Will my old version of Declude work with the new version of Imail?
TIA,
Sharyn
---
This E-mail came from the Declude.JunkMail mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.JunkMail". The archives can be found
at http://www.mail-archive.co
Title: Declude and Imail 2006
Hi,
We are getting ready to upgrade to Imail 2006.
I am wondering if my older version of declude virus and junkmail (2.0.6) will work with Imail 2006?
Thanks,
Sharyn
---This E-mail came from the Declude.JunkMail mailing list. Tounsubscribe, just send
Title: Possible virus?
Anyone seen or heard of a virus that is sending out random power point attachments?
One of the attachments is called House_of_Golf.pps
Thanks,
Sharyn
Title: Correct path in virus config?
Hi,
I'm going to be using a different version of McAfee Virus Scan software. This version is VS80i.
It looks like the command line scanner installs in a different location then the old version (4.0) that I was using.
Can someone verify for me that th
Title: Message
I’ll see that you are
taken off the lists as soon as our email administer comes in. Thanks for
the report. We’ll fix the problem with unsubscribe as
well.
Have a great
vacation!
Thanks
Bill!
See you all
when I return!
Shary
Title: U can check out but you can never leave
Sorry to interrupt with a non technical post but…
I have tried 3 times already to unsubscribe from this list.
I get the confirmation request, I send it off, but I never receive notification that I've been unsubscribed.
Then, I get more emai
Title: Virus notifications from local host
Hi,
I have Declude set to send me an email notification when it has quarrantined an email containing a virus, using this variable:
From: [EMAIL PROTECTED]
I have since changed my OHN in IMAIL.
The notification still has the old OHN
It's com
Title: Possible official host name change
Declude folks…
If I change the official host name on my mailserver, I am going to need a new activation key for junkmail and virus (I'm assuming).
How do I go about getting this?
Thanks,
Sharyn
After 4 years of hard work and little sleep Scott Perry has decided to move
away from customer facing activities with Declude and will be spending more
of his time working with the Red Cross.
Scott continues his commitment to Declude in an advisory role.
LOL! Now, folks, is this a BIG SHOCKER t
Zafi.d sends messages in different european languages having "christmas
content" (for example in Italian with the subject line "Buon natale")
We are getting HAMMERED by these but Declude/McAfee is catching them and
identifying them correctly, DAT 4414..
Declude Virus caught a virus with the sub
Title: Virus infection warnings
Scott?
At one time you were following up with mailservers that had Declude software installed, that were sending out these messages for forging viruses.
Anything you can do about this?
Thanks,
Sharyn
The Declude Virus software on fmmalaysia.com.my has
Title: V1.81?
I never installed 1.80 after reading some of the jpeg issues on this list.
Now, I see 1.81 is out.
Have the false positive issues been resolved?
I'm assuming there is no need to upgrade to 1.80 first before installing 1.81. Correct?
Thanks,
Sharyn
Title: Lines in the virus.cfg file
I was looking through my virus.cfg and I noticed the following:
# The SKIPEXT option will let you skip scanning of certain file extensions. For
# example, a GIF file can't contain a virus, so there is no need to scan it.
#
SKIPEXT GIF
SKIPEXT
Title: New release
Hi,
Due to a minor inconvenience called Hurricane Jeanne, we have been offline for about 5 days now.
Can someone please tell me when the newest release was available for download?
Thanks,
Sharyn
And no, it was not my wife. I am genetically prone to bloody noses in dry
weather. This week, the average humidity in Southern California has been
around 15%.
Gee, come to Florida where we are about to be hit with our FOURTH hurricane
in about 6 weeks, lots of rain and humidity here!
Sharyn
W
server and have users check mail direct from the
backup as far as I know you would need a second license for
declude.
Jim Matuska Jr.Computer Tech
IICCNANez Perce TribeInformation Systems[EMAIL PROTECTED]
- Original Message -
From:
Sharyn
Schmidt
Title: Second mail server
Scott,
Am I to assume that if I configure a backup mailserver I will need to purchase another full license for the Declude products?
Thanks,
Sharyn
Title: OT: Hello?
I haven't rec'd anything from either of these lists today?
Sharyn
Thanks!
We are patched.
Sharyn
We are the worldwide producer and marketer of the award winning Cruzan
Single Barrel Rum, judged "Best in the World" at the annual
San Francisco Wine and Spirits Championships. For
more information, please click (go to) http://www.cruzanrums.com";>www.cruzanrums.c
Title: OT- Anyone know about this latest "attack" reported by CNN?
Here is what CNN says:
http://www.cnn.com/2004/TECH/internet/06/24/internet.attack.ap/index.html
Sharyn
Title: Message
http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=100715
Got it, thanks.
I'm apparantly a bit brain dead this morning.
:)
Sharyn
Title: Exploit-ObjectData trojan
Forgive me , I've been out of the loop, working on other things.
What is this Exploit-ObjectData trojan?
I can't seem to find mention of it on McAfee's website and Declude is nabbing them like crazy.
Thanks in advance,
Sharyn
W32/[EMAIL PROTECTED] virus
Aww, c'mon "NewWorm" has a nice ring to it.
Sharyn
We are the worldwide producer and marketer of the award winning Cruzan
Single Barrel Rum, judged "Best in the World" at the annual
San Francisco Wine and Spirits Championships. For
more information, please click (g
Title: Message
Are you talking about
the creators or the users who open them anyways?
LOL! I was talking about the creators, however, if the
shoe fits.
Sharyn
Title: I've officially given up
As of 11:19am, today, I am stripping ZIPs at the firewall. I've had 3 of these new passworded varients make it to my users' inboxes. Fortunately they were all savy enough not to open them. I won't be so lucky next time!
Makes you wonder what sort of people hav
Title: Message
I can also recommend
snort. There is a full windows version put out by
Engagesecurity.com The product is called EagleX and is a single
install of all needed components for Snort to operate on a Windows
platform.
For those of you running Snort, please give me wha
Yes, I saw that. I am not familiar with peering, sorry.
LOL neither am I which why I don't have a clue how it got turned out.
Anyway, all's well that ends well.
Sharyn
We are the worldwide producer and marketer of the award winning Cruzan
Single Barrel Rum, judged "Best in the World" at the a
Title: Non bouncingto non users..FIXED
Answer/Solution: If IMail says 'OK, accepted for peer' and you are not currently using any additional IMail servers with the Peering feature, here is the fix: run regedit. Go to:
HKEY_LOCAL_MACHINE\SOFTWARE\Ipswitch\IMail\Domains\your-domain
Delete the V
John..look at this from my message to the IMAIL group:
I telnetted to my mail server from my desktop, bypassing the firewall
and everything else
220 todhunter.com (IMail 7.15 7868-2) NT-ESMTP Server X1
helo
250 hello todhunter.com
mail from:<[EMAIL PROTECTED]>
250 ok
rcpt to:<[EMAIL PROTECTED]>
2
What is the flavor? I hope you do not have the IP of that firewall in
the Imail SMTP relay for addresses.
It's a Watchguard Firebox 3 and the IMAIL server sits on what the
Watchguard people call the Optional Interface but what I would call the
DMZ.
If all mail passes through the Firebox smtp prox
This is expected in a gateway configuration.
And yes, I feel like an @ss for not thinking of the smtp proxy on the
firewall as the culprit sooner...so please, be gentle..no flames
Sharyn
We are the worldwide producer and marketer of the award winning Cruzan
Single Barrel Rum, judged "Best i
Sharyn, I am trying to help you find out what is wrong.
I know you are ..I am not being obtuse (or dishonest) on purpose,
honest.
I thought you stated before you are not using a gateway, that e-mail is
received directly by the Imail server where the mail boxes are.
And the lightbulb goes off. M
--
Henry H. Isgett, MCSE
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Sharyn Schmidt
Sent: Tuesday, January 27, 2004 11:24 AM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] MyDoom going to non existent users
Ok, maybe I'm reading the mail logs wrong...here is the behavi
Sharyn, what exactly does the Qbacc08dd025a52a7.SMD file say?
QD:\IMAIL\spool\Dbacc08dd025a52a7.SMD
Htodhunter.com
WD:\IMAIL
E0,
R<[EMAIL PROTECTED]>
S<[EMAIL PROTECTED]>
NRCPT TO:<[EMAIL PROTECTED]>
R<[EMAIL PROTECTED]>
The masterbackup address is the email address used for the copy all mail
Title: Deleting quarrantined viruses
Due to the overwhelming amount of MyDoom quarrantines, my virus folder is huge.
I know this has been addressed, sorry, but can I just delete what is in there?
Sharyn
To all that are having this problem. Please check the Q file to see if
there is at least one valid user listed.
We are required by federal law, due to the nature of our business, to
keep copies of all email received so we use the copy all function in
IMAIL, sending every email received to a mast
Title: Message
If they
don't exist how are you receiving them? Do you have nobody alias?
Ok Folks, color me stupid but wouldn't the nobody
alias be located in the "Alias"
folder?
If this is the case, then the mysterious nobody is
non existant and I still don't have a clue why these em
Title: Message
If they
don't exist how are you receiving them? Do you have nobody alias?
I've always wondered
that myself.
Perhaps you want to deactivate it for the duration
of this virus frenzy..
I will deactivate it permanently if I can find the freaking
thing.
Tha
Title: MyDoom going to non existant users
Over 1/2 the MyDoom emails we are receiving are being sent to users that don't even exist, as in, [EMAIL PROTECTED]
Is anyone else seeing this and is there any way to stop these emails before all the scanning is done on them?
Sharyn
Todhunter Firewall. Have sender deliver to [EMAIL PROTECTED] and CC: you. Contact Network Administrator (Sharyn Schmidt) for message retrieval.]
It will be done automatically. :)
Why isn't all software this easy to use??!!!
Thanks,
Sharyn
We are the worldwide producer and marketer of the award winning Cruzan
Single Barrel Rum, judged "Best in the World" at the annual
San Francisco W
Title: Virtual domains
I have just added a virtual domain (my first, so please bear with me!).
I want to make sure both JM and Virus are scanning mail on the virtual domain.
Is there any special configuration I need or will it do it automatically, as it's using the same mail server?
Tha
Title: Message
Not a single person in the domains hosted on our server has received a
single incident.
Kami,
If it makes you
feel any better, I am getting approximately 40 to 50 of these a day, while the
rest of my users, combined, have received no more than 20.
Sharyn
Title: This in from my local newspaper
Looks like someone is busy writing a trojan that takes advantage of the security flaw that MS announced last week..
http://ap.polkonline.com/pstories/technology/20030916/1468801.shtml
Sharyn
You can download it here http://www.csonline.net/imailstuff/viruslog.htm
It *is* my day for dumb questions, or perhaps it's a tribute to Declude
virus that I haven't had to touch the config file since the day I
installed it. After changing the loglevel to MID to use this tool, does
anything need
> vir0819.log 437 437
> vir0820.log 2,939 2,939
> vir0821.log 3,937 3,937
> vir0822.log 2,755 2,755
> vir0823.log 275 275
> vir0824.log 91 91
> vir0825.log 8,525
I'm running McAfee NetShield on the servers, where I can exclude certain
folders, e.g., the Imail Spool folder tree.
I am too, with the IMAIL directory excluded, and haven't
had any problems with either Declude or infections on the mail server
itself.
And, FYI, McAfee was catching the Mimail vi
Title: Message
This
is what I'm getting..
The IP address of the offending server is
12.154.100.6
The name of the virus is [Unknown: Err].
The attachment is the Exploit-CodeBase trojan !!!
Sharyn
Feel free to send it to [EMAIL PROTECTED] (just be sure to let me
know
after you send it, as that mailbox isn't monitored).
-Scott
Guess we are all curious now as to what it is.
Sharyn
We are the worldwide producer and marketer of the awar
You can go to http://www.declude.com/virus/manual.htm and look at the
latest .eml files, which include the settings that we recommend (such as
not sending the notifications to the senders of the Klez virus).
-Scott
:)
That's where I was looking when I realized there
Thanks, Scott, last question for the day...
Can I use the SKIPIFVIRUSNAMEHAS on a vulnerability?
As in, add a line that says.
SKIPIFVIRUSNAMEHAS Vulnerability (provided I spell it correctly which
I'm not sure I did here)
I set up the .eml options a really LONG time ago
Yes, unless you add the SKIPIF line.
Is there any way to skip sending the notification to a particular
address, as opposed to a virus name?
Sharyn
We are the worldwide producer and marketer of the award winning Cruzan
Single Barrel Rum, judged "Best in the World" at the annual
San Francisco Wi
Afternoon,
I am curious, does Declude send out the sender.eml message when it
catches a vulnerability as opposed to a virus?
Thanks,
Sharyn
We are the worldwide producer and marketer of the award winning Cruzan
Single Barrel Rum, judged "Best in the World" at the annual
San Francisco Wine and
(reader's digest version is
fine)
TIA,
Sharyn Schmidt
Network Administrator
Florida Distillers Company
(863) 956-1116 x221
We are the worldwide producer and marketer of the award winning Cruzan
Single Barrel Rum, judged "Best in the World" at the annual
San Francisco Wine
global.cfg
---
frndgrt filter d:\imail\declude\frndgrt.txt x 0 0
$default$.junkmail
-
frndgrt BOUNCE
frndgrt.txt
-
BODY0 CONTAINSF r i e n d - G r e e t i n g s . c o m
(without the spaces)
Thanks! This is exact
<>
Exactly. That sort of set up is only good for a small business like mine
where everyone is forced to authenticate through my firewall before
going out to the web, and doesn't help anyone who doesn't have a
firewall, or doesn't have control of theirs.
Thanks for not flaming! :)
Sharyn
We
<>
At the risk of getting flamed for mentioning something that is somewhat
off topic in regard to this, I am blocking friendcard.com with the http
proxy on my firewall.
No, that doesn't prevent the email with the link from coming in, but it
sure as heck prevents my users from clicking on it and
I havent received mail from the IMAIL list in about 2 days. Is the list
down?
Sharyn
We are the worldwide producer and marketer of the award winning Cruzan
Single Barrel Rum, judged "Best in the World" at the annual
San Francisco Wine and Spirits Championships, and the
artisan tequilas of Porf
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of R. Scott Perry
Sent: Monday, February 18, 2002 4:24 PM
To: [EMAIL PROTECTED]
<>>
I have checked the dates..they are all back from last July. I seem to
remember having some sort of problem with the on acc
In my IMAIL spool folder, I have a bunch of .vir subfolders, such as
Dc29c2b4.vir. I am assuming these were viruses that were nabbed by
Declude and sent to a quarrantine folder.
Can these just be deleted?
Thanks,
Sharyn Schmidt
Network Specialist
Florida Distillers Company
(863) 956-1116
I have excluded the imail directory from any on access scan.
I am looking at the old setup, on the server that was running mail and
declude and netshield and it's set up the exact same way.
I'll be happy to email you my virus.cfg and logs. You want me to send
them to this address or email you o
Looking at the virus log, it looks like Declude is running, but
everything is being passed off as virus free.
Sharyn
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of R. Scott Perry
Sent: Thursday, February 14, 2002 5:41 PM
To: [EMAIL PROTECTED]
Subject:
sed to get.
The Official Host name is the same, I copied over the whole Imail
directory, including the Declude folder and declude.exe. I launched the
declude.exe file.
Is there something else I need to do?
Sharyn Schmidt
Network Specialist
Florida Distillers Company
(863) 956-1116 x139
And some of us have been at this for awhile and are STILL making
mistakes :)
Sharyn Schmidt
Network Specialist
Florida Distillers Company
(863) 956-1116 x139
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of Sheldon Koehler
Sent: Friday, December
x27;t have gotten past the mail server once it hit my network but
somehow it did. I am running Netshield (and Declude) on my mail server
with the latest scan engine and DAT file, and up until now, the latest
Badtrans was being caught.
Thanks!
Sharyn Schmidt
Network Specialist
Florida Distille
I have my entire IMAIL directory excluded, with the option to include
subfolders checked.
It's working fine for me.
Sharyn
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of R. Scott Perry
Sent: Friday, October 12, 2001 1:01 PM
To: [EMAIL PROTECTED]
Subje
No, I have the "on access" protection turned OFF for the whole Imail
directory as this seemed to be causing a problem when I had it turned
on.
I have the default Declude time out set..I didn't mess with this setting
at all.
Sharyn
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAI
ober 08, 2001 11:50 AM
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus] Magstr.39921
Hi Sharyn,
What av are you using with Declude ?
- Original Message -----
From: "Sharyn Schmidt" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Monday, October 08, 2001 3:41 PM
Su
Hmmm
I'm using the Declude/McAfee Netshield setup and mine caught it,
complete with email notification that I had received a virus,
etc...wonder if I just got lucky :)
Sharyn
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of Rick Rountree
Sent: Monda
The Declude installed on my mail server nabbed this :)
Sharyn
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of Dan Spangenberg
Sent: Monday, October 08, 2001 11:37 AM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] Magstr.39921
I received this messa
Ok, so..we delete them manually?
I agree..I don't see any reason to save them if they really contain a
virus. Is there a certain time period that it's "safe" to get rid of
these?
Sharyn
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of R. Scott Perry
Se
PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Sharyn Schmidt
Sent: Tuesday, September 25, 2001 7:54 AM
To: [EMAIL PROTECTED]
Subject: [Declude.Virus] Virus notifications
Scott,
Up until now, I have been getting the Declude email notifications that a
virus was received on blah blah date, blah blah
It's possible. I thought of that too, but I don't understand why this
would suddenly just start happening...and..I thought Declude scanned it
first?
Obviously I need a Sequence 101 tutorial on what exactly does what
first. I have only been using Declude for about 6 weeks now and am still
learning
I got the email notifications from
Declude.
Any clue as to why I'm not getting the email notifications each time I'm
receiving a virus? As far as I know, nothing in my configuration has
changed.
Thanks,
Sharyn Schmidt
Network Specialist
Florida Distillers Company
(863) 956-1116 x1
Ok Scott,
Please forgive me for being stupid, but in the manual on the Declude
website, it said something about making sure that Netshield is
creating/saving a report file in the same directory as the scanner is
operating from? Does it do that by default?
I think this is where I'm having some c
But don't I have to do some configuration with Netshield itself
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of R. Scott Perry
Sent: Monday, July 30, 2001 2:47 PM
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus] %virusname% and %virusfile%
>I am
ld logs to, to report.txt, but
after looking at the file itself, it doesnt seem to contain the proper
information.
Thanks in advance for your help!
Sharyn Schmidt
Network Specialist
Florida Distillers Company
(863) 956-1116 x139
We are the worldwide producer and marketer of the award winn
OK..
I think you hit it Scott.
The one that was missed, is the only one so far, that has come through
with the .doc.com extension. Everything else has come with the .pif. My
guess would be that Mcaffee saw the .doc extension and just quit
scanning.
Just goes to show that even with all the best/
Yes! I checked the log and everything seems to be working fine. The
email came through as "virus free", however, the day before Declude
nabbed it, and has been nabbing it.
I'm not sure what Roger means by this..
We had one sneak in for the first time this last week as well. We know
it happened b
I had one today sneak in..fortunately the user didn't recognize the
sender and was smart enough to delete the email.
The Declude/McAfee setup has been catching this virus left and right. I
don't have a clue why all of a sudden it would let this one in.
Sharyn Schmidt
Network Speciali
80 matches
Mail list logo