Hello,

go to \imail\declude\virus.cfg
modify the Loglevel to DEBUG 
try sending you a virus from http://www.declude.com/tools/mailsend.html
what does your logfile now say (\imail\spool\vir0927.log) if such a mail
comes in? 

it should look like 
09/27/2002 18:47:15 Q8b924e790110ed6e MIME file: eicar.com [base64;
Length=68 Checksum=4622]
09/27/2002 18:47:15 Q8b924e790110ed6e Scanner 1: Virus=: EICAR_Test_File
Attachment=eicar.com [0] I
09/27/2002 18:47:15 Q8b924e790110ed6e Found a bogus .com file
09/27/2002 18:47:15 Q8b924e790110ed6e File(s) are INFECTED [3]
09/27/2002 18:47:15 Q8b924e790110ed6e Scanned: CONTAINS A VIRUS [MIME: 2
487]
09/27/2002 18:47:15 Q8b924e790110ed6e From: [EMAIL PROTECTED] To:
[EMAIL PROTECTED]
09/27/2002 18:47:15 Q8b924e790110ed6e Subject: Test eicar.com file
[eicarplain]

if not, maybe declude is not running? (try declude --diag)

Alex 


> -----Original Message-----
> From: Kevin (Linkbrokers Support) [mailto:[EMAIL PROTECTED]]
> Sent: Friday, September 27, 2002 6:17 PM
> To: [EMAIL PROTECTED]
> Subject: Re: [Declude.Virus] DSN:KLEZ virus
> 
> 
> Question then - Does F-Prot stop Klez?
> Yes its being delivered to my customers.
> 
>  I went through all 17 test from eicar.com
> they all came back - and were caught by the PC's virus scan. 
> Non of them had
> been clean.
> 
> What next?
> ----- Original Message -----
> From: "R. Scott Perry" <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Sent: Friday, September 27, 2002 11:48 AM
> Subject: Re: [Declude.Virus] DSN:KLEZ virus
> 
>
> >
> > >I would really like to stop this virus from reaching our 
> customers -
> > >What's the best way to config the virus.cfg file to stop 
> this virus  I
> > >have declude virus. can anyone point me in the right direction.
> >
> > Assuming that your virus scanner can detect Klez (which all 
> should be able
> > to do, except ones with old virus definitions), the virus should be
> > detected automatically.  Is it being delivered to your 
> customers?  If so,
> > does the eicar.com file get delivered when sent from the 
> Test Virus Sender
> > at http://www.declude.com/tools ?  If the eicar.com file doesn't get
> > caught, something isn't set up properly (in that case, you 
> can send me
> your
> > \IMail\Declude\virus.cfg file and \IMail\spool\vir####.log 
> file, and I can
> > take a look to see what is wrong).
> >                         -Scott
> >
> > ---
> > [This E-mail was scanned for viruses by Declude Virus
> (http://www.declude.com)]
> >
> > ---
> > This E-mail came from the Declude.Virus mailing list.  To
> > unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
> > type "unsubscribe Declude.Virus".    The archives can be found
> > at http://www.mail-archive.com.
> >
> >
> >
> > [Reliable Web Hosting by -  http://www.linkbrokers.com/hosting.cfm]
> > [This E-mail scanned for viruses by LinkBrokers EMail Service]
> > [This E-mail scanned for spam mail against orbs and spamcop]
> >
> >
> >
> 
> 
> 
> 
> 
> [Reliable Web Hosting by -  http://www.linkbrokers.com/hosting.cfm]
> [This E-mail scanned for viruses by LinkBrokers EMail Service]
> [This E-mail scanned for spam mail against orbs and spamcop]
> 
> ---
> [This E-mail was scanned for viruses by Declude Virus 
(http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to