Hello R.,

Friday, April 30, 2004, 9:30:44 PM, you wrote:


>>RSP> Note the directory P:\SPROTECT\Virus\ -- Trend is finding a virus that
>>RSP> Declude Virus already found.  :)
>>
>>"P:\SPROTECT\Virus\" is where Trend puts a virus after it finds one.
>>My default file for Declude to put viruses is L:\VirusTrap which Trend
>>is set NOT to scan.

RSP> Ah, OK.  In that case, it's presumably finding the virus in the .SMD file
RSP> in the \IMail\spool directory, which would be before Declude Virus had a
RSP> chance to scan it.

Not in this case.  The \spool directory is excluded from virus
scanning.  As I mentioned, the files is getting caught by Declude
JM/Sniffer.  The virus is getting caught by Trend when being moved by our
software from \spool\spam to our per user quarantine review folder for
all email that gets JM weighted HOLD.

RSP> How do you know that it was created/stored after Declude processed it?

Because Trend can't get to any files that are being actively processed
by Imail/Declude.  (See above.)

RSP> That may mean that you have a problem.  Are you running v1.79 (with "BANEXT
RSP> EZIP" in the virus.cfg file), the latest .exe of your virus scanner, and
RSP> latest definitions?

Yep, yep and yep.

Declude 1.79 Beta (upgraded from the interim version), Fprot 3.14e and
latest defs.

Here's the appropriate lines from virus.cfg:

BANEZIPEXTS     ON

BANEXT          BAS
BANEXT          BAT
BANEXT          CMD
BANEXT          COM
BANEXT          CPL
BANEXT          EXE
BANEXT          HTA
BANEXT          JS
BANEXT          MSI
BANEXT          MSP
BANEXT          MST
BANEXT          PIF
BANEXT          REG
BANEXT          SCR
BANEXT          SCT
BANEXT          VB
BANEXT          VBE
BANEXT          VBS
BANEXT          WS
BANEXT          WSC
BANEXT          WSF
BANEXT          WSH


-- 
Best regards,
 David                            mailto:[EMAIL PROTECTED]

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to