Scott,
I am not using BANEXT EZIP with i7 nor i8 per your instructions to remove it
in place of the new commands:
BANEZIPEXTS and BANZIPEXTS ON
I used that encoded file to test it under i8 first and it went straight
through, that is what tipped me off that something was not right. I then turned
around and made my own test from eicar.com and it went through. I just tested it
under i7 and it got caught. I am unsure where to turn as our .vir directories are off
the charts.
Keith
-----Original Message-----
From: [EMAIL PROTECTED] on behalf of R. Scott Perry
Sent: Wed 3/3/2004 9:01 AM
To: [EMAIL PROTECTED]
Cc:
Subject: RE: [Declude.Virus] New interim Declude Virus Pro to block bogus
.bat, .com, .pif, and .scr files
> For whatever reason, any password laid virus zip files
> containing com, pif, scr, exe, or others are not getting picked up on our
> system with i8, however, they are with i7. I hope this helps.
I assume you are using "BANEXT EZIP" with i7. Are you using it with i8 as
well? Do you have "BANEXT com", "BANEXT pif", etc. in your virus.cfg file?
> I just used to test this was the Eicar.com virus zipped up with
> WinZip with an applied password. Ran it through both to an address on
> the system and also to another Declude protected Imail system, both came
> straight through.
Do the eicarencodedzip E-mail from the Test Virus Sender at
http://www.declude.com/tools/ get caught?
-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers
since 2000.
Declude Virus: Catches known viruses and is the leader in mailserver
vulnerability detection.
Find out what you've been missing: Ask for a free 30-day evaluation.
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus". The archives can be found
at http://www.mail-archive.com.
<<winmail.dat>>
