Hello,

  Sine I started using SOPHOS I have been getting the following lines
  the Virus Analyzer.  Is there away of having it log as the first line and not
  the one ones with   'W32/Netsky-C' found in file
  S:\spool\D98AC0~1.VIR\\0.com only?
  Also i am getting alot of dxxx.vir folders in my spool dir. They do
  seem to go away some times.  If there is alot say 100 I have to
  delete them or they just sit in the spool.
  I am not runing either on access scanner(Sophos or McAfee) so I ruled that out.
  
Virus Summary by Count ---------------------------------------

Count          Inbound/Outbound            Name
27                 27 / 0               the W32/[EMAIL PROTECTED] virus !!!
3                   3 / 0               the W32/[EMAIL PROTECTED] virus !!!
2                   2 / 0               the W32/[EMAIL PROTECTED] virus !!!
2                   2 / 0               the W32/Bagle.e!zip virus !!!
1                   1 / 0               'W32/Netsky-C' found in file 
S:\spool\D98AC0~1.VIR\\0.com
1                   1 / 0               'W32/Netsky-D' found in file 
S:\spool\D983B0~1.VIR\\0.pif
1                   1 / 0               'W32/Netsky-D' found in file 
S:\spool\D9ABA0~1.VIR\\0.pif
1                   1 / 0               the W32/[EMAIL PROTECTED] virus !!!
1                   1 / 0               'W32/Netsky-D' found in file 
S:\spool\D97530~1.VIR\\1.pif

--------------------------------------------------------------

I am not seeing an errors in the actual virus log.
------------Snip----------
03/02/2004 09:20:48 Q983b0044011e8c69 Scanner 1: Virus= the W32/[EMAIL PROTECTED] 
virus !!! Attachment=yours.pif [20] I
03/02/2004 09:20:50 Q983b0044011e8c69 Scanner 2: Virus= 'W32/Netsky-D' found in file 
S:\spool\D983B0~1.VIR\\0.pif Attachment=yours.pif [20] I
03/02/2004 09:20:50 Q983b0044011e8c69 Found a bogus .pif file
03/02/2004 09:20:50 Q983b0044011e8c69 File(s) are INFECTED [ the W32/[EMAIL PROTECTED] 
virus !!!: 3]
03/02/2004 09:20:51 Q983b0044011e8c69 Scanned: CONTAINS A VIRUS [MIME: 2 17592]
03/02/2004 09:20:51 Q983b0044011e8c69 From: [Forged] To: [EMAIL PROTECTED] [incoming 
from 68.118.252.138]
03/02/2004 09:20:51 Q983b0044011e8c69 Subject: Re: Here
03/02/2004 09:22:39 Q98ac000c01444593 Scanner 1: Virus= the W32/[EMAIL PROTECTED] 
virus !!! Attachment=doc_ang.txt.com [20] I
03/02/2004 09:22:41 Q98ac000c01444593 Scanner 2: Virus= 'W32/Netsky-C' found in file 
S:\spool\D98AC0~1.VIR\\0.com Attachment=doc_ang.txt.com [20] I
03/02/2004 09:22:41 Q98ac000c01444593 File(s) are INFECTED [ the W32/[EMAIL PROTECTED] 
virus !!!: 3]
03/02/2004 09:22:42 Q98ac000c01444593 Scanned: CONTAINS A VIRUS [MIME: 2 25509]
03/02/2004 09:22:42 Q98ac000c01444593 From: [Forged] To: [EMAIL PROTECTED] [incoming 
from 68.10.208.15]
-------------End Snip------------

Lines from Virus.cfg
SCANFILE1 C:\Progra~1\Common~1\networ~1\viruss~1\4.0.xx\scan.exe /ALL /NOMEM /NOBEEP 
/NOBREAK /UNZIP /SILENT /NODDA /REPORT report.txt
VIRUSCODE1 13
REPORT1  Found

SCANFILE2  C:\Progra~1\Sophos~1\SAV32CLI.EXE -ns -p=report.txt -mac -archive
VIRUSCODE2 3
VIRUSCODE2 6
REPORT2    >>> Virus

-- 
Best regards,
 ~Paul~                          mailto:[EMAIL PROTECTED]

---
{This E-mail scanned for viruses by Declude Virus/McAfee}

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to