Ok, I've captured one of these files and confirmed from a manual scan
that it is still taking an excessive amount of time...but wait, there's
more. The report.txt file that it creates shows that it detected
Mytob, but every test where I send this to myself in E-mail results in
no virus detected by F-Prot using VIRUSCODE 3, 6, 8, 9 or 10. I
haven't gone as far as coding something up that can capture the exit
code from the command line yet, but I would be curious what if any was
returned. Here's what Declude Virus shows for this file when I send it to myself: 04/28/2005 17:40:57 Q58666795008E87C7 MIME file: [text/html][7bit; Length=695 Checksum=54365]Here's a link to the virus for those that might want to test it out for themselves. Turn off your real-time virus scanner, right click the file and press save as, and rename it as doc.zip (it's not really a text file). http://administration.mailpure.com/virus/doc.txtHere's the command line for F-Prot that I was using with the file located in C:\test\doc.zip: C:\Progra~1\FSI\F-Prot\fpcmd.exe /TYPE /SILENT /NOBOOT /NOMEM /ARCHIVE=5 /PACKED /DUMB /REPORT=C:\test\report.txt C:\test\doc.zipHere's the output from the report.txt file when manually scanned: Virus scanning report - 28 April 2005 @ 17:45So it takes 10 seconds, find a "security risk named W32/[EMAIL PROTECTED]" and says it is "Suspicious", but I have Declude configured to treat an exit code of 8 as a virus currently, and that's what Suspicious files are supposedly marked as. I don't know if there is a different code being returned, or if F-Prot is just bugging out and not returning a code. Maybe some of you can clear that part up. Matt -- ===================================================== MailPure custom filters for Declude JunkMail Pro. http://www.mailpure.com/software/ ===================================================== |
- [Declude.Virus] Warning for Imail 8.2 updater... Matt
- [Declude.Virus] Warning for Imail 8.2 up... Wind
- Re: [Declude.Virus] Warning for Imai... Sanford Whiteman
- RE: [Declude.Virus] F-Prot missing virus... Colbeck, Andrew
- Re: [Declude.Virus] F-Prot missing v... Darrell \([EMAIL PROTECTED])
- Re: [Declude.Virus] F-Prot missing v... Matt
- RE: [Declude.Virus] F-Prot missing virus... Colbeck, Andrew
- RE: [Declude.Virus] F-Prot missing virus... Colbeck, Andrew