Hi,

Am I doing something wrong? I have both F-Prot and Sophos to scan the mail
for virusses. I know Declude has trouble distilling the name of the virus
from the Sophos report file as is does not end the virus name with new line.
However, I've been trying playing with the order in which Declude calls both
scanners.

I'm running Declude c1.75 as reported by the -diag switch.

 I'm either getting:
-------------------
Declude Virus v1.75 caught the : EICAR_Test_File virus in Sophos SWEEP for
NT
from [EMAIL PROTECTED] to:  [EMAIL PROTECTED]

Date:       12/22/2003 13:52:09
Subject:    Test eicar.com file [eicarzip]
Spool File: De8f70022020af014.SMD
Remote IP:  216.58.174.203
[.....]
-------------------
or
-------------------
Declude Virus v1.75 caught the  'EICAR-AV-Test' found in file
C:\IMail\spool\DE71F0~1.VIR\\1_1.com virus in Sophos SWEEP for NT
from [EMAIL PROTECTED] to:  [EMAIL PROTECTED]

Date:       12/22/2003 13:44:17
Subject:    Test eicar.com file [eicarmimeuu]
Spool File: De71f001f026abca2.SMD
Remote IP:  216.58.174.203
[....]
-------------------

As I'm seeing the line "in Sophos SWEEP for NT" I was thinking I did
something wrong. However, here are both report files (manually run from the
commandline). Where is Declude getting the sting "in Sophos ....NT" from?


---f-prot report-------------------
Virus scanning report  -  22 December 2003 @ 13:50

F-PROT ANTIVIRUS
Program version: 3.14b
Engine version: 3.14.7

VIRUS SIGNATURE FILES
SIGN.DEF created 20 December 2003
SIGN2.DEF created 20 December 2003
MACRO.DEF created 15 December 2003

Search: eicar.com
Action: Report only
Files: "Dumb" scan of all files
Switches: /ARCHIVE /REPORT=report.txt /SILENT /NOBOOT /NOMEM
Memory was not scanned.
Hard disk boot sectors were not scanned.

C:\virtest\eicar.com  Infection: EICAR_Test_File

Results of virus scanning:

Files: 1
MBRs: 0
Boot sectors: 0
Objects scanned: 1
Infected: 1
Suspicious: 0
Disinfected: 0
Deleted: 0
Renamed: 0

Time: 0:00

----------------------

---Sophos report -------------------
Sophos Anti-Virus
Version 3.76, December 2003 [Win32/Intel]
Includes detection for 86142 viruses, trojans and worms
Copyright (c) 1989,2003 Sophos Plc, www.sophos.com

System time 13:47:52, System date 22 December 2003
Command line qualifiers are: -nc -mac -archive

IDE directory is: C:\Program Files\Sophos SWEEP for NT

Using IDE file agobo-aw.ide
Using IDE file agobotag.ide
Using IDE file agobotas.ide
[.....]
Using IDE file Yaha-y.ide
Using IDE file zana-a.ide

Quick Scanning

>>> Virus 'EICAR-AV-Test' found in file eicar.com

1 file swept in 1 second.
1 virus was discovered.
1 file out of 1 was infected.
Please send infected samples to Sophos for analysis.
For advice consult www.sophos.com, email [EMAIL PROTECTED]
or telephone +44 1235 559933
Ending Sophos Anti-Virus.

----------------------

Met vriendelijke groet,

Bonno Bloksma

---
[This E-mail scanned for viruses by Declude Virus using f-prot and Sophos]

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to