I sent an encrypted zip file out, changing the .zip to ._ip. F-prot scanned
it and returned code 8, so Declude dutifly tagged it as infected.

Virus Code 8 means suspect, correct?

If this is what F-Prot is going to do, we need to rethink having
users/clients rename files.

04/14/2005 09:04:54.958 Q949B0A0B0000D0F1 [392] 0 - filename._ip
04/14/2005 09:04:54.958 Q949B0A0B0000D0F1 [392] Scanning files (2 scanners)
04/14/2005 09:04:54.973 Q949B0A0B0000D0F1 [392] Starting scanner #1:
C:\Progra~1\FSI\F-Prot\fpcmd.exe /TYPE /SILENT /NOMEM /ARCHIVE=5 /NOBOOT
/DUMB /REPORT=report.txt F:\SPOOL\D949B0~1.VIR\
04/14/2005 09:04:54.973 Q949B0A0B0000D0F1 [392] Waiting for free processes
[20 fpcmd.exe]
04/14/2005 09:04:54.973 Q949B0A0B0000D0F1 [392] Done waiting for free
processes [0].
04/14/2005 09:04:54.973 Q949B0A0B0000D0F1 [392] Virus Scanner Started:
C:\Progra~1\FSI\F-Prot\fpcmd.exe /TYPE /SILENT /NOMEM /ARCHIVE=5 /NOBOOT
/DUMB /REPORT=report.txt F:\SPOOL\D949B0~1.VIR\
04/14/2005 09:04:55.067 Q949B0A0B0000D0F1 [392] Scanning Time: 109ms
[kernel=31 user=78]
04/14/2005 09:04:55.067 Q949B0A0B0000D0F1 [392] Virus scanner 1 reports exit
code of 8

John T
eServices For You


---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to