Scott,
        I am not using BANEXT EZIP with i7 nor i8 per your instructions to remove it 
in place of the new commands:
 
BANEZIPEXTS and BANZIPEXTS ON
 
       I used that encoded file to test it under i8 first and it went straight 
through, that is what tipped me off that something was not right.  I then turned 
around and made my own test from eicar.com and it went through.  I just tested it 
under i7 and it got caught.  I am unsure where to turn as our .vir directories are off 
the charts.  
 
Keith

        -----Original Message----- 
        From: [EMAIL PROTECTED] on behalf of R. Scott Perry 
        Sent: Wed 3/3/2004 9:01 AM 
        To: [EMAIL PROTECTED] 
        Cc: 
        Subject: RE: [Declude.Virus] New interim Declude Virus Pro to block bogus 
.bat, .com, .pif, and .scr files
        
        


        >          For whatever reason, any password laid virus zip files
        > containing com, pif, scr, exe, or others are not getting picked up on our
        > system with i8, however, they are with i7.   I hope this helps.
        
        I assume you are using "BANEXT EZIP" with i7.  Are you using it with i8 as
        well?  Do you have "BANEXT com", "BANEXT pif", etc. in your virus.cfg file?
        
        >          I just used to test this was the Eicar.com virus zipped up with
        > WinZip with an applied password.  Ran it through both to an address on
        > the system and also to another Declude protected Imail system, both came
        > straight through.
        
        Do the eicarencodedzip E-mail from the Test Virus Sender at
        http://www.declude.com/tools/ get caught?
        
                                                            -Scott
        ---
        Declude JunkMail: The advanced anti-spam solution for IMail mailservers
        since 2000.
        Declude Virus: Catches known viruses and is the leader in mailserver
        vulnerability detection.
        Find out what you've been missing: Ask for a free 30-day evaluation.
        
        ---
        [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
        
        ---
        This E-mail came from the Declude.Virus mailing list.  To
        unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
        type "unsubscribe Declude.Virus".    The archives can be found
        at http://www.mail-archive.com.
        

<<winmail.dat>>

Reply via email to