Actually this breaks Declude because Declude Virus can't look for multiple
REPORT lines.

Scott,
How can we setup Declude Virus to look for multiple lines in the report.txt
file?

Mark

> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED] On Behalf Of Mark Smith
> Sent: Saturday, September 25, 2004 2:49 AM
> To: [EMAIL PROTECTED]
> Subject: [Declude.Virus] Fprot GDI Scanner lines.
>
> Just did some testing with the POC and noticed that Fprot now
> is adding a new line to the report.txt:
>
> e:\imail\test\poc.jpg  Contains the exploit named W32/[EMAIL PROTECTED]
>
> So I had to add the line:
>
> REPORT                Contains the exploit named
>
> To my virus.cfg file.
>
> My complete setup for F-Prot is now:
>
> SCANFILE      c:\progra~1\fsi\f-prot\FPcmd.exe /TYPE /SILENT /NOMEM
> /ARCHIVE=5 /NOBOOT /DUMB /SERVER /REPORT=report.txt
> VIRUSCODE     3
> VIRUSCODE     6
> VIRUSCODE     8
> REPORT                Infection:
> REPORT                Contains the exploit named
>
>
>
> ---
> [This E-mail was scanned for viruses by Declude Virus
> (http://www.declude.com)]
>
> ---
> This E-mail came from the Declude.Virus mailing list.  To
> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
> type "unsubscribe Declude.Virus".    The archives can be found
> at http://www.mail-archive.com.
>


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to