08/12/2003 05:23:13 Qc0100ea3011071fb Scanned: Virus Free [Prescan OK][MIME: 1 1678] 08/12/2003 05:23:19 Qc012117801167b13 MIME file: [text/html][quoted-printable; Length=881 Checksum=72056] 08/12/2003 05:23:19 Qc012117801167b13 MIME file: KOF2002.exe [base64; Length=34304 Checksum=3657899] 08/12/2003 05:23:21 Qc0120ea401107aa6 Scanned: Virus Free [MIME: 1 961] 08/12/2003 05:23:22 Qc012117801167b13 Scanner 1: Virus=: W32/[EMAIL PROTECTED] Attachment=KOF2002.exe [1] I 08/12/2003 05:23:22 Qc012117801167b13 Scanner 2: Virus= the W32/[EMAIL PROTECTED] virus !!! Attachment=KOF2002.exe [1] I 08/12/2003 05:23:23 Qc01a0ea80110989e Scanned: Virus Free [Prescan OK] 08/12/2003 05:23:25 Qc012117801167b13 File(s) are INFECTED [: W32/[EMAIL PROTECTED]: 0] 08/12/2003 05:23:25 Qc012117801167b13 Deleting file with virus 08/12/2003 05:23:25 Qc012117801167b13 Deleting E-mail with virus! 08/12/2003 05:23:25 Qc012117801167b13 Scanned: CONTAINS A VIRUS [Prescan OK][MIME: 2 35205]
I installed AVG as a third scanner using these settings but it is not showing in the virus logs... I see scanner 1 and 2 (above) but not 3. Are my settings bad or does Declude discard the third scan if the first two find a virus? Settings: SCANFILE1 C:\Progra~1\FSI\F-Prot\F-Prot.exe /TYPE /SILENT /NOMEM /ARCHIVE /NOFLOPPY /NOBOOT /DUMB /REPORT=report.txt VIRUSCODE1 3 VIRUSCODE1 6 VIRUSCODE1 8 REPORT1 Infection SCANFILE2 scan.exe /ALL /NOMEM /NOBEEP /NOBREAK /UNZIP /SILENT /NODDA /REPORT report.txt VIRUSCODE2 13 REPORT2 Found SCANFILE3 C:\Progra~1\Grisoft\AVG7\avgscan.exe /NOMEM /NOSELF /ARC /REPORT=report.txt VIRUSCODE3 2 VIRUSCODE3 6 REPORT3 identified -- Roger Heath [EMAIL PROTECTED] www.rleeheath.com ----- Copy of Original Message(s): ----- >> Here is the response I received from them this morning: >> >> The Mimail.A worm started spreading this weekend and has already gained wide >> distribution. W32/[EMAIL PROTECTED] spreads by infected attachments to e-mail >> messages disguised as being from the recipient's local administrator. >> >> W32/[EMAIL PROTECTED] is detected and prevented from running with the latest >> versions of F-Prot Antivirus (released on 2-5 August 2003) using virus >> signature files dated 2 August 2003 or later. >> >> Windows users using the RealTime Protector were not in any danger from >> W32/[EMAIL PROTECTED] as the RealTime Protector stopped it from executing. >> >> So they are trying to tell me F-Prot is catching it while I can clearly see >> with evidence it is not. What is wrong with them? D> The latest signature dates I have are app 8/2 and macro 8/4 and it says up-to-date D> so there is no 8/5 updates. I am running 3.14 32-bit. Can someone send me the D> virus to see if it gets through? D> -- Dan D> --- D> [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] D> --- D> This E-mail came from the Declude.Virus mailing list. To D> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and D> type "unsubscribe Declude.Virus". The archives can be found D> at http://www.mail-archive.com. D> -- D> ActivatorMail(tm) ver.00608031 Scanned for all viruses by D> www.activatormail.com intelligent anti-virus anti-spam service -- ActivatorMail(tm) ver.00811031 Scanned for all viruses by www.activatormail.com intelligent anti-virus anti-spam service --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.
