The other day, I downloaded a mail archive (text file, almost 150000 lines).
When it was scanned by clamscan,
>cat suspicious_File | clamscan -
stdin: Worm.Bagle.AT FOUND
Worm.Bagle.AT shows up.
Web search says that Worm.Bagle comes as mail attachment.
So, I tried to identify where worm is.
Step 1. spilt into small files.
split -l 10000 suspicious_file
Step 2. which part worm resides.
----------- SCAN SUMMARY -----------
Known viruses: 820141
Engine version: 0.96.1
Scanned directories: 0
Scanned files: 15
Infected files: 0
Data scanned: 13.10 MB
Data read: 5.26 MB (ratio 2.49:1)
Time: 36.063 sec (0 m 36 s)
Then the worm is gone. ???
T thought that worm was cut by split command, so I used different size fraction, then result is same.
I am totally lost.
Can anybody please explain this situation?