Nevermind, found a copy of it, just had trouble with the German.  It seems my Inoc 
caught it correctly, however, the Fprot didn't, gave me error.  
 
Q6f7408d2006085b0 Scanner 1 reported error code #8, which is listed as OK
09/27/2004 15:52:20 Q6f7408d2006085b0 Scanner 2: Virus= JPEG.MS04-028.Exploit.Trojan 
Attachment=jpegcompoc.zip.ZIP [1] I
09/27/2004 15:52:20 Q6f7408d2006085b0 File(s) are INFECTED [ 
JPEG.MS04-028.Exploit.Trojan: 101]
 
Keith

        -----Original Message----- 
        From: Keith Johnson on behalf of Keith Johnson 
        Sent: Mon 9/27/2004 3:02 PM 
        To: [EMAIL PROTECTED] 
        Cc: 
        Subject: RE: [Declude.Virus] Fprot GDI Scanner lines.
        
        
        Mark,
             What did you use to generate the GDI Exploit test file?  Thanks
         
        Keith

                -----Original Message----- 
                From: [EMAIL PROTECTED] on behalf of Mark Smith 
                Sent: Mon 9/27/2004 1:55 PM 
                To: [EMAIL PROTECTED] 
                Cc: 
                Subject: RE: [Declude.Virus] Fprot GDI Scanner lines.
                
                

                Send a GDI Exploit test file through.
                You'll get the error "Can't Parse Virus type" in the Declude Virus log.
                
                
                
                > -----Original Message-----
                > From: [EMAIL PROTECTED]
                > [mailto:[EMAIL PROTECTED] On Behalf Of Bill Landry
                > Sent: Saturday, September 25, 2004 11:22 AM
                > To: [EMAIL PROTECTED]
                > Subject: Re: [Declude.Virus] Fprot GDI Scanner lines.
                >
                > ----- Original Message -----
                > From: "Mark Smith" <[EMAIL PROTECTED]>
                >
                >
                > > Actually this breaks Declude because Declude Virus can't
                > look for multiple
                > > REPORT lines.
                > >
                > > Scott,
                > > How can we setup Declude Virus to look for multiple lines in the
                > report.txt
                > > file?
                >
                > I've been running F-Prot Version 3.15b since it was released
                > yesterday and
                > have not had to make any changes to my virus config to support the 
new
                > version.  It has been running exactly the way it always has.
                >
                > Bill
                >
                > ---
                > [This E-mail was scanned for viruses by Declude Virus
                > (http://www.declude.com)]
                >
                > ---
                > This E-mail came from the Declude.Virus mailing list.  To
                > unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
                > type "unsubscribe Declude.Virus".    The archives can be found
                > at http://www.mail-archive.com.
                >
                
                
                ---
                [This E-mail was scanned for viruses by Declude Virus 
(http://www.declude.com)]
                
                ---
                This E-mail came from the Declude.Virus mailing list.  To
                unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
                type "unsubscribe Declude.Virus".    The archives can be found
                at http://www.mail-archive.com.
                

<<winmail.dat>>

Reply via email to