Markus, are you sure that there is a "C" variant out now? Both RAV and F-Prot released updates to catch the new "B" variant:
========== VIRUS ALERT! Win32/[EMAIL PROTECTED] June 5, 2003 - RAV AntiVirus Team is alerting all computer users that a dangerous Internet worm, called Win32/[EMAIL PROTECTED], is reported to have a high infection level in the last 24 hours. This worm is classified as "Potentially destructive" by RAV Team. ========== Bill ----- Original Message ----- From: "Markus Gufler" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Thursday, June 05, 2003 6:00 AM Subject: RE: [Declude.Virus] high virus traffic today? > > > Sophos and McAfee just minutes ago announced a new variant of > > Bugbear, > > which apparently started spreading yesterday. They both have > > reported that > > it is spreading fast. > > It's 3:00 PM now here, and we are already on more then 300% of a > "normal" day. > Strange: The new version is Bugbear.C > We catch here only Bugbear.B but have running definitely the latest > definitions. > > Markus > > > --- > [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] > > --- > This E-mail came from the Declude.Virus mailing list. To > unsubscribe, just send an E-mail to [EMAIL PROTECTED], and > type "unsubscribe Declude.Virus". The archives can be found > at http://www.mail-archive.com. > --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.