I'd say that this is definitely a lot faster to process at least, and I no longer am seeing NTVDM in Task Manager, typically achieving over 10% of my processing per call, no sign of avgscan.exe showing up at all.  Check out the time stamps:

----- 16-bit AVG as Scanner 2 -----
03/04/2004 06:38:30 Q153116df009a6d09 MIME file: yours.pif [base64; Length=17424 Checksum=1974125]
03/04/2004 06:38:30 Q153116df009a6d09 Banning file with PIF extension [application/octet-stream].
03/04/2004 06:38:30 Q153116df009a6d09 Scanner 1: Virus=W32/[EMAIL PROTECTED] Attachment=yours.pif [1] O
03/04/2004 06:38:33 Q153116df009a6d09 Scanner 2: Virus=I-Worm/Netsky.D Attachment=yours.pif [1] O

03/04/2004 06:38:33 Q153116df009a6d09 Invalid PIF Vulnerability
03/04/2004 06:38:33 Q153116df009a6d09 Found a bogus .pif file
03/04/2004 06:38:33 Q153116df009a6d09 File(s) are INFECTED [ W32/[EMAIL PROTECTED]: 6]
03/04/2004 06:38:33 Q153116df009a6d09 Scanned: CONTAINS A VIRUS [MIME: 2 17587]
03/04/2004 06:38:33 Q153116df009a6d09 From: [EMAIL PROTECTED] To: [EMAIL PROTECTED] [outgoing from 200.29.136.130]
03/04/2004 06:38:33 Q153116df009a6d09 Subject: Re: Here

03/04/2004 06:49:02 Q17a80b2d02820bfc MIME file: old_photos.txt.exe [base64; Length=30211 Checksum=2891900]
03/04/2004 06:49:02 Q17a80b2d02820bfc Banning file with EXE extension [application/octet-stream].
03/04/2004 06:49:02 Q17a80b2d02820bfc Scanner 1: Virus= W32/FunLove.4099 Attachment=old_photos.txt.exe [1] O
03/04/2004 06:49:05 Q17a80b2d02820bfc Scanner 2: Virus= I-Worm/Netsky.C Attachment=old_photos.txt.exe [1] O

03/04/2004 06:49:05 Q17a80b2d02820bfc File(s) are INFECTED [ W32/FunLove.4099: 6]
03/04/2004 06:49:05 Q17a80b2d02820bfc Scanned: CONTAINS A VIRUS [MIME: 2 30380]
03/04/2004 06:49:05 Q17a80b2d02820bfc From: [EMAIL PROTECTED] To: [EMAIL PROTECTED] [outgoing from 61.11.62.171]
03/04/2004 06:49:05 Q17a80b2d02820bfc Subject: notice!



----- 32-bit AVG as Scanner 2 -----
03/04/2004 20:21:22 Qd60f3d16013ccdd7 MIME file: [message/delivery-status][*DEFAULT*; Length=338 Checksum=29511]
03/04/2004 20:21:23 Qd60f3d16013ccdd7 MIME file: frank.htm [base64; Length=205439 Checksum=11285100]
03/04/2004 20:21:23 Qd60f3d16013ccdd7 Scanner 1: Virus=VBS/Lovelorn.dropper Attachment=frank.htm [1] I
03/04/2004 20:21:23 Qd60f3d16013ccdd7 Scanner 2: Virus=I-Worm/Lovelorn.dropper Attachment=frank.htm [1] I

03/04/2004 20:21:23 Qd60f3d16013ccdd7 File(s) are INFECTED [ VBS/Lovelorn.dropper: 6]
03/04/2004 20:21:24 Qd60f3d16013ccdd7 Scanned: CONTAINS A VIRUS [MIME: 4 206441]
03/04/2004 20:21:24 Qd60f3d16013ccdd7 From: <> To: [EMAIL PROTECTED] [incoming from 68.168.78.205]
03/04/2004 20:21:24 Qd60f3d16013ccdd7 Subject: Mail System Error - Returned Mail

03/04/2004 20:21:52 Qd62f045e02164ae7 MIME file: party.rtf.pif [base64; Length=22016 Checksum=2446937]
03/04/2004 20:21:52 Qd62f045e02164ae7 Banning file with PIF extension [application/octet-stream].
03/04/2004 20:21:52 Qd62f045e02164ae7 Scanner 1: Virus=W32/[EMAIL PROTECTED] Attachment=party.rtf.pif [1] I
03/04/2004 20:21:53 Qd62f045e02164ae7 Scanner 2: Virus=I-Worm/Netsky.B Attachment=party.rtf.pif [1] I

03/04/2004 20:21:53 Qd62f045e02164ae7 Invalid PIF Vulnerability
03/04/2004 20:21:53 Qd62f045e02164ae7 Found a bogus .pif file
03/04/2004 20:21:53 Qd62f045e02164ae7 File(s) are INFECTED [ W32/[EMAIL PROTECTED]: 6]
03/04/2004 20:21:53 Qd62f045e02164ae7 Scanned: CONTAINS A VIRUS [MIME: 2 22070]
03/04/2004 20:21:53 Qd62f045e02164ae7 From: [EMAIL PROTECTED] To: [EMAIL PROTECTED] [incoming from 208.250.84.162]
03/04/2004 20:21:53 Qd62f045e02164ae7 Subject: warning

03/04/2004 20:22:28 Qd6503d21013cce8e MIME file: ps.zip [base64; Length=35125 Checksum=4018378]
03/04/2004 20:22:29 Qd6503d21013cce8e Scanner 1: Virus=W32/[EMAIL PROTECTED] Attachment=ps.zip [1] O
03/04/2004 20:22:29 Qd6503d21013cce8e Scanner 2: Virus=I-Worm/Mydoom.F Attachment=ps.zip [1] O

03/04/2004 20:22:29 Qd6503d21013cce8e File(s) are INFECTED [ W32/[EMAIL PROTECTED]: 6]
03/04/2004 20:22:29 Qd6503d21013cce8e Scanned: CONTAINS A VIRUS [MIME: 2 37072]
03/04/2004 20:22:29 Qd6503d21013cce8e From: [EMAIL PROTECTED] To: [EMAIL PROTECTED] [outgoing from 24.58.252.43]
03/04/2004 20:22:29 Qd6503d21013cce8e Subject: Hshzkwl








R. Scott Perry wrote:

I should have read the previous message closer, so point the finger at me for jumping the gun totally.  The 32-bit version of avgscan.exe does in fact now work (this definitely wasn't the case earlier).  The switches for this should be modified when moving to the 32-bit version.  I'm not positive that all of this is necessary, but here's what I'm using after researching what they did.

SCANFILE2     C:\Progra~1\Grisoft\AVG7\avgscan.exe /NOMEM /NOBOOT /NOHIMEM /NOEXPORT /NOSELF /ARC /RT /ARCW /RTW /MACROW /REPORT=report.txt
VIRUSCODE2    5
VIRUSCODE2    6
REPORT2       identified

If others can agree on the best switches, this should probably be added to the Declude Virus manual.

This is good news.  :)

After this gets discussed, we'll add the configuration to the manual.

                                                   -Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask for a free 30-day evaluation.

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.



-- 
=====================================================
MailPure custom filters for Declude JunkMail Pro.
http://www.mailpure.com/software/
=====================================================


Reply via email to