Matt
I've been told if you have sniffer running and you block SNF RETURN CODE
049 AND 055 you block most virus's.
I ended up putting different weights for the return codes years ago.
I score them high enough to delete on weight only and as well delete on
the names
Here is my setup from global config

#  NAME                TEST      CODE                   FILE LOCATION
WEIGHT
SNIFFER-SURE            external    020
"D:\IMail\declude\Sniffer3.0\SNFClient.exe"                     30
0
SNIFFER-SUSPECT         external    040
"D:\IMail\declude\Sniffer3.0\SNFClient.exe"                     8
0
SNIFFER-TRAVEL          external        047
"D:\IMail\declude\Sniffer3.0\SNFClient.exe"                     18
0
SNIFFER-INSURANCE             external  048
"D:\IMail\declude\Sniffer3.0\SNFClient.exe"                     18
0
SNIFFER-AV-PUSH               external  049
"D:\IMail\declude\Sniffer3.0\SNFClient.exe"                     40
0
SNIFFER-WAREZ           external        050
"D:\IMail\declude\Sniffer3.0\SNFClient.exe"                     18
0
SNIFFER-SPAMWARE              external  051
"D:\IMail\declude\Sniffer3.0\SNFClient.exe"                     20
0
SNIFFER-SNAKEOIL              external  052
"D:\IMail\declude\Sniffer3.0\SNFClient.exe"                     18
0
SNIFFER-SCAMS           external        053
"D:\IMail\declude\Sniffer3.0\SNFClient.exe"                     20
0
SNIFFER-PORN            external        054
"D:\IMail\declude\Sniffer3.0\SNFClient.exe"                     20
0
SNIFFER-MALWARE               external  055
"D:\IMail\declude\Sniffer3.0\SNFClient.exe"                     40
0
SNIFFER-ADVERTISING     external        056
"D:\IMail\declude\Sniffer3.0\SNFClient.exe"                     18
0
SNIFFER-SCHEME          external        057
"D:\IMail\declude\Sniffer3.0\SNFClient.exe"                     18
0
SNIFFER-CREDIT          external        058
"D:\IMail\declude\Sniffer3.0\SNFClient.exe"                     18
0
SNIFFER-GAMBLING              external  059
"D:\IMail\declude\Sniffer3.0\SNFClient.exe"                     18
0
SNIFFER-GREYMAIL              external  060
"D:\IMail\declude\Sniffer3.0\SNFClient.exe"                     18
0
SNIFFER-EXPERIMENTAL    external        061
"D:\IMail\declude\Sniffer3.0\SNFClient.exe"                     18
0
SNIFFER-OBFUSCATION     external        062
"D:\IMail\declude\Sniffer3.0\SNFClient.exe"                     18
0
SNIFFER-IP-RULES              external  063
"D:\IMail\declude\Sniffer3.0\SNFClient.exe"                     18
0

Here is a simple version of the above (it does not address the virus
issue) but it's easy to get going

 FROM PETE MCNEAL ON 3/14/2013
#
SNIFFER                 external        nonzero
"D:\IMail\declude\Sniffer3.0\SNFClient.exe"                     20
0
SNFTruncate             external        20
"D:\IMail\declude\Sniffer3.0\SNFClient.exe"                     5
0
SNFCaution              external        40
"D:\IMail\declude\Sniffer3.0\SNFClient.exe"                    -10
0


I installed clamwin and added this to my virus config file
After installing change the file locations to yours and give it a try.
There are 2 lines (in case this wraps) the second line begins VIRUSCODE
1

#CLAMSCAM USED BY US SCANFILE1 C:\Progra~1\ClamWin\bin\clamscan.exe --verbose
--database=D:\IMail\Declude\Scanners\ClamAV\db
--tempdir=D:\IMail\spool\proc\work --no-summary -l report.txt
VIRUSCODE 1

I have not had a single hit as I scan after after sniffer using
"AVAFTERJM   ON" in virus config.

Hope this helps

John





-----Original Message-----
From: SM Admin [mailto:imailad...@bcwebhost.net]
Sent: Wednesday, April 17, 2013 12:05 PM
To: Declude.JunkMail@declude.com
Subject: Re: [Declude.JunkMail] ***DECLUDE NO-AUTHENTICATION KEY***

So what needs to be done with ClamAV?

-----Original Message-----
From: Matt
Sent: Wednesday, April 17, 2013 11:24 AM
To: Declude.JunkMail@declude.com
Subject: [Declude.JunkMail] ***DECLUDE NO-AUTHENTICATION KEY***

It seems clear at this point that the failure of Declude's licensing
system is causing widespread havoc for their customers, and they are not
responding to support issues, or any issues at all, and that they are in
fact out of business.  Therefore I am going to share the key that allows
Declude to operate without authentication.  This key will not allow
either AVG nor Commtouch Zero Hour to work, but it will allow Declude to
process email with filters and other add-ons.

The key goes in your Declude.cfg file and it requires a restart. This is
the same key that was shared, but I am changing the subject in order to
highlight that the code is in here:

     CODE        28607230-BF21-4CDE-A59B-A451CC7C9CA0

My recommendation is to configure both Sniffer (convert your license
with Pete if it was bound to Declude) and ClamAV so that you have virus
protection.

Matt



---
This E-mail came from the Declude.JunkMail mailing list.  To
unsubscribe, just send an E-mail to imail...@declude.com, and type
"unsubscribe Declude.JunkMail".  The archives can be found at
http://www.mail-archive.com.




---
This E-mail came from the Declude.JunkMail mailing list.  To
unsubscribe, just send an E-mail to imail...@declude.com, and type
"unsubscribe Declude.JunkMail".  The archives can be found at
http://www.mail-archive.com.



---
This E-mail came from the Declude.JunkMail mailing list.  To
unsubscribe, just send an E-mail to imail...@declude.com, and
type "unsubscribe Declude.JunkMail".  The archives can be found
at http://www.mail-archive.com.

Reply via email to