RE: [Declude.Virus] OT anyone know these guys ?
> http://authorizations.net/ > > sending this mail as html, the webpage looks ok but I can't take > such email serious > > Benny This is a scam my friend, the page you go to redirects to authorize.net which is a legtimate company. Real companies never just send an email asking for personal information like that. Billy --- [This E-mail was scanned for viruses by QuestNet.net (http://www.QuestNet.net)] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus".The archives can be found at http://www.mail-archive.com.
RE: [Declude.Virus] Fw: Your mail server sent us a virus
> Of course, if everyone had their configuration correct... > > John Tolmachoff MCSE CSSA > Engineer/Consultant > eServices For You > www.eservicesforyou.com Amen, I didn't get nearly enough sleep last night and had received this auto-response from another declude user that had received a virus from a forged address at my domain... The Declude Virus software on our mail server detected the W32/[EMAIL PROTECTED] virus that appears to have come from your mail server. It was sent in an attachment your_details.pif, from [EMAIL PROTECTED] to [EMAIL PROTECTED], with the subject "Re: Thank you!". The Message-ID was: <[EMAIL PROTECTED]>. This notice is sent as a courtesy so that you have the option of contacting your user and helping them get rid of the virus. This message was sent by Declude Virus. If your mail server had better virus protection, it would have caused less work for our server and could have prevented one of your users from getting a virus. The part that set me off was them telling people that if their mail server had better protection it would cause theirs less work!!! Arg...My response was... > If your mail server had better virus protection, it would have > caused less > work for our server and could have prevented one of your users > from getting a > virus. #1 Our mail server does have "better" virus protection(in fact the same yours does), and it does prevent our users from infection. #2 If you had "better" administration you would turn off notifications to postmasters and senders as it is well known the Sobig Virus and all variants of this virus forge email addresses. I am sure I am one of many that has received this in the wrong. #3 Your auto response comes off unnecessarily rude, and makes your technical staff look ignorant. I would hope this is not a reflection of how your company does business. If you would like to cause your mail server less work take our suggestion in #2 > Received: from DTS-ORL02 ([66.35.177.66]) Not my IP Thank you for your time, the intention of this email is only to educate. I am sure your technical staff is competent. --- [This E-mail was scanned for viruses by QuestNet.net (http://www.QuestNet.net)] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus".The archives can be found at http://www.mail-archive.com.
[Declude.Virus] AVG - Grisoft
Which executable do I use for AVG 7.0? I download the trial and want to evaluate the differences between F-prot and AVG 7.0. I currently only have the lite version of declude virus and don't have the cash to upgrade to pro quite yet. After 3 days F-prot still isn't catching this virus which seems very unacceptable? I had heard such good reviews about it and don't want to give up too quickly...does F-prot often keep behind others, or is this a rare occurrence? Billy --- [This E-mail was scanned for viruses by QuestNet.net (http://www.QuestNet.net)] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus".The archives can be found at http://www.mail-archive.com.
[Declude.Virus] F-Prot and Mimail
At this point is F-Prot catching it? If not has anyone found a good work around, without having to block all .zips... --- [This E-mail was scanned for viruses by QuestNet.net (http://www.QuestNet.net)] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus".The archives can be found at http://www.mail-archive.com.
RE: [Declude.Virus] M e s s a g e . z i p possible virus
I am using F-Prot and it is completely update to date, and not catching it the virus...is anyone using F-prot actually stopping it? > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] Behalf Of Andy Schmidt > Sent: Friday, August 01, 2003 4:44 PM > To: [EMAIL PROTECTED] > Subject: RE: [Declude.Virus] M e s s a g e . z i p possible virus > > > >> Is there a way to have Declude Virus remove this instead of JM << > > Yes. Simply by keeping your virus scanner current. > > Protection has been available since March 2003: > http://vil.nai.com/vil/content/v_99383.htm > > Best Regards > Andy > > --- > [This E-mail was scanned for viruses by Declude Virus > (http://www.declude.com)] > > --- > This E-mail came from the Declude.Virus mailing list. To > unsubscribe, just send an E-mail to [EMAIL PROTECTED], and > type "unsubscribe Declude.Virus".The archives can be found > at http://www.mail-archive.com. > > --- > [This E-mail was scanned for viruses by QuestNet.net > (http://www.QuestNet.net)] > > --- [This E-mail was scanned for viruses by QuestNet.net (http://www.QuestNet.net)] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus".The archives can be found at http://www.mail-archive.com.
RE: [Declude.Virus] Message.zip possible virus
I have been trying to follow the posts...what rule would I use to block this attachment? I know I put it in the body, is it just message.zip? --- [This E-mail was scanned for viruses by QuestNet.net (http://www.QuestNet.net)] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus".The archives can be found at http://www.mail-archive.com.
[Declude.Virus] Follow up - Declude Not Working after move
Thanks for all who helped, I fixed the problem. I'm not sure exactly why it happened, but I went into the configuration file for declude, then removed all of the "SKIPEXT" directives, and my number of viruses caught jumped back up to normal levels within an hour. Puzzled as to why this happened, I set the SKIPEXT directives back to what they were, and the viruses continued to be caught. Maybe it just needed to reload the configuation file or something? Ah well it's working now :) Thanks again! Billy Kimble, Webmaster ebase, LLC --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com .
RE: [Declude.Virus] Is anyone catching Nimda with McAfee
We are using F-Prot with the latest virus definitions, and our situation is similar. We catch dozens of Magistr and Sircam and Kaks a day, but I have yet to see any instances of Declude catching Nimda .. what is up with that? :) BK At 08:01 PM 9/24/01 +0200, you wrote: > >I am using Declude on our IMail server and have the latest DAT file from > >McAfee. We catch 100's of SirCam and W32Magistr but still haven't caught a > >single instance of Nimda. We just got our network cleaned up. Is anyone > >having any luck with McAfee. Should I consider switching to FProt. > >We are using F-prot and have so fra catched around 20 of them but mostly >its Sircam > >The system is passing about 15000 mails every day and F-prot catch on a >good (bad) week about 7000 mails with different virus > >Benny >Visual Web Norway >This E-mail came from the Declude.Virus mailing list. To >unsubscribe, just send an E-mail to [EMAIL PROTECTED], and >type "unsubscribe Declude.Virus". You can E-mail >[EMAIL PROTECTED] for assistance. You can visit our web >site at http://www.declude.com . This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com .
Re: [Declude.Virus] Question about Postmaster.EML
Cool feature :) I've had a few complaints from other systems' postmasters that have people frequently send viri using their domain (ie sexyfun.net) and these postmasters ask to not receive the viri notification e-mails because they get 30 - 40 a day. Perhaps there should be a way to exclude addresses? Just a suggestion .. I'm just turning it off for now :) BK - Original Message - From: R. Scott Perry <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Wednesday, May 09, 2001 5:43 PM Subject: Re: [Declude.Virus] Question about Postmaster.EML > > >Does the file HAVE to exist? Or can I turn off the "E-Mail the Postmaster" > >feature by just removing the file? It's a simple thing to test but I don't > >wanna try it out and have declude/imail blow up on me :) > > That file doesn't need to exist; you can safely remove it. Declude will > look for any files in \IMail\Declude that end in .eml. So, you can get rid > of any you don't want, and you can add new ones if you want. > -Scott > > This E-mail came from the Declude.Virus mailing list. To > unsubscribe, just send an E-mail to [EMAIL PROTECTED], and > type "unsubscribe Declude.Virus". You can E-mail > [EMAIL PROTECTED] for assistance. You can visit our web > site at http://www.declude.com . > This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com .
[Declude.Virus] Question about Postmaster.EML
Does the file HAVE to exist? Or can I turn off the "E-Mail the Postmaster" feature by just removing the file? It's a simple thing to test but I don't wanna try it out and have declude/imail blow up on me :) Billy Kimble, Webmaster ebase, LLC
[Declude.Virus] Declude 1.17 not detecting viri?
On average, out system has about 5 e-mails containing viri per day .. at least it did until we upgraded to declude 1.17. We upgraded on this past friday and over the weekend we had NO detections. One of our clients called us up today to say that a virus (called Magistr, IWorm_Magistr, I-Worm.Magistr or W32/Magistr@mm) got through to them and screwed up their system. I sent a test using the EICAR file and it was detected just fine but its VERY odd that right after we upgraded to 1.17, our detections suddenly slowed to 1 every 3 days, from 5 a day. Some of you might think it was because of the false positive problem, but nearly all of the viri Declude detected were "SnowWhite" viri. We are using Frisk's F-Prot for our detection, with the latest set of definitions. Frisk reports that they do indeed detect the viri so it must be a declude issue. Thanks for any help you guys can provide. Billy Kimble, Webmaster ebase, LLC
[Declude.Virus] IMAIL Upgrading ..
It appears that when you upgrade Imail, it overwrites the SenderName.Key in the registry so that it is pointing back to Imail\SMTP32.exe ... all you need to do is change it back to being Imail\declude.exe ... at least that appears to be what our most recent problem was :) Billy K, Webmaster ebase, LLC