During past days I got a copy of it. It is now catched by F-PROT with updates of march 7th and 11th.
With the above updates however today another suspicious file "Crdlswiz.exe" passed throgh. I sent a copy of it to F-PROT ([EMAIL PROTECTED]) BTW: W32/Gibe.A (bogus MS pacth) detection was added in 03-06 patch (as from F-Secure site) http://www.europe.f-secure.com/v-descs/gibe.shtml --------------------- Franco Celli [EMAIL PROTECTED] > > From: "Sheldon Koehler" <[EMAIL PROTECTED]> > Subject: [Declude.Virus] Bogus MS patch > Date: Sat, 9 Mar 2002 19:22:29 -0800 > Reply-To: [EMAIL PROTECTED] > I just got a copy of the bogus MS patch going around. How can I block this > with Declude? F-Prot let it get by... > > Sheldon --- [Quipo ISP - Questa E-mail e' stata controllata dal programma Declude Virus] [Quipo ISP - This E-mail was scanned for viruses by Declude Virus] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com .
