logo       

Update (daily: 135): msg#00017

security.virus.clamav.virusdb

Subject: Update (daily: 135)

ClamAV databases updated (19-Feb-2004 13:16 GMT): daily.cvd, viruses.db2
daily.cvd version: 135

Submission: 1259
Sender: Luiz Cordeiro
Submitted virus name: Unknown Virus
Virus name: Worm.P2P.Xinef
Virus name alias: W32/Spybot.worm.gen (McAfee)
Notes: I'm unsure what to call this W32 virus, so the name may change
Notes: Drops hidden msplus.exe in %windir%\system32.
Notes: Drops msplus.txt, looks like some log-file
Notes: Running process "msplus.exe"
Notes: Tries to spread via shares and P2P
Added: Yes

Submission: 973
Sender: Andy Fiddaman
Submitted virus name: Unknown Virus
Virus name: Trojan.Loony
Virus name alias: BackDoor-AZV (McAfee)
Notes: This may be a variant of Trojan.Hackarmy
Added: Yes

---below submissions I processed some time ago but have not published---
Submission: 962
Sender: Andreas Kerber
Submitted virus name: Unknown Virus
Notes: Broken Sober sample - e-mail addresses mixed with
Notes: binary data.
Added: No

Submission: 963
Sender: Andreas Kerber
Submitted virus name: Unknown Virus
Notes: Broken Sober sample - e-mail addresses mixed with
Notes: binary data.
Added: No

Submission: 974
Sender: Andy Fiddaman
Submitted virus name: Unknown Virus
Notes: Same as submission 973
Added: No
Submission: 985
Sender: Captain Schnemo
Submitted virus name: Exploit-URLSpoof.gen trojan
Added: No, already detected (Trojan.URLspoof.P)

Submission: 986
Sender: Alexander Danilov
Submitted virus name: EICAR.COM
Notes: Eicar test virus found if e-mail is extracted from this
Notes: badly broken sample.
Added: No

Best regards,
Diego d'Ambra

Attachment: smime.p7s
Description: S/MIME cryptographic signature

<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

News | FAQ | advertise