We agreed that adding the file name would be useful and it is on the dev list. I thought I posted this to the list but it may have got overlooked with all the activity from last week ;)
From: supp...@declude.com [mailto:supp...@declude.com] On Behalf Of Andy Schmidt Sent: Monday, May 03, 2010 1:41 PM To: firstname.lastname@example.org Subject: [Declude.Virus] RE: Internal (AVG Scanner) does NOT report file name Hi Dave (just in case this was overlooked in all the activity last week): Considering that AVG is integrated INTO Declude, it should interface at LEAST as good as any external scanner. However, the virus bounce message "filename" variable is NOT set when a virus is caught by AVG. Only the Virus Name variable is populated. Obviously, Declude is AWARE of the file name, because when Declude passes control to an external scanners next, then the infected file is reported correctly. So there should be no good reason, why a virus caught by the internal scanner would not report the filename!? This is also evident in the LOG file. Here's the EICAR virus caught by AVG in the .48 build. It only reports the virus name "EICAR_Test". 04/29/2010 22:22:20.277 qeae8000000cc0002.smd AVG Reports VIRUS: EICAR_Test 04/29/2010 22:22:20.277 qeae8000000cc0002.smd File(s) are INFECTED [EICAR_Test: 7] 04/29/2010 22:22:20.293 qeae8000000cc0002.smd Scanned: CONTAINS A VIRUS [Prescan OK][MIME: 3 905] If the SAME file is detected by an external scanner (in this case ClamAV) it reports the virus name AND the file name: 04/28/2010 12:49:29.722 q67480000c63e0425.smd Virus scanner 1 reports exit code of 1 04/28/2010 12:49:29.722 q67480000c63e0425.smd Scanner 1: Virus= Eicar-Test-Signature Attachment=eicar.zip  I 04/28/2010 12:49:29.722 q67480000c63e0425.smd Scanned: CONTAINS A VIRUS [Prescan OK][MIME: 3 875] The AVG integration should be improved to match the quality of integration of external scanners. Best Regards, Andy --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to imail...@declude.com, and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com. --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to imail...@declude.com, and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.