On Fri, 2004-07-30 at 10:17, Giorgio Bellussi wrote: > Good day all. > Online scanner http://www.gietl.com/test-clamav/ doesn't recognize > mabutu.a (same way as clamav-0.75) > The same file results infected at > http://www.kaspersky.com/scanforvirus (*I-Worm.Mabutu.a)* > and > h > <http://www.ravantivirus.com/scan/indexn.php>ttp://www.ravantivirus.com/scan/indexn.php. > > <http://www.ravantivirus.com/scan/indexn.php>(Win32/HLLW.Mabutu.B). > > clamav-devel-20040728 recognizes it as Worm.Mabutu.A-upx.
clamav-devel-20040728 contains a UPX unpacker, clamav-0.75 does not. Hence, it is able to unpack the file and finds the worm. -trog
signature.asc
Description: This is a digitally signed message part