> -----Original Message----- > From: Jesse Guardiani [mailto:[EMAIL PROTECTED] > Sent: 19. september 2003 23:51 > To: [EMAIL PROTECTED] > Subject: [Clamav-users] RE: UPDATE81.exe getting thru > > Kevin Hanser wrote: > > > Yes, I received a couple of these this morning, one with an attachment > > called Update53.exe, and another w/an attachment called Install932.exe. > > > > I'm assuming this is the new "Swen" virus I have recently heard about? > > Yes, also Gibe-F apparently. But ClamAV's current virus def for > Worm.Gibe.F > seems to be faulty because it only catches about 50% of my Gibe-F > viruses... >
There is nothing wrong with the current Worm.Gibe.F signature. There are currently many e-mail samples that contain no binary attachment (0 byte) - this might be due to some bug in the virus or a virus scanner that is "stripping" the offending part in an infected e-mail passing through it. Since the binary is completely missing it's difficult to create a signature that will catch the "damaged" versions of Gibe.F. Best regards, Diego d'Ambra ------------------------------------------------------- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf _______________________________________________ Clamav-users mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/clamav-users