On Tue, 17 Feb 2004 19:03:23 +0100 (CET)
Jesper Juhl <[EMAIL PROTECTED]> wrote:

> On Tue, 17 Feb 2004, Jim Mercer wrote:
> 
> > On Tue, Feb 17, 2004 at 11:44:39AM -0500, David A. Lee wrote:
> > > For some reason beyond my understanding, ClamAV thinks this email
> > > contained the"FunLove" virus
> > >
> > > >>>> X-Virus: W32.FunLove.4099 FOUND
> > >
> > > Maybe simply the words "Fun Lov" in the text ?
> >
> > actually, it appears that the full text of:
> >
> > echo '_Fun Loving Criminal_' | sed 's/_/~/g'
> >
> > generates the hit.
> >
> If that's all it takes to generate a positive I'd say someone needs to
> update the signature to include more binary data...

Unfortunately we don't have any sample of this virus. By mistake I
repaired all files while testing my small utility - funclean a few years
ago :-(

Best regards,
Tomasz Kojm
-- 
      oo    .....       [EMAIL PROTECTED]         www.ClamAV.net
     (\/)\.........     http://www.clamav.net/gpg/tkojm.gpg
        \..........._   0DCA5A08407D5288279DB43454822DC8985A444B
          //\   /\      Tue Feb 17 22:25:08 CET 2004

Attachment: pgp00000.pgp
Description: PGP signature

Reply via email to