During past days I got a copy of it. It is now catched by F-PROT with
updates of march 7th and 11th.

With the above updates however today another suspicious file "Crdlswiz.exe"
passed throgh.
I sent a copy of it to F-PROT ([EMAIL PROTECTED])

BTW: W32/Gibe.A (bogus MS pacth) detection was added in 03-06 patch (as from
F-Secure site)
http://www.europe.f-secure.com/v-descs/gibe.shtml

---------------------
Franco Celli
[EMAIL PROTECTED]

>
> From: "Sheldon Koehler" <[EMAIL PROTECTED]>
> Subject: [Declude.Virus] Bogus MS patch
> Date: Sat, 9 Mar 2002 19:22:29 -0800
> Reply-To: [EMAIL PROTECTED]
> I just got a copy of the bogus MS patch going around. How can I block this
> with Declude? F-Prot let it get by...
>
> Sheldon


---
[Quipo ISP - Questa E-mail e' stata controllata dal programma Declude Virus]
[Quipo ISP - This E-mail was scanned for viruses by Declude Virus]

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .

Reply via email to