I have been following the recent threads but I have not seen a definitive
answer.  Most likely because it is still so new (F-prot 3.14E).  Some help
would be greatly appreciated.

What about the /SERVER setting?  Any advantage to using it.

I am also a bit confused about the Viruscode settings.

I am using the defaults that you recommend
VIRUSCODE       3
VIRUSCODE       6
REPORT    Infection:

But I see others are adding

VIRUSCODE       8
OKCODE2         5

What value do they have if any?  I assume they must have some value or they
would not be using them (I Hope <g>).

Lastly where can I verify and find future info on which Viruses forge
headers.  This list was nicely supplied to me from someone on this list and
I have added it to my cfg.

FORGINGVIRUS    Klez
FORGINGVIRUS    Bagle
FORGINGVIRUS    Braid
FORGINGVIRUS    Bridex
FORGINGVIRUS    Bugbear
FORGINGVIRUS    Dumaru
FORGINGVIRUS    Fizzer
FORGINGVIRUS    Hybris
FORGINGVIRUS    Klez
FORGINGVIRUS    Lentin
FORGINGVIRUS    Magistr
FORGINGVIRUS    Mydoom
FORGINGVIRUS    Mimail
FORGINGVIRUS    Palyh
FORGINGVIRUS    Sober
FORGINGVIRUS    Sobig
FORGINGVIRUS    Vulnerability
FORGINGVIRUS    Yaha

Thanks

Doug




-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of R. Scott Perry
Sent: Thursday, March 18, 2004 1:13 PM
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus] Log error with latest interim release



>Scott,  your thoughts?

 From what I have seen, AV heuristics just don't do a good enough job to be 
useful.  Specifically, they seem to catch legitimate E-mails regularly 
(typically .doc/.xls files).  However, depending on your needs, it may be 
worthwhile to use the heuristics, if the occasional false positive is 
acceptable.

                                                    -Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers 
since 2000.
Declude Virus: Ultra reliable virus detection and the leader in mailserver 
vulnerability detection.
Find out what you've been missing: Ask for a free 30-day evaluation.

---
[This E-mail was scanned for viruses by Declude Virus
(http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To unsubscribe, just
send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.
---
[This E-mail scanned for viruses by Declude Virus]


---
[This E-mail scanned for viruses by Declude Virus]

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to