RE: [Declude.Virus] OT anyone know these guys ?

2003-10-15 Thread Billy

> http://authorizations.net/
>
> sending this mail as html, the webpage looks ok but I can't take
> such email serious
>
> Benny

This is a scam my friend, the page you go to redirects to authorize.net
which is a legtimate company. Real companies never just send an email asking
for personal information like that.

Billy


---
[This E-mail was scanned for viruses by QuestNet.net (http://www.QuestNet.net)]

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".The archives can be found
at http://www.mail-archive.com.


RE: [Declude.Virus] Fw: Your mail server sent us a virus

2003-08-21 Thread Billy
> Of course, if everyone had their configuration correct...
>
> John Tolmachoff MCSE CSSA
> Engineer/Consultant
> eServices For You
> www.eservicesforyou.com

Amen, I didn't get nearly enough sleep last night and had received this
auto-response from another declude user that had received a virus from a
forged address at my domain...

The Declude Virus software on our mail server detected the  W32/[EMAIL PROTECTED]
virus that appears to have come from your mail server.  It was sent in
an attachment your_details.pif, from [EMAIL PROTECTED] to
[EMAIL PROTECTED],
with the subject "Re: Thank you!".  The Message-ID was:
<[EMAIL PROTECTED]>.

This notice is sent as a courtesy so that you have the option of contacting
your user and helping them get rid of the virus.  This message was sent by
Declude Virus.

If your mail server had better virus protection, it would have caused less
work for our server and could have prevented one of your users from getting
a
virus.



 The part that set me off was them telling people that if their mail
server had better protection it would cause theirs less work!!! Arg...My
response was...

> If your mail server had better virus protection, it would have
> caused less
> work for our server and could have prevented one of your users
> from getting a
> virus.

#1 Our mail server does have "better" virus protection(in fact the same
yours does), and it does prevent our users from infection.
#2 If you had "better" administration you would turn off notifications to
postmasters and senders as it is well known the Sobig Virus and all variants
of this virus forge email addresses. I am sure I am one of many that has
received this in the wrong.
#3 Your auto response comes off unnecessarily rude, and makes your technical
staff look ignorant. I would hope this is not a reflection of how your
company does business. If you would like to cause your mail server less work
take our suggestion in #2

> Received: from DTS-ORL02 ([66.35.177.66])

Not my IP

Thank you for your time, the intention of this email is only to educate. I
am sure your technical staff is competent.


---
[This E-mail was scanned for viruses by QuestNet.net (http://www.QuestNet.net)]

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".The archives can be found
at http://www.mail-archive.com.


[Declude.Virus] AVG - Grisoft

2003-08-04 Thread Billy
Which executable do I use for AVG 7.0? I download the trial and want to
evaluate the differences between F-prot and AVG 7.0.

I currently only have the lite version of declude virus and don't have the
cash to upgrade to pro quite yet. After 3 days F-prot still isn't catching
this virus which seems very unacceptable? I had heard such good reviews
about it and don't want to give up too quickly...does F-prot often keep
behind others, or is this a rare occurrence?

Billy



---
[This E-mail was scanned for viruses by QuestNet.net (http://www.QuestNet.net)]

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".The archives can be found
at http://www.mail-archive.com.


[Declude.Virus] F-Prot and Mimail

2003-08-04 Thread Billy
At this point is F-Prot catching it? If not has anyone found a good work
around, without having to block all .zips...


---
[This E-mail was scanned for viruses by QuestNet.net (http://www.QuestNet.net)]

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".The archives can be found
at http://www.mail-archive.com.


RE: [Declude.Virus] M e s s a g e . z i p possible virus

2003-08-01 Thread Billy
I am using F-Prot and it is completely update to date, and not catching it
the virus...is anyone using F-prot actually stopping it?

> -Original Message-
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED] Behalf Of Andy Schmidt
> Sent: Friday, August 01, 2003 4:44 PM
> To: [EMAIL PROTECTED]
> Subject: RE: [Declude.Virus] M e s s a g e . z i p possible virus
>
>
> >> Is there a way to have Declude Virus remove this instead of JM <<
>
> Yes. Simply by keeping your virus scanner current.
>
> Protection has been available since March 2003:
> http://vil.nai.com/vil/content/v_99383.htm
>
> Best Regards
> Andy
>
> ---
> [This E-mail was scanned for viruses by Declude Virus
> (http://www.declude.com)]
>
> ---
> This E-mail came from the Declude.Virus mailing list.  To
> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
> type "unsubscribe Declude.Virus".The archives can be found
> at http://www.mail-archive.com.
>
> ---
> [This E-mail was scanned for viruses by QuestNet.net
> (http://www.QuestNet.net)]
>
>


---
[This E-mail was scanned for viruses by QuestNet.net (http://www.QuestNet.net)]

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".The archives can be found
at http://www.mail-archive.com.


RE: [Declude.Virus] Message.zip possible virus

2003-08-01 Thread Billy
I have been trying to follow the posts...what rule would I use to block this
attachment? I know I put it in the body, is it just message.zip?


---
[This E-mail was scanned for viruses by QuestNet.net (http://www.QuestNet.net)]

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".The archives can be found
at http://www.mail-archive.com.


[Declude.Virus] Follow up - Declude Not Working after move

2002-02-14 Thread Billy Kimble

Thanks for all who helped, I fixed the problem. I'm not sure exactly why it 
happened, but I went into the configuration file for declude, then removed 
all of the "SKIPEXT" directives, and my number of viruses caught jumped 
back up to normal levels within an hour. Puzzled as to why this happened, I 
set the SKIPEXT directives back to what they were, and the viruses 
continued to be caught. Maybe it just needed to reload the configuation 
file or something? Ah well it's working now :) Thanks again!

Billy Kimble, Webmaster
ebase, LLC

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .



RE: [Declude.Virus] Is anyone catching Nimda with McAfee

2001-09-24 Thread Billy Kimble

We are using F-Prot with the latest virus definitions, and our situation is
similar. We catch dozens of Magistr and Sircam and Kaks a day, but I have
yet to see any instances of Declude catching Nimda .. what is up with that? :)
BK

At 08:01 PM 9/24/01 +0200, you wrote:


> >I am using Declude on our IMail server and have the latest DAT file from
> >McAfee. We catch  100's of SirCam and W32Magistr but still haven't caught a
> >single instance of Nimda. We just got our network cleaned up. Is anyone
> >having any luck with McAfee. Should I consider switching to FProt.
>
>We are using F-prot and have so fra catched around 20 of them but mostly 
>its Sircam
>
>The system is passing about 15000 mails every day and F-prot catch on a 
>good (bad) week about 7000 mails with different virus
>
>Benny
>Visual Web Norway
>This E-mail came from the Declude.Virus mailing list.  To
>unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
>type "unsubscribe Declude.Virus".  You can E-mail
>[EMAIL PROTECTED] for assistance.  You can visit our web
>site at http://www.declude.com .

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .



Re: [Declude.Virus] Question about Postmaster.EML

2001-05-09 Thread Billy Kimble

Cool feature :)

I've had a few complaints from other systems' postmasters that have people
frequently send viri using their domain (ie sexyfun.net) and these
postmasters ask to not receive the viri notification e-mails because they
get 30 - 40 a day. Perhaps there should be a way to exclude addresses? Just
a suggestion .. I'm just turning it off for now :)

BK


- Original Message -
From: R. Scott Perry <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Wednesday, May 09, 2001 5:43 PM
Subject: Re: [Declude.Virus] Question about Postmaster.EML


>
> >Does the file HAVE to exist? Or can I turn off the "E-Mail the
Postmaster"
> >feature by just removing the file? It's a simple thing to test but I
don't
> >wanna try it out and have declude/imail blow up on me :)
>
> That file doesn't need to exist; you can safely remove it.  Declude will
> look for any files in \IMail\Declude that end in .eml.  So, you can get
rid
> of any you don't want, and you can add new ones if you want.
>  -Scott
>
> This E-mail came from the Declude.Virus mailing list.  To
> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
> type "unsubscribe Declude.Virus".  You can E-mail
> [EMAIL PROTECTED] for assistance.  You can visit our web
> site at http://www.declude.com .
>

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .



[Declude.Virus] Question about Postmaster.EML

2001-05-09 Thread Billy Kimble



Does the file HAVE to exist? Or can I turn off the 
"E-Mail the Postmaster" feature by just removing the file? It's a simple thing 
to test but I don't wanna try it out and have declude/imail blow up on me 
:) 
 
Billy Kimble, Webmaster
ebase, LLC


[Declude.Virus] Declude 1.17 not detecting viri?

2001-04-09 Thread Billy Kimble




On average, out system has about 5 e-mails 
containing viri per day .. at least it did until we upgraded to declude 1.17. We 
upgraded on this past friday and over the weekend we had NO detections. One 
of our clients called us up today to say that a virus (called Magistr, IWorm_Magistr, I-Worm.Magistr or W32/Magistr@mm) got through to them and screwed 
up their system. I sent a test using the EICAR file and it was detected just 
fine but its VERY odd that right after we upgraded to 1.17, our detections 
suddenly slowed to 1 every 3 days, from 5 a day. 
 
Some of you might think it was 
because of the false positive problem, but nearly all of the viri Declude 
detected were "SnowWhite" viri. We 
are using Frisk's F-Prot for our detection, with the latest set of definitions. 
Frisk reports that they do indeed detect the viri so it must be a declude issue. 
Thanks for any help you guys can provide.
 
Billy Kimble, Webmaster
ebase, 
LLC


[Declude.Virus] IMAIL Upgrading ..

2001-03-23 Thread Billy Kimble



It appears that when you upgrade Imail, it 
overwrites the SenderName.Key in the registry so that it is pointing back to 
Imail\SMTP32.exe ... all you need to do is change it back to being 
Imail\declude.exe ... at least that appears to be what our most recent problem 
was :)
 
Billy K, Webmaster
ebase, LLC