-----Mensaje original-----
De: Paget, Francois [mailto:Francois_Paget@NAI.com]
Enviado el: jueves, 17 de diciembre de 1998 15:15
Para: 'Daniel Villalba'
Asunto: RE: Virus nuevo - 2ª parte ===> Ithaqua.mp.8542 virus
-------------------------------------
Hi Daniel,
Please find attached an extra driver for our V4 engine. It is not possible to detect this virus with our V3.
This driver must be copied in the directory of our SCAN DOS engine.
Please use :
SCAN <file> /EXTRA EXTRA.DAT in order to detect this virus.
<<EXTRA.DAT>>
This new detection will be added ASAP in our next WEEKLYDAT available at
http:\\beta.nai.com. Please download the new DAT files next week.
This virus from 29A is a nasty virus. It is strange that this virus has
spread in your company because it is very bugged. On december 4th, I have
sent to you a mail in order to receive some other suspicious files. I have
received nothing. HAVE YOU RECEIVED MY MAIL ???? Have you only 2 infected
files KEYB and DEBUG ????
In order to verify our work, please send me some other infected files.
When it is possible to remove the virus, a remover is included (/CLEAN
option).
Many files are corrupted after infection, however it seems possible to
detect the files - these are infected with just 1 layer of encryption. Virus
frequently fails to pass the control from the host to the decryptor.
We envisage to detect the damaged files as ".dam" because some of them even
work OK (when virus just appends some rubbish at the eof) but never infect.
I wait for your response and I thank you for using the NAI products...
Regards,
Francois Paget
AVERT - McAfee Labs - PARIS
Network Associates
francois_paget@nai.com
|