On Tue, 17 Feb 2004 19:03:23 +0100 (CET) Jesper Juhl <[EMAIL PROTECTED]> wrote:
> On Tue, 17 Feb 2004, Jim Mercer wrote: > > > On Tue, Feb 17, 2004 at 11:44:39AM -0500, David A. Lee wrote: > > > For some reason beyond my understanding, ClamAV thinks this email > > > contained the"FunLove" virus > > > > > > >>>> X-Virus: W32.FunLove.4099 FOUND > > > > > > Maybe simply the words "Fun Lov" in the text ? > > > > actually, it appears that the full text of: > > > > echo '_Fun Loving Criminal_' | sed 's/_/~/g' > > > > generates the hit. > > > If that's all it takes to generate a positive I'd say someone needs to > update the signature to include more binary data... Unfortunately we don't have any sample of this virus. By mistake I repaired all files while testing my small utility - funclean a few years ago :-( Best regards, Tomasz Kojm -- oo ..... [EMAIL PROTECTED] www.ClamAV.net (\/)\......... http://www.clamav.net/gpg/tkojm.gpg \..........._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Tue Feb 17 22:25:08 CET 2004
pgp00000.pgp
Description: PGP signature