RE: [Declude.Virus] exe in zip file why not blocked...

2007-07-30 Thread David Barker
Scott,

 

What version of Declude ?

 

Are you using the directive AVAFTERJM  ON?

 

David

 

From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Scott
Fisher
Sent: Friday, July 27, 2007 3:06 PM
To: declude.virus@declude.com
Subject: [Declude.Virus] exe in zip file why not blocked...

 

I was looking at my spam folder and noticed an email with a zip that
contained an exe.

 

07/27/2007 11:10:14.234 q18d4010e464c.smd Vulnerability flags = 862

07/27/2007 11:10:14.234 q18d4010e464c.smd MIME file: fungame.zip
[base64; Length=19363 Checksum=2473579]

07/27/2007 11:10:17.749 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:20.390 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:23.015 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:25.640 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:28.374 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:30.374 q18d4010e464c.smd Could not find parse string
Found in report.txt

07/27/2007 11:10:30.374 q18d4010e464c.smd Error 8 in virus scanner 2.

07/27/2007 11:10:30.374 q18d4010e464c.smd Scanned: Error in virus
scanner. [MIME: 2 19668]

 

virus.cfg lines:

BANEXTexe

BANZIPEXTS ON

 

I believe this should have been blocked (regardless of the problem with
scanner 2).

 

Scott Fisher

Dir of IT

Farm Progress Companies

191 S Gary Ave

Carol Stream, IL 60188

Tel: 630-462-2323

 

This email message, including any attachments, is for the sole use of the
intended recipient(s) and may contain confidential and privileged
information. Any unauthorized review, use, disclosure or distribution is
prohibited. If you are not the intended recipient, please contact the sender
by reply email and destroy all copies of the original message. Although Farm
Progress Companies has taken reasonable precautions to ensure no viruses are
present in this email, the company cannot accept responsibility for any loss
or damage arising from the use of this email or attachments.

 


---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com. 



---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.

RE: [Declude.Virus] exe in zip file why not blocked...

2007-07-30 Thread Scott Fisher
Declude 4.3.57

 

AVAFTERJM ON YES.

 

 

 

-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of David
Barker
Sent: Monday, July 30, 2007 7:48 AM
To: declude.virus@declude.com
Subject: RE: [Declude.Virus] exe in zip file why not blocked...

 

Scott,

 

What version of Declude ?

 

Are you using the directive AVAFTERJM  ON?

 

David

 

From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Scott
Fisher
Sent: Friday, July 27, 2007 3:06 PM
To: declude.virus@declude.com
Subject: [Declude.Virus] exe in zip file why not blocked...

 

I was looking at my spam folder and noticed an email with a zip that
contained an exe.

 

07/27/2007 11:10:14.234 q18d4010e464c.smd Vulnerability flags = 862

07/27/2007 11:10:14.234 q18d4010e464c.smd MIME file: fungame.zip
[base64; Length=19363 Checksum=2473579]

07/27/2007 11:10:17.749 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:20.390 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:23.015 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:25.640 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:28.374 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:30.374 q18d4010e464c.smd Could not find parse string
Found in report.txt

07/27/2007 11:10:30.374 q18d4010e464c.smd Error 8 in virus scanner 2.

07/27/2007 11:10:30.374 q18d4010e464c.smd Scanned: Error in virus
scanner. [MIME: 2 19668]

 

virus.cfg lines:

BANEXTexe

BANZIPEXTS ON

 

I believe this should have been blocked (regardless of the problem with
scanner 2).

 

Scott Fisher

Dir of IT

Farm Progress Companies

191 S Gary Ave

Carol Stream, IL 60188

Tel: 630-462-2323

 

This email message, including any attachments, is for the sole use of the
intended recipient(s) and may contain confidential and privileged
information. Any unauthorized review, use, disclosure or distribution is
prohibited. If you are not the intended recipient, please contact the sender
by reply email and destroy all copies of the original message. Although Farm
Progress Companies has taken reasonable precautions to ensure no viruses are
present in this email, the company cannot accept responsibility for any loss
or damage arising from the use of this email or attachments.

 


---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com. 


---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com.


---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.


RE: [Declude.Virus] exe in zip file why not blocked...

2007-07-30 Thread David Barker
AVAFTERJM  ON means if the email reaches the JM either HOLD or DELETE to not
call the AV in the Declude code. Try switching this OFF to see if it
resolves the issue.


David

 

From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Scott
Fisher
Sent: Monday, July 30, 2007 10:27 AM
To: declude.virus@declude.com
Subject: RE: [Declude.Virus] exe in zip file why not blocked...

 

Declude 4.3.57

 

AVAFTERJM ON YES.

 

 

 

-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of David
Barker
Sent: Monday, July 30, 2007 7:48 AM
To: declude.virus@declude.com
Subject: RE: [Declude.Virus] exe in zip file why not blocked...

 

Scott,

 

What version of Declude ?

 

Are you using the directive AVAFTERJM  ON?

 

David

 

From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Scott
Fisher
Sent: Friday, July 27, 2007 3:06 PM
To: declude.virus@declude.com
Subject: [Declude.Virus] exe in zip file why not blocked...

 

I was looking at my spam folder and noticed an email with a zip that
contained an exe.

 

07/27/2007 11:10:14.234 q18d4010e464c.smd Vulnerability flags = 862

07/27/2007 11:10:14.234 q18d4010e464c.smd MIME file: fungame.zip
[base64; Length=19363 Checksum=2473579]

07/27/2007 11:10:17.749 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:20.390 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:23.015 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:25.640 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:28.374 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:30.374 q18d4010e464c.smd Could not find parse string
Found in report.txt

07/27/2007 11:10:30.374 q18d4010e464c.smd Error 8 in virus scanner 2.

07/27/2007 11:10:30.374 q18d4010e464c.smd Scanned: Error in virus
scanner. [MIME: 2 19668]

 

virus.cfg lines:

BANEXTexe

BANZIPEXTS ON

 

I believe this should have been blocked (regardless of the problem with
scanner 2).

 

Scott Fisher

Dir of IT

Farm Progress Companies

191 S Gary Ave

Carol Stream, IL 60188

Tel: 630-462-2323

 

This email message, including any attachments, is for the sole use of the
intended recipient(s) and may contain confidential and privileged
information. Any unauthorized review, use, disclosure or distribution is
prohibited. If you are not the intended recipient, please contact the sender
by reply email and destroy all copies of the original message. Although Farm
Progress Companies has taken reasonable precautions to ensure no viruses are
present in this email, the company cannot accept responsibility for any loss
or damage arising from the use of this email or attachments.

 


---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com. 


---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com. 
---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com. 



---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.

RE: [Declude.Virus] exe in zip file why not blocked...

2007-07-30 Thread John T \(lists\)
David, the log snipped posted is of the Declude Virus log, meaning it passed
Junkmail and was scanned.

 

John T

 

From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of David
Barker
Sent: Monday, July 30, 2007 9:24 AM
To: declude.virus@declude.com
Subject: RE: [Declude.Virus] exe in zip file why not blocked...

 

AVAFTERJM  ON means if the email reaches the JM either HOLD or DELETE to not
call the AV in the Declude code. Try switching this OFF to see if it
resolves the issue.


David

 

From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Scott
Fisher
Sent: Monday, July 30, 2007 10:27 AM
To: declude.virus@declude.com
Subject: RE: [Declude.Virus] exe in zip file why not blocked...

 

Declude 4.3.57

 

AVAFTERJM ON YES.

 

 

 

-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of David
Barker
Sent: Monday, July 30, 2007 7:48 AM
To: declude.virus@declude.com
Subject: RE: [Declude.Virus] exe in zip file why not blocked...

 

Scott,

 

What version of Declude ?

 

Are you using the directive AVAFTERJM  ON?

 

David

 

From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Scott
Fisher
Sent: Friday, July 27, 2007 3:06 PM
To: declude.virus@declude.com
Subject: [Declude.Virus] exe in zip file why not blocked...

 

I was looking at my spam folder and noticed an email with a zip that
contained an exe.

 

07/27/2007 11:10:14.234 q18d4010e464c.smd Vulnerability flags = 862

07/27/2007 11:10:14.234 q18d4010e464c.smd MIME file: fungame.zip
[base64; Length=19363 Checksum=2473579]

07/27/2007 11:10:17.749 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:20.390 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:23.015 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:25.640 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:28.374 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:30.374 q18d4010e464c.smd Could not find parse string
Found in report.txt

07/27/2007 11:10:30.374 q18d4010e464c.smd Error 8 in virus scanner 2.

07/27/2007 11:10:30.374 q18d4010e464c.smd Scanned: Error in virus
scanner. [MIME: 2 19668]

 

virus.cfg lines:

BANEXTexe

BANZIPEXTS ON

 

I believe this should have been blocked (regardless of the problem with
scanner 2).

 

Scott Fisher

Dir of IT

Farm Progress Companies

191 S Gary Ave

Carol Stream, IL 60188

Tel: 630-462-2323

 

This email message, including any attachments, is for the sole use of the
intended recipient(s) and may contain confidential and privileged
information. Any unauthorized review, use, disclosure or distribution is
prohibited. If you are not the intended recipient, please contact the sender
by reply email and destroy all copies of the original message. Although Farm
Progress Companies has taken reasonable precautions to ensure no viruses are
present in this email, the company cannot accept responsibility for any loss
or damage arising from the use of this email or attachments.

 


---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com. 


---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com. 
---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com. 


---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com. 



---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.

Re: [Declude.Virus] exe in zip file why not blocked...

2007-07-30 Thread Matt

Dave,

His logs show however that the AV scanners were called, so this message 
didn't hit HOLD or DELETE.


Matt



David Barker wrote:


AVAFTERJM  ON means if the email reaches the JM either HOLD or DELETE 
to not call the AV in the Declude code. Try switching this OFF to see 
if it resolves the issue.



David

 

*From:* [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] *On Behalf Of 
*Scott Fisher

*Sent:* Monday, July 30, 2007 10:27 AM
*To:* declude.virus@declude.com
*Subject:* RE: [Declude.Virus] exe in zip file why not blocked...

 


Declude 4.3.57

 


AVAFTERJM ON YES.

 

 

 


-Original Message-
*From:* [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] *On Behalf Of 
*David Barker

*Sent:* Monday, July 30, 2007 7:48 AM
*To:* declude.virus@declude.com
*Subject:* RE: [Declude.Virus] exe in zip file why not blocked...

 


Scott,

 


What version of Declude ?

 


Are you using the directive AVAFTERJM  ON?

 


David

 

*From:* [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] *On Behalf Of 
*Scott Fisher

*Sent:* Friday, July 27, 2007 3:06 PM
*To:* declude.virus@declude.com
*Subject:* [Declude.Virus] exe in zip file why not blocked...

 

I was looking at my spam folder and noticed an email with a zip that 
contained an exe.


 


07/27/2007 11:10:14.234 q18d4010e464c.smd Vulnerability flags = 862

07/27/2007 11:10:14.234 q18d4010e464c.smd MIME file: fungame.zip 
[base64; Length=19363 Checksum=2473579]


07/27/2007 11:10:17.749 q18d4010e464c.smd Virus scanner 2 reports 
exit code of 8


07/27/2007 11:10:20.390 q18d4010e464c.smd Virus scanner 2 reports 
exit code of 8


07/27/2007 11:10:23.015 q18d4010e464c.smd Virus scanner 2 reports 
exit code of 8


07/27/2007 11:10:25.640 q18d4010e464c.smd Virus scanner 2 reports 
exit code of 8


07/27/2007 11:10:28.374 q18d4010e464c.smd Virus scanner 2 reports 
exit code of 8


07/27/2007 11:10:30.374 q18d4010e464c.smd Could not find parse 
string Found in report.txt


07/27/2007 11:10:30.374 q18d4010e464c.smd Error 8 in virus scanner 2.

07/27/2007 11:10:30.374 q18d4010e464c.smd Scanned: Error in virus 
scanner. [MIME: 2 19668]


 


virus.cfg lines:

BANEXTexe

BANZIPEXTS ON

 

I believe this should have been blocked (regardless of the problem 
with scanner 2).


 


Scott Fisher

Dir of IT

Farm Progress Companies

191 S Gary Ave

Carol Stream, IL 60188

Tel: 630-462-2323

 

/This email message, including any attachments, is for the sole use of 
the intended recipient(s) and may contain confidential and privileged 
information. Any unauthorized review, use, disclosure or distribution 
is prohibited. If you are not the intended recipient, please contact 
the sender by reply email and destroy all copies of the original 
message. Although Farm Progress Companies has taken reasonable 
precautions to ensure no viruses are present in this email, the 
company cannot accept responsibility for any loss or damage arising 
from the use of this email or attachments./


 



---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com.


---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com.
---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com.


---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com. 



---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.

RE: [Declude.Virus] exe in zip file why not blocked...

2007-07-30 Thread David Barker
John I saw that, but I am not sure how much of the virus code is executed
once the JM threshold is met.


David

 

From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of John T
(lists)
Sent: Monday, July 30, 2007 12:55 PM
To: declude.virus@declude.com
Subject: RE: [Declude.Virus] exe in zip file why not blocked...

 

David, the log snipped posted is of the Declude Virus log, meaning it passed
Junkmail and was scanned.

 

John T

 

From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of David
Barker
Sent: Monday, July 30, 2007 9:24 AM
To: declude.virus@declude.com
Subject: RE: [Declude.Virus] exe in zip file why not blocked...

 

AVAFTERJM  ON means if the email reaches the JM either HOLD or DELETE to not
call the AV in the Declude code. Try switching this OFF to see if it
resolves the issue.


David

 

From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Scott
Fisher
Sent: Monday, July 30, 2007 10:27 AM
To: declude.virus@declude.com
Subject: RE: [Declude.Virus] exe in zip file why not blocked...

 

Declude 4.3.57

 

AVAFTERJM ON YES.

 

 

 

-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of David
Barker
Sent: Monday, July 30, 2007 7:48 AM
To: declude.virus@declude.com
Subject: RE: [Declude.Virus] exe in zip file why not blocked...

 

Scott,

 

What version of Declude ?

 

Are you using the directive AVAFTERJM  ON?

 

David

 

From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Scott
Fisher
Sent: Friday, July 27, 2007 3:06 PM
To: declude.virus@declude.com
Subject: [Declude.Virus] exe in zip file why not blocked...

 

I was looking at my spam folder and noticed an email with a zip that
contained an exe.

 

07/27/2007 11:10:14.234 q18d4010e464c.smd Vulnerability flags = 862

07/27/2007 11:10:14.234 q18d4010e464c.smd MIME file: fungame.zip
[base64; Length=19363 Checksum=2473579]

07/27/2007 11:10:17.749 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:20.390 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:23.015 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:25.640 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:28.374 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:30.374 q18d4010e464c.smd Could not find parse string
Found in report.txt

07/27/2007 11:10:30.374 q18d4010e464c.smd Error 8 in virus scanner 2.

07/27/2007 11:10:30.374 q18d4010e464c.smd Scanned: Error in virus
scanner. [MIME: 2 19668]

 

virus.cfg lines:

BANEXTexe

BANZIPEXTS ON

 

I believe this should have been blocked (regardless of the problem with
scanner 2).

 

Scott Fisher

Dir of IT

Farm Progress Companies

191 S Gary Ave

Carol Stream, IL 60188

Tel: 630-462-2323

 

This email message, including any attachments, is for the sole use of the
intended recipient(s) and may contain confidential and privileged
information. Any unauthorized review, use, disclosure or distribution is
prohibited. If you are not the intended recipient, please contact the sender
by reply email and destroy all copies of the original message. Although Farm
Progress Companies has taken reasonable precautions to ensure no viruses are
present in this email, the company cannot accept responsibility for any loss
or damage arising from the use of this email or attachments.

 


---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com. 


---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com. 
---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com. 


---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com. 


---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com. 



---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.

RE: [Declude.Virus] exe in zip file why not blocked...

2007-07-30 Thread Scott Fisher
I'm not sure my server can take the performance hit of putting AVAFTERJM to
OFF.

 

I reforwarded the message through and it was caught.

So I'm working on the assumption my Virusscan problems were messing things
up. I've disabled Viruscan.

 

-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of David
Barker
Sent: Monday, July 30, 2007 11:24 AM
To: declude.virus@declude.com
Subject: RE: [Declude.Virus] exe in zip file why not blocked...

 

AVAFTERJM  ON means if the email reaches the JM either HOLD or DELETE to not
call the AV in the Declude code. Try switching this OFF to see if it
resolves the issue.


David

 

From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Scott
Fisher
Sent: Monday, July 30, 2007 10:27 AM
To: declude.virus@declude.com
Subject: RE: [Declude.Virus] exe in zip file why not blocked...

 

Declude 4.3.57

 

AVAFTERJM ON YES.

 

 

 

-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of David
Barker
Sent: Monday, July 30, 2007 7:48 AM
To: declude.virus@declude.com
Subject: RE: [Declude.Virus] exe in zip file why not blocked...

 

Scott,

 

What version of Declude ?

 

Are you using the directive AVAFTERJM  ON?

 

David

 

From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Scott
Fisher
Sent: Friday, July 27, 2007 3:06 PM
To: declude.virus@declude.com
Subject: [Declude.Virus] exe in zip file why not blocked...

 

I was looking at my spam folder and noticed an email with a zip that
contained an exe.

 

07/27/2007 11:10:14.234 q18d4010e464c.smd Vulnerability flags = 862

07/27/2007 11:10:14.234 q18d4010e464c.smd MIME file: fungame.zip
[base64; Length=19363 Checksum=2473579]

07/27/2007 11:10:17.749 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:20.390 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:23.015 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:25.640 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:28.374 q18d4010e464c.smd Virus scanner 2 reports exit
code of 8

07/27/2007 11:10:30.374 q18d4010e464c.smd Could not find parse string
Found in report.txt

07/27/2007 11:10:30.374 q18d4010e464c.smd Error 8 in virus scanner 2.

07/27/2007 11:10:30.374 q18d4010e464c.smd Scanned: Error in virus
scanner. [MIME: 2 19668]

 

virus.cfg lines:

BANEXTexe

BANZIPEXTS ON

 

I believe this should have been blocked (regardless of the problem with
scanner 2).

 

Scott Fisher

Dir of IT

Farm Progress Companies

191 S Gary Ave

Carol Stream, IL 60188

Tel: 630-462-2323

 

This email message, including any attachments, is for the sole use of the
intended recipient(s) and may contain confidential and privileged
information. Any unauthorized review, use, disclosure or distribution is
prohibited. If you are not the intended recipient, please contact the sender
by reply email and destroy all copies of the original message. Although Farm
Progress Companies has taken reasonable precautions to ensure no viruses are
present in this email, the company cannot accept responsibility for any loss
or damage arising from the use of this email or attachments.

 


---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com. 


---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com. 
---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com. 


---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. The archives can be found
at http://www.mail-archive.com.


---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.