have both fprot and mcafee Prescan off
#22 getting caught without a problem #17 going thru
Andrew is catching #17, can it have anything to do with AVAFTERJM ON ?
----- Original Message ----- From: "David Sullivan" <[EMAIL PROTECTED]>
To: <[email protected]>
Sent: Monday, December 20, 2004 9:47 PM
Subject: Re[8]: [Declude.Virus] testvirus.org #22
I turned if off and it still got through.
Test #17: Eicar virus hidden using the "CR Vulnerability" (attachment can be
opened by all versions of Microsoft Outlook and Outlook Express)
RSP> I just checked this one, and it got through here, too. I examined the raw
RSP> source of the E-mail, and there doesn't appear to be a lone CR character in
RSP> it, so it doesn't appear to actually contain the Outlook "CR Vulnerability".
Scott, what do you get for test #22. Some have reported it caught while others haven't. My F-Prot config is:
SCANFILE P:\Progra~1\fsi\f-prot\fpcmd.exe /TYPE /SILENT /NOMEM /ARCHIVE=3 /NOBOOT /DUMB /REPORT=report.txt
VIRUSCODE 3
VIRUSCODE 6
VIRUSCODE 8
REPORT Infection:
-- Best regards, David mailto:[EMAIL PROTECTED]
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
--- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.
--- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
--- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.
