North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

RE: interesting new virus, maybe???

  • From: Hank Nussbacher
  • Date: Sat Jan 10 11:54:38 2004

At 11:16 AM 09-01-04 -0800, [email protected] wrote:

Send it in to AVERT. It's free analysis and will give you
recommendations for how to deal with it:

https://www.webimmune.net/default.asp

...does require registration but again, it's free.

or email it in per instructions here:

http://vil.nai.com/vil/submit-sample.asp

other vendors may have similar mechanisms.
If you get a new virus here are some addresses:

Command Software             <[email protected]>
Computer Associates (US)     <[email protected]>
Computer Associates (Vet/EZ) <[email protected]>
DialogueScience (Dr. Web)    <[email protected]>
Eset (NOD32)                 <[email protected]>
F-Secure Corp.               <[email protected]>
Frisk Software (F-PROT)      <[email protected]>
Grisoft (AVG)                <[email protected]>
H+BEDV (AntiVir):            <[email protected]>
Kaspersky Labs               <[email protected]>
Network Associates (McAfee)  <[email protected]>
Norman (NVC)                 <[email protected]>
Sophos Plc.                  <[email protected]>
Symantec (Norton)            <[email protected]>
Trend Micro (PC-cillin)      <[email protected]>

-Hank



-----Original Message-----
From: [email protected] [mailto:[email protected]] On Behalf Of
Scott Granados
Sent: Friday, January 09, 2004 12:43 PM
To: [email protected]
Subject: interesting new virus, maybe???



I'm not sure if anyone has seen this or if its just to early but.

While opening mail, <not with a microsoft outlook product> I found
something which looked different.  The message was from pgp-public-key
and
said "Here is my key".  When you look at the attachment its called
youremail.doc.com obviously something meant to be executed.  What struck

me as  different from the top was it wasn't from a [email protected] or
some such address it specifically mentioned pgp_public_key.  Also, I
obviously didn't try to run the code or do anything with it, it is 76 K
in
size and again called youremail.doc.com.

I haven't tried a virus scanner against it yet but will later.

Thanks

Scott