> -----Original Message-----
> From: Jesse Guardiani [mailto:[EMAIL PROTECTED]
> Sent: 19. september 2003 23:51
> To: [EMAIL PROTECTED]
> Subject: [Clamav-users] RE: UPDATE81.exe getting thru
> 
> Kevin Hanser wrote:
> 
> > Yes, I received a couple of these this morning, one with an
attachment
> > called Update53.exe, and another w/an attachment called
Install932.exe.
> >
> > I'm assuming this is the new "Swen" virus I have recently heard
about?
> 
> Yes, also Gibe-F apparently. But ClamAV's current virus def for
> Worm.Gibe.F
> seems to be faulty because it only catches about 50% of my Gibe-F
> viruses...
> 

There is nothing wrong with the current Worm.Gibe.F signature. There are
currently many e-mail samples that contain no binary attachment (0 byte)
- this might be due to some bug in the virus or a virus scanner that is
"stripping" the offending part in an infected e-mail passing through it.


Since the binary is completely missing it's difficult to create a
signature that will catch the "damaged" versions of Gibe.F.

Best regards,
Diego d'Ambra


-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Clamav-users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/clamav-users

Reply via email to