Hello R., Friday, April 30, 2004, 9:30:44 PM, you wrote:
>>RSP> Note the directory P:\SPROTECT\Virus\ -- Trend is finding a virus that >>RSP> Declude Virus already found. :) >> >>"P:\SPROTECT\Virus\" is where Trend puts a virus after it finds one. >>My default file for Declude to put viruses is L:\VirusTrap which Trend >>is set NOT to scan. RSP> Ah, OK. In that case, it's presumably finding the virus in the .SMD file RSP> in the \IMail\spool directory, which would be before Declude Virus had a RSP> chance to scan it. Not in this case. The \spool directory is excluded from virus scanning. As I mentioned, the files is getting caught by Declude JM/Sniffer. The virus is getting caught by Trend when being moved by our software from \spool\spam to our per user quarantine review folder for all email that gets JM weighted HOLD. RSP> How do you know that it was created/stored after Declude processed it? Because Trend can't get to any files that are being actively processed by Imail/Declude. (See above.) RSP> That may mean that you have a problem. Are you running v1.79 (with "BANEXT RSP> EZIP" in the virus.cfg file), the latest .exe of your virus scanner, and RSP> latest definitions? Yep, yep and yep. Declude 1.79 Beta (upgraded from the interim version), Fprot 3.14e and latest defs. Here's the appropriate lines from virus.cfg: BANEZIPEXTS ON BANEXT BAS BANEXT BAT BANEXT CMD BANEXT COM BANEXT CPL BANEXT EXE BANEXT HTA BANEXT JS BANEXT MSI BANEXT MSP BANEXT MST BANEXT PIF BANEXT REG BANEXT SCR BANEXT SCT BANEXT VB BANEXT VBE BANEXT VBS BANEXT WS BANEXT WSC BANEXT WSF BANEXT WSH -- Best regards, David mailto:[EMAIL PROTECTED] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.