Scott, we have the following entry in our virus.cfg files on both of our IMail/Declude servers:

SCANFILE2 C:\Progra~1\Trend\Sprotect\vscantm.bin /NBPM /NM /NB /NC /Q /VSTEMP=m:\temp\ /LR=report.txt
VIRUSCODE2 1
REPORT2 Found


I also have:  PRESCAN  OFF

However, this particular PayPal phishing message is not getting caught by Declude Virus. If I run the following from the command-line:

This is almost certainly because your AV program is reporting a different error code when it finds a phishing message than it does when it finds a virus. If you check the log file, you should see the code that they return when they detect a phishing message.


Are these not getting tagged by Declude Virus because of the "Undet [ ]( )" line that is listed just before the "Found [ HTML_BOFRA.B]( 1)" line in the report file? If so, is there a way to fix this? Shouldn't Declude Virus be looking for the word "Found" in the report file? We are running Declude v1.81.

If that were the problem, Declude Virus would block the E-mail, and just report it as "Unknown Virus". However, since it is not being blocked, that means that Declude Virus doesn't know there is a virus there.


-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000.
Declude Virus: Ultra reliable virus detection and the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask for a free 30-day evaluation.



---- This outgoing message is guaranteed to be authentic by Message Level users. Guarantee the authenticity of your email @ http://www.messagelevel.com. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to