Hi Dave (just in case this was overlooked in all the activity last week):
Considering that AVG is integrated INTO Declude, it should interface at
LEAST as good as any external scanner.
However, the virus bounce message "filename" variable is NOT set when a
virus is caught by AVG. Only the Virus Name variable is populated.
Obviously, Declude is AWARE of the file name, because when Declude passes
control to an external scanners next, then the infected file is reported
correctly. So there should be no good reason, why a virus caught by the
internal scanner would not report the filename!?
This is also evident in the LOG file. Here's the EICAR virus caught by AVG
in the .48 build. It only reports the virus name "EICAR_Test".
04/29/2010 22:22:20.277 qeae8000000cc0002.smd AVG Reports VIRUS: EICAR_Test
04/29/2010 22:22:20.277 qeae8000000cc0002.smd File(s) are INFECTED
04/29/2010 22:22:20.293 qeae8000000cc0002.smd Scanned: CONTAINS A VIRUS
[Prescan OK][MIME: 3 905]
If the SAME file is detected by an external scanner (in this case ClamAV) it
reports the virus name AND the file name:
04/28/2010 12:49:29.722 q67480000c63e0425.smd Virus scanner 1 reports exit
code of 1
04/28/2010 12:49:29.722 q67480000c63e0425.smd Scanner 1: Virus=
Eicar-Test-Signature Attachment=eicar.zip  I
04/28/2010 12:49:29.722 q67480000c63e0425.smd Scanned: CONTAINS A VIRUS
[Prescan OK][MIME: 3 875]
The AVG integration should be improved to match the quality of integration
of external scanners.
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to imail...@declude.com, and
type "unsubscribe Declude.Virus". The archives can be found