Hi!

About a month ago, i submitted a virus sample since it was detected by most
of malware scanners but clamav. The submitted file was DCIM.exe, md5:
bf4b5b28fd0e463702fef45fe45b31c6 and my submitter's email was
[EMAIL PROTECTED]

Upon now, things are the same. Just for reference, scan results from
http://virusscan.jotti.org/:

Scanner results 
   AntiVir   Found Worm/Genun.A.62
   ArcaVir   Found Worm.Generic
   Avast   Found Win32:XGTray
   AVG Antivirus   Found I-Worm/VB.LF
   BitDefender   Found Win32.Worm.VB.CC
   ClamAV   Found nothing
   Dr.Web   Found Win32.HLLM.Utenti
   F-Prot Antivirus   Found W32/VB.KP
   Fortinet   Found W32/[EMAIL PROTECTED]
   Kaspersky Anti-Virus   Found Email-Worm.Win32.VB.bj
   NOD32   Found Win32/VB.NAC
   Norman Virus Control   Found W32/[EMAIL PROTECTED]
   VirusBuster   Found I-Worm.VB.BGD
   VBA32   Found Email-Worm.Win32.generic

Today, i scanned my sample with clamscan --debug and found following in it's
output:

LibClamAV debug: Recognized DOS/W32 executable/library/driver file
LibClamAV debug: in cli_peheader
LibClamAV debug: Virus offset: 12850, expected: 13178 (Worm.Traxg)
LibClamAV debug: Type: 502, expected: 511 (W97M.Lafool-4)
LibClamAV debug: Calculated MD5 checksum: bf4b5b28fd0e463702fef45fe45b31c6

Still, clamav considered this file clean.

-- 
Regards,
Al Nikolov       jid: [EMAIL PROTECTED] irc: clown uin: 312108671
pgp fingerprint: 4B50 F1E3 080C 21A2 91F4  8BF0 CD60 3B5A 2ECF 984B

_______________________________________________
http://lurker.clamav.net/list/clamav-users.html

Reply via email to