Mailing List Archive

Update
ClamAV, database updated (17:03 on 19/9/2003 GMT): viruses.db2

SSubmission: 383
Sender: Farit
Virus: BAT.Nonstop.b
Alias: Trojan.BAT.Nonstop.b - Kaspersky
Added: Yes

Submission: 384
Sender: Farit
Virus: Win32.Rores.A
Alias: VirTool.Win32.Rores - Kaspersky
Added: Yes

Submission: 385
Sender: Farit
Virus: Win32.KME
Alias: PE_ZMORPH.AX - Trend Micro
Added: Yes

Submission: 386, 387, 388, 390, 391, 392, 393, 394, 396,
397, 398, 399, 400, 401, 402, 403, 404, 405,
406, 507, 508
Sender: Different senders
Virus: Worm.Gibe.F
Added: No, already detected

Submission: 389
Sender: Jonathan Vincze
Virus: Trojan.DSNX
Alias: Backdoor.DSNX - NOD32, Backdoor.DSNX.04 - Kaspersky
Added: Yes

Submission: 395
Sender: Andrei Gasheyev
Virus: Worm.Mapson.D
Alias: W32.Mapson.D.Worm - Norton, I-Worm.Mapson.d - Kaspersky
Added: Yes

Submission: 0, 1
Sender: Different senders
Virus: Worm.Gibe.F
Added: No, already detected

Note on Worm.Gibe.F: Since Gibe.F in some cases tries to use the IFRAME
exploit ClamAV might detect the Exploit.Iframe.gen signature before the
Worm.Gibe.F if the virus is "hidden" within an e-mail. The same is the
case with other viruses that tries to use this exploit - i.e. Klez.

Best regards,
Diego d'Ambra