After several hours of working on this, I still cannot get the new version
of SCAN32.exe to detect viruses and return the correct response for AVP to
move the files.  Currently I am using the OnAccess Scanner of 7.1 to remove
the infected files as they arrive, but it is not as clean as running AVP as
I also have to play cleanup manually of a lot of RCP files.  If anyone (with
more experience) knows a way of determining the errorlevel response that the
new version might be using, I sure could use some pointers !   I found a
couple of changes to the command line switches, but no matter what I do, I
cannot get the program to reply to AVP with an acceptable response.  As I
understand it, the scan32.exe is only suppose to open, detect, and close
with an errorlevel that AVP understands, so that it can move the file.  I am
thinking they removed or changed that errorlevel function. 

    Also, I noticed that someone here was telling me about their removal or
worms by excluding extensions.  This Witty.worm virus did not come through
like other email worms. This was a direct machine-to-machine attack of a
vulnerable port 4000 in the BlackIce (software) firewall/Intrusion detection
system (prior to 3.6ccg released on March 20th), and the virus infected and
destroyed one machine in 11 minutes.  I have since installed multiple
firewall-routers of different brands to help thwart off future attacks, and
recommend the same to everyone.  I never thought that the very product I was
depending on to protect my system,  would be the cause of an attack.  I have
been using their products since 1996, so history of no problems, is no
guarantee either.

John Martoccio 
[EMAIL PROTECTED] 

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]
On Behalf Of John Martoccio
Sent: Thursday, March 25, 2004 4:26 PM
To: [email protected]
Subject: Anyone using AVP with VirusScan 7.1 ?


I am trying to configure the Scanner settings of my AVP, but haven't figured
out what the new settings are, as I moved from Netshield 4.5 to VirusScan
7.1, when the Witty.worm virus ate my BlackIce, and proceded to wipe out my
entire system !

We are now using multiple firewalls & products.
John Martoccio 
Intelligent Solutions (a computer VAR) 
Fox Lake, IL, USA 
[EMAIL PROTECTED] 

This is the discussion list for the IMS Free email server software.
  To unsubscribe send mailto:[EMAIL PROTECTED]

            Delivered by Rockliffe MailSite
           http://www.rockliffe.com/mailsite
                Rock Solid Software (tm)

Reply via email to