Hi! About a month ago, i submitted a virus sample since it was detected by most of malware scanners but clamav. The submitted file was DCIM.exe, md5: bf4b5b28fd0e463702fef45fe45b31c6 and my submitter's email was [EMAIL PROTECTED]
Upon now, things are the same. Just for reference, scan results from http://virusscan.jotti.org/: Scanner results AntiVir Found Worm/Genun.A.62 ArcaVir Found Worm.Generic Avast Found Win32:XGTray AVG Antivirus Found I-Worm/VB.LF BitDefender Found Win32.Worm.VB.CC ClamAV Found nothing Dr.Web Found Win32.HLLM.Utenti F-Prot Antivirus Found W32/VB.KP Fortinet Found W32/[EMAIL PROTECTED] Kaspersky Anti-Virus Found Email-Worm.Win32.VB.bj NOD32 Found Win32/VB.NAC Norman Virus Control Found W32/[EMAIL PROTECTED] VirusBuster Found I-Worm.VB.BGD VBA32 Found Email-Worm.Win32.generic Today, i scanned my sample with clamscan --debug and found following in it's output: LibClamAV debug: Recognized DOS/W32 executable/library/driver file LibClamAV debug: in cli_peheader LibClamAV debug: Virus offset: 12850, expected: 13178 (Worm.Traxg) LibClamAV debug: Type: 502, expected: 511 (W97M.Lafool-4) LibClamAV debug: Calculated MD5 checksum: bf4b5b28fd0e463702fef45fe45b31c6 Still, clamav considered this file clean. -- Regards, Al Nikolov jid: [EMAIL PROTECTED] irc: clown uin: 312108671 pgp fingerprint: 4B50 F1E3 080C 21A2 91F4 8BF0 CD60 3B5A 2ECF 984B _______________________________________________ http://lurker.clamav.net/list/clamav-users.html