On Tue, 2008-12-02 at 10:10 +0100, Tomasz Kojm wrote:
> On Tue, 02 Dec 2008 00:59:01 +0100
> Karsten Bräckelmann <[EMAIL PROTECTED]> wrote:
FWIW, detected as Trojan.Invo-13 and Trojan.Downloader-60790.
Which (again) raises the question why that variation, for what appears
to be a single malware.
> > Should I submit the entire, original email, or the attachment only?
>
> The entire email is usually most useful to us.
Thanks, Tomasz. I kind of went paranoid, given the scary report
recently referred in my OP.
--
char *t="[EMAIL PROTECTED]";
main(){ char h,m=h=*t++,*x=t+2*h,c,i,l=*x,s=0; for (i=0;i<l;i++){ i%8? c<<=1:
(c=*++x); c&128 && (s+=h); if (!(h>>=1)||!t[s+h]){ putchar(t[s]);h=m;s=0; }}}
_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml