It might be this, if my F-Prot is more up to date than yours, as mine
has identified a few zip files with a plus sign in the name as
W32/Brepibot.gen

http://www.f-secure.com/weblog/archives/archive-062006.html#00000902

The fake HELO names were CNN.com and TradersWorld.com if that's any use.

Andrew 8)

 

> -----Original Message-----
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On 
> Behalf Of Ncl Admin
> Sent: Friday, June 16, 2006 2:03 PM
> To: declude.virus@declude.com
> Subject: Re: [Declude.Virus] new virus
> 
> Yes,
> 
> 04dotzip just came through here but McAfee stopped it. But 
> F-prot not getting it.
> 
> At 04:30 PM 6/16/2006 -0400, you wrote: 
> >>>>
> Is anyone else seeing new virus zip files getting past F-Prot?
> the last one was just numbers.zip
> Earlier a few came through with name.zip
>   
> Bruce Loughlin
>   
> ---
> This E-mail came from the Declude.Virus mailing list. To 
> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and 
> type "unsubscribe Declude.Virus". The archives can be found 
> at http://www.mail-archive.com. 
> <<<<
> 
> 
> 
> 
> ---
> This E-mail came from the Declude.Virus mailing list.  To 
> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
> type "unsubscribe Declude.Virus".    The archives can be found
> at http://www.mail-archive.com.
> 
> 


---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to