logo       

Update (main: 20, daily: 146): msg#00027

security.virus.clamav.virusdb

Subject: Update (main: 20, daily: 146)

ClamAV databases updated (2004.02.28 20:30 GMT): daily.cvd, viruses.db2,
main.cvd, viruses.db
Version: main: 20, daily: 146


Big main.cvd cleanups: removed duplicated and oversized signatures,
fixed false positive alerts. Signatures in daily.cvd older than 3 weeks
have been moved to main.cvd. Some names have been changed (the major
changes are: Worm.SCO.A-dam -> Worm.SCO.A, Worm.MyDoom.E.UPX ->
Worm.Mydoom.F, Worm.Bagle.C -> Worm.Bagle.E)


Submission: 1190
Sender: Axel Dunkel
Virus: false positive of Trojan.URLspoof.gen in html document
Added: n/a. Removed.

Submission: 1199
Sender: Peter Lindberg
Virus: false positive of Win32.Mix & Win32.Alcaul.A
Added: n/a. Temporarily removed.
Note: One more scanner detects the viruses, however that may be a false
Note: positive alert. New signatures will be added soon.

Submission: 1285-web
Sender: Max Kosmach
Virus: false positive of Constructor.THKit3
Added: Constructor.THKit3
Note: Old signature removed. New signature by Tomasz Papszun.

Submission: 1414
Sender: Eric
Virus: false positive of HLLP.18078
Added: Signature fixed.

Submission: 1430
Sender: Eric
Virus: false positive of Collor.878
Added: n/a. Removed.

Submission: 1434
Sender: Eric
Virus: false positive of Joke/Scr
Added: n/a. Removed.
Note: That was not a real false positive. The original program is
Note: a harmless self-displaying text screen dump and just shouldn't
Note: be treated as a joke.

Submission: 1437
Sender: Eric
Virus Name: false positive VGEN/62.663
Note: The signature was OK, the name wasn't.
Added: n/a. New name: Trojan.Canadian (according to Sophos)

Submission: 1445
Sender: fernando Amatte
Virus: false positive of W32/Sintesys
Added: n/a. Removed.

Submission: 1448
Sender: Leonid Zeitlin
Virus Name: false positive of TR/FlashKiller.B
Added: n/a
Note: the file was not properly cleaned and contains a code of the CIH
virus.

Submission: 1462
Sender: John
Virus Name: false positive Trojan.Dropper.Boot.NCBoot
Added: n/a. removed
Note: clamav _doesn't_ detect a virus in the attached Excel document.
Note: The signature seems to be too generic and has been removed,
though.

Best regards,
Tomasz Kojm
--
oo ..... tkojm@xxxxxxxxxx www.ClamAV.net
(\/)\......... http://www.clamav.net/gpg/tkojm.gpg
\..........._ 0DCA5A08407D5288279DB43454822DC8985A444B
//\ /\ Sat Feb 28 21:11:37 CET 2004

Attachment: pgpDxLRgs7oeR.pgp
Description: PGP signature

<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

News | FAQ | advertise