It might be this, if my F-Prot is more up to date than yours, as mine has identified a few zip files with a plus sign in the name as W32/Brepibot.gen
http://www.f-secure.com/weblog/archives/archive-062006.html#00000902 The fake HELO names were CNN.com and TradersWorld.com if that's any use. Andrew 8) > -----Original Message----- > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On > Behalf Of Ncl Admin > Sent: Friday, June 16, 2006 2:03 PM > To: declude.virus@declude.com > Subject: Re: [Declude.Virus] new virus > > Yes, > > 04dotzip just came through here but McAfee stopped it. But > F-prot not getting it. > > At 04:30 PM 6/16/2006 -0400, you wrote: > >>>> > Is anyone else seeing new virus zip files getting past F-Prot? > the last one was just numbers.zip > Earlier a few came through with name.zip > > Bruce Loughlin > > --- > This E-mail came from the Declude.Virus mailing list. To > unsubscribe, just send an E-mail to [EMAIL PROTECTED], and > type "unsubscribe Declude.Virus". The archives can be found > at http://www.mail-archive.com. > <<<< > > > > > --- > This E-mail came from the Declude.Virus mailing list. To > unsubscribe, just send an E-mail to [EMAIL PROTECTED], and > type "unsubscribe Declude.Virus". The archives can be found > at http://www.mail-archive.com. > > --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.