08/12/2003 05:23:13 Qc0100ea3011071fb Scanned: Virus Free [Prescan OK][MIME: 1 1678]
08/12/2003 05:23:19 Qc012117801167b13 MIME file: [text/html][quoted-printable; 
Length=881 Checksum=72056]
08/12/2003 05:23:19 Qc012117801167b13 MIME file: KOF2002.exe [base64; Length=34304 
Checksum=3657899]
08/12/2003 05:23:21 Qc0120ea401107aa6 Scanned: Virus Free [MIME: 1 961]
08/12/2003 05:23:22 Qc012117801167b13 Scanner 1: Virus=: W32/[EMAIL PROTECTED] 
Attachment=KOF2002.exe [1] I
08/12/2003 05:23:22 Qc012117801167b13 Scanner 2: Virus= the W32/[EMAIL PROTECTED] 
virus !!! Attachment=KOF2002.exe [1] I
08/12/2003 05:23:23 Qc01a0ea80110989e Scanned: Virus Free [Prescan OK]
08/12/2003 05:23:25 Qc012117801167b13 File(s) are INFECTED [: W32/[EMAIL PROTECTED]: 0]
08/12/2003 05:23:25 Qc012117801167b13 Deleting file with virus
08/12/2003 05:23:25 Qc012117801167b13 Deleting E-mail with virus!
08/12/2003 05:23:25 Qc012117801167b13 Scanned: CONTAINS A VIRUS [Prescan OK][MIME: 2 
35205]

I installed AVG as a third scanner using these settings but it is not
showing in the virus logs... I see scanner 1 and 2 (above) but not 3.
Are my settings bad or does Declude discard the third scan if the
first two find a virus?

Settings:

SCANFILE1       C:\Progra~1\FSI\F-Prot\F-Prot.exe /TYPE /SILENT /NOMEM /ARCHIVE 
/NOFLOPPY /NOBOOT /DUMB /REPORT=report.txt
VIRUSCODE1      3
VIRUSCODE1      6
VIRUSCODE1      8
REPORT1         Infection

SCANFILE2       scan.exe /ALL /NOMEM /NOBEEP /NOBREAK /UNZIP /SILENT /NODDA /REPORT 
report.txt
VIRUSCODE2      13
REPORT2         Found

SCANFILE3       C:\Progra~1\Grisoft\AVG7\avgscan.exe /NOMEM /NOSELF /ARC 
/REPORT=report.txt
VIRUSCODE3      2
VIRUSCODE3      6
REPORT3         identified



--
Roger Heath
[EMAIL PROTECTED]
www.rleeheath.com


----- Copy of Original Message(s): -----

>> Here is the response I received from them this morning:
>>
>> The Mimail.A worm started spreading this weekend and has already gained wide
>> distribution. W32/[EMAIL PROTECTED] spreads by infected attachments to e-mail
>> messages disguised as being from the recipient's local administrator.
>>
>> W32/[EMAIL PROTECTED] is detected and prevented from running with the latest
>> versions of F-Prot Antivirus (released on 2-5 August 2003) using virus
>> signature files dated 2 August 2003 or later.
>>
>> Windows users using the RealTime Protector were not in any danger from
>> W32/[EMAIL PROTECTED] as the RealTime Protector stopped it from executing.
>>
>> So they are trying to tell me F-Prot is catching it while I can clearly see
>> with evidence it is not. What is wrong with them?

D> The latest signature dates I have are app 8/2 and macro 8/4 and it says up-to-date
D> so there is no 8/5 updates.  I am running 3.14 32-bit.  Can someone send me the
D> virus to see if it gets through?

D>   -- Dan

D> ---
D> [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

D> ---
D> This E-mail came from the Declude.Virus mailing list.  To
D> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
D> type "unsubscribe Declude.Virus".    The archives can be found
D> at http://www.mail-archive.com.
D> --
D> ActivatorMail(tm) ver.00608031 Scanned for all viruses by 
D> www.activatormail.com intelligent anti-virus anti-spam service

--
ActivatorMail(tm) ver.00811031 Scanned for all viruses by 
www.activatormail.com intelligent anti-virus anti-spam service

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to