Hi, Am I doing something wrong? I have both F-Prot and Sophos to scan the mail for virusses. I know Declude has trouble distilling the name of the virus from the Sophos report file as is does not end the virus name with new line. However, I've been trying playing with the order in which Declude calls both scanners.
I'm running Declude c1.75 as reported by the -diag switch. I'm either getting: ------------------- Declude Virus v1.75 caught the : EICAR_Test_File virus in Sophos SWEEP for NT from [EMAIL PROTECTED] to: [EMAIL PROTECTED] Date: 12/22/2003 13:52:09 Subject: Test eicar.com file [eicarzip] Spool File: De8f70022020af014.SMD Remote IP: 216.58.174.203 [.....] ------------------- or ------------------- Declude Virus v1.75 caught the 'EICAR-AV-Test' found in file C:\IMail\spool\DE71F0~1.VIR\\1_1.com virus in Sophos SWEEP for NT from [EMAIL PROTECTED] to: [EMAIL PROTECTED] Date: 12/22/2003 13:44:17 Subject: Test eicar.com file [eicarmimeuu] Spool File: De71f001f026abca2.SMD Remote IP: 216.58.174.203 [....] ------------------- As I'm seeing the line "in Sophos SWEEP for NT" I was thinking I did something wrong. However, here are both report files (manually run from the commandline). Where is Declude getting the sting "in Sophos ....NT" from? ---f-prot report------------------- Virus scanning report - 22 December 2003 @ 13:50 F-PROT ANTIVIRUS Program version: 3.14b Engine version: 3.14.7 VIRUS SIGNATURE FILES SIGN.DEF created 20 December 2003 SIGN2.DEF created 20 December 2003 MACRO.DEF created 15 December 2003 Search: eicar.com Action: Report only Files: "Dumb" scan of all files Switches: /ARCHIVE /REPORT=report.txt /SILENT /NOBOOT /NOMEM Memory was not scanned. Hard disk boot sectors were not scanned. C:\virtest\eicar.com Infection: EICAR_Test_File Results of virus scanning: Files: 1 MBRs: 0 Boot sectors: 0 Objects scanned: 1 Infected: 1 Suspicious: 0 Disinfected: 0 Deleted: 0 Renamed: 0 Time: 0:00 ---------------------- ---Sophos report ------------------- Sophos Anti-Virus Version 3.76, December 2003 [Win32/Intel] Includes detection for 86142 viruses, trojans and worms Copyright (c) 1989,2003 Sophos Plc, www.sophos.com System time 13:47:52, System date 22 December 2003 Command line qualifiers are: -nc -mac -archive IDE directory is: C:\Program Files\Sophos SWEEP for NT Using IDE file agobo-aw.ide Using IDE file agobotag.ide Using IDE file agobotas.ide [.....] Using IDE file Yaha-y.ide Using IDE file zana-a.ide Quick Scanning >>> Virus 'EICAR-AV-Test' found in file eicar.com 1 file swept in 1 second. 1 virus was discovered. 1 file out of 1 was infected. Please send infected samples to Sophos for analysis. For advice consult www.sophos.com, email [EMAIL PROTECTED] or telephone +44 1235 559933 Ending Sophos Anti-Virus. ---------------------- Met vriendelijke groet, Bonno Bloksma --- [This E-mail scanned for viruses by Declude Virus using f-prot and Sophos] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.
