shing spam.
Original Message
From: "Colbeck, Andrew" <[EMAIL PROTECTED]>
Sent: Thursday, April 26, 2007 6:11 PM
To: declude.virus@declude.com
Subject: RE: [Declude.Virus] new virus with .rar attachment
Gary, you beat them by a day with your own assessment, but Symante
Basically that is what ClamAV is doing. It detects it as a phishing spam.
Original Message
> From: "Colbeck, Andrew" <[EMAIL PROTECTED]>
> Sent: Thursday, April 26, 2007 6:11 PM
> To: declude.virus@declude.com
> Subject: RE: [Declude.Virus] ne
the message as spam.
Andrew.
> -Original Message-
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On
> Behalf Of Gary Steiner
> Sent: Wednesday, April 25, 2007 10:31 AM
> To: declude.virus@declude.com
> Subject: [Declude.Virus] new virus with .rar attachment
>
ClamAV is now picking this up as Email.Phishing.RB-686
Original Message
> From: "Gary Steiner" <[EMAIL PROTECTED]>
> Sent: Wednesday, April 25, 2007 1:48 PM
> To: declude.virus@declude.com
> Subject: [Declude.Virus] new virus with .rar attachment
I started getting some messages today that were picked up as spam, but were not
being identified as viruses. They looked suspicious, having subject lines of
Virus Activity Detected!
Spyware Alert!
It containes a .gif message that tells the user to open the .rar file and run
the patch there to