Dumaru.c and F-prot

Antony Stone Antony at SOFT-SOLUTIONS.CO.UK
Sat Sep 27 13:03:14 IST 2003


On Saturday 27 September 2003 12:37 pm, Jan Elmqvist Nielsen wrote:

> Have users of f-prot observed that f-prot dosn't catch Dumaru.c virus
> (patch.exe)?
>
> I am using:
> F-PROT ANTIVIRUS
> Program version: 4.2.0
> Engine version: 3.13.4
>
> VIRUS SIGNATURE FILES
> SIGN.DEF created 25 September 2003
> SIGN2.DEF created 25 September 2003
> MACRO.DEF created 25 September 2003
>
> Kaspersky 4 catch it!

Very strange.

I am using exactly the same version of F-Prot as you - Program 4.2.0, engine 
3.13.4, and yet mine is picking up Dumaru quite happily as W32/Dumaru.A at mm 
(and has been since 4th September - that's the first one I received).

ClamAV: patch.exe contains Worm.Dumaru 
AntiVir: ALERT: [Worm/Dumaru.A virus] ./h8HARit25281/patch.exe <<< Contains 
signature of the worm Worm/Dumaru.A
F-Prot: 
/var/spool/mailscanner/incoming/3241/h8HARit25281/patch.exe  Infection: 
W32/Dumaru.A at mm
Executables are dangerous in email (patch.exe)

Regards,

Antony.

-- 

Normal people think "if it ain't broke, don't fix it".
Engineers think "if it ain't broke, it doesn't have enough features yet".




More information about the MailScanner mailing list