RE: [Declude.Virus] Blocked Extension getting through

2004-12-21 Thread Hermann Strassner
Any solution yet?

Hermann Straßner

 -Original Message-
 From: [EMAIL PROTECTED] 
 [mailto:[EMAIL PROTECTED] On Behalf Of R. Scott Perry
 Sent: Wednesday, December 15, 2004 6:59 PM
 To: Declude.Virus@declude.com
 Subject: RE: [Declude.Virus] Blocked Extension getting through
 
 
 
 I hope that what you're assuming is NOT true.  Given that 
 Declude Virus
 unpacks all of the attachments and calls your antivirus scanner(s) on
 the unpacked attachments, I would expect that the BAN option takes
 effect based on that MIME decoding, so that it sees the correct
 filename.
 
 The problem here is that the filename is encoded using a very unusual 
 format -- we are currently investigating this.
 
 The files will get caught by a virus scanner, but the banned file 
 extensions may not work as expected.
 
 -Scott
 ---
 Declude JunkMail: The advanced anti-spam solution for IMail 
 mailservers 
 since 2000.
 Declude Virus: Ultra reliable virus detection and the leader 
 in mailserver 
 vulnerability detection.
 Find out what you've been missing: Ask for a free 30-day evaluation.
 
 
 
 This outgoing message is guaranteed to be authentic by 
 Message Level users.
 Guarantee the authenticity of your email @ 
 http://www.messagelevel.com.
 ---
 [This E-mail was scanned for 
 viruses by Declude Virus (http://www.declude.com)]
 
 ---
 This E-mail came from the Declude.Virus mailing list.  To
 unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
 type unsubscribe Declude.Virus.The archives can be found
 at http://www.mail-archive.com.
 

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.


[Declude.Virus] Blocked Extension getting through

2004-12-15 Thread Hermann Strassner
Hello!

I have blocked a few extensions in Declude Virus, e.g. zip, exe, bat,
scr, pif, chm and a few others. Normally that workes.

But since a few days some mails (with virus) are getting through.
They have an attachment like Rechnung18745514.chm, it is displayed as
Rechnung18745514.chm in Outlook or other mail clients, but in virus scan
or in raw mail format its name is: 
86BA342CB7A4
Content-Type: CHEMICAL/X-CS-CHEMDRAW;
name==?koi8-r?B?UmVjaG51bmcxODc0NTUxNC5j?=
 =?koi8-r?B?aG0=?=
Content-transfer-encoding: base64
Content-Disposition: attachment;
filename==?koi8-r?B?UmVjaG51bmcxODc0NTUxNC5j?=
 =?koi8-r?B?aG0=?=

What can i do to block this? This is a new worm yet not detected from
virus scanners. This happens often. But this mails are blocked by
extension filtering. Now they are getting through to the clients.

Hermann

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.


RE: [Declude.Virus] Blocked Extension getting through

2004-12-15 Thread Hermann Strassner
What do you want me to do?

I still have BANEXT CHM in my virus.cfg, and i successfully block .chm
attachments.
Here it is not working because of the encryption of the filename, as
you can see in the mail.

I show you the virus logfile:
vir1215.log: 12/15/2004 04:06:29 Qaa3414bd035a6555 MIME file:
=?koi8-r?B?UmVjaG51bmcxODc0NTUxNC5j?==?koi8-r?B?aG0=?= [base64;
Length=33018 Checksum=3232477]
vir1215.log: 12/15/2004 04:06:29 Qaa3414bd035a6555 Scanned: Virus Free
[MIME: 2 33569]


Hermann

 -Original Message-
 From: [EMAIL PROTECTED] 
 [mailto:[EMAIL PROTECTED] On Behalf Of William 
 Stillwell
 Sent: Wednesday, December 15, 2004 2:00 PM
 To: [EMAIL PROTECTED]
 Subject: Re: [Declude.Virus] Blocked Extension getting through
 
 
 BANEXT CHM
 
 
 
 - Original Message - 
 From: Hermann Strassner [EMAIL PROTECTED]
 To: [EMAIL PROTECTED]
 Sent: Wednesday, December 15, 2004 4:12 AM
 Subject: [Declude.Virus] Blocked Extension getting through
 
 
  Hello!
 
  I have blocked a few extensions in Declude Virus, e.g. zip, 
 exe, bat,
  scr, pif, chm and a few others. Normally that workes.
 
  But since a few days some mails (with virus) are getting through.
  They have an attachment like Rechnung18745514.chm, it is 
 displayed as
  Rechnung18745514.chm in Outlook or other mail clients, but 
 in virus scan
  or in raw mail format its name is:
  86BA342CB7A4
  Content-Type: CHEMICAL/X-CS-CHEMDRAW;
  name==?koi8-r?B?UmVjaG51bmcxODc0NTUxNC5j?=
  =?koi8-r?B?aG0=?=
  Content-transfer-encoding: base64
  Content-Disposition: attachment;
  filename==?koi8-r?B?UmVjaG51bmcxODc0NTUxNC5j?=
  =?koi8-r?B?aG0=?=
 
  What can i do to block this? This is a new worm yet not 
 detected from
  virus scanners. This happens often. But this mails are blocked by
  extension filtering. Now they are getting through to the clients.
 
  Hermann
 
  ---
  [This E-mail was scanned for viruses by Declude Virus 
  (http://www.declude.com)]
 
  ---
  This E-mail came from the Declude.Virus mailing list.  To
  unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
  type unsubscribe Declude.Virus.The archives can be found
  at http://www.mail-archive.com.
  ---
  This email has been scanned for possible viruses by Declude 
 Antivirus.
  For more information on Declude Antivirus, Visit www.declude.com
 
  
 
 ---
 This email has been scanned for possible viruses by Declude Antivirus.
 For more information on Declude Antivirus, Visit www.declude.com
 
 ---
 [This E-mail was scanned for viruses by Declude Virus 
(http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.


[Declude.Virus] Notification for forwarded messages

2004-05-28 Thread Hermann Strassner
Hello!

We block ZIPs and some executable extensions and want to leave it this
way. Because some folks need to send them, we have to check the
quarantined files (for viruses) and forward the mails without viruses
manually. Is there a way to inform the user that his mail is now
forwarded?

Alternatively, is it possible for the user to answer to the automatic
generated mail and forward the mail by himself? Is it possible somehow?
I think of it as follows: User sends email with ZIP, gets a
notification, answers to the notification with YES or something like
that, Declude sees it and forwards this email. I think this is enough to
make sure the user sends the email intentionally.

Hermann

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.


[Declude.Virus] Declude Hosting

2004-05-10 Thread Hermann Strassner
Has the domain or IP for Declude Virus changed from 24.107.232.14 to
68.186.245.124?

I am asking because my mail server wants to connect very often to this
IP with domain UDP since 9.5.04 2:30 MEST and it is everytime when
Declude detects a virus.

Hermann

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.


RE: [Declude.Virus] Declude Virus v1.79 (beta) released

2004-04-05 Thread Hermann Strassner
Hello Scott!

Since installing the 1.79 i had a lot of this messages in log file:

MIME file: =?iso-8859-1?Q?20040405-ddp_alben_=FCberarbeitung.xls?=
[base64; Length=15360 Checksum=870398]
1 [1 of 2 not deleted] files were deleted.  Use ONACCESS ON if you use
an external (on access) virus scanner.
Scanned: Virus Free [MIME: 2 16045]

What does this mean?
I upgraded from 1.77 with no changes in Virusscanner F-Prot Windows.

Hermann

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.


RE: [Declude.Virus] Declude Virus v1.79 (beta) released

2004-04-05 Thread Hermann Strassner
No, i changed nothing in the virus scanner. I do not have on access
scanning on before and not after the new declude.
I just copied the new delude.exe over the old one.

Every message has this or similar lines (1 of 2 not deleted, 2 of 3 not
deleted, 4 of 5 not deleted), except those with only skipped extensions.

Hermann

 -Original Message-
 From: [EMAIL PROTECTED] 
 [mailto:[EMAIL PROTECTED] On Behalf Of R. Scott Perry
 Sent: Monday, April 05, 2004 8:34 PM
 To: [EMAIL PROTECTED]
 Subject: RE: [Declude.Virus] Declude Virus v1.79 (beta) released
 
 
 
 Since installing the 1.79 i had a lot of this messages in log file:
 
 MIME file: =?iso-8859-1?Q?20040405-ddp_alben_=FCberarbeitung.xls?=
 [base64; Length=15360 Checksum=870398]
 1 [1 of 2 not deleted] files were deleted.  Use ONACCESS ON 
 if you use
 an external (on access) virus scanner.
 Scanned: Virus Free [MIME: 2 16045]
 
 What does this mean?
 
 Well, I hate to ask, but are you running an on-access virus 
 scanner (which 
 will interfere with Declude Virus)?
 
 Are there any log file entries indicating that the E-mail 
 contained a virus 
 or vulnerability?
 
 -Scott
 ---
 Declude JunkMail: The advanced anti-spam solution for IMail 
 mailservers 
 since 2000.
 Declude Virus: Ultra reliable virus detection and the leader 
 in mailserver 
 vulnerability detection.
 Find out what you've been missing: Ask for a free 30-day evaluation.
 
 ---
 [This E-mail was scanned for viruses by Declude Virus 
(http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.


RE: [Declude.Virus] Declude Virus v1.79 (beta) released

2004-04-05 Thread Hermann Strassner
The next one is:

Declude does not find viruses as viruses, only blocked extensions. I
blocked all dangerous extensions as pif, scr, exe and so on.
Normaly i get 100 viruses a hour, now i do not get a single one, only
vulnerabilities, but a lot of blocked extension, which are for sure
viruses (text, size and extension match)

Hermann

 -Original Message-
 From: [EMAIL PROTECTED] 
 [mailto:[EMAIL PROTECTED] On Behalf Of R. Scott Perry
 Sent: Monday, April 05, 2004 8:34 PM
 To: [EMAIL PROTECTED]
 Subject: RE: [Declude.Virus] Declude Virus v1.79 (beta) released
 
 
 
 Since installing the 1.79 i had a lot of this messages in log file:
 
 MIME file: =?iso-8859-1?Q?20040405-ddp_alben_=FCberarbeitung.xls?=
 [base64; Length=15360 Checksum=870398]
 1 [1 of 2 not deleted] files were deleted.  Use ONACCESS ON 
 if you use
 an external (on access) virus scanner.
 Scanned: Virus Free [MIME: 2 16045]
 
 What does this mean?
 
 Well, I hate to ask, but are you running an on-access virus 
 scanner (which 
 will interfere with Declude Virus)?
 
 Are there any log file entries indicating that the E-mail 
 contained a virus 
 or vulnerability?
 
 -Scott
 ---
 Declude JunkMail: The advanced anti-spam solution for IMail 
 mailservers 
 since 2000.
 Declude Virus: Ultra reliable virus detection and the leader 
 in mailserver 
 vulnerability detection.
 Find out what you've been missing: Ask for a free 30-day evaluation.
 
 ---
 [This E-mail was scanned for viruses by Declude Virus 
(http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.


RE: [Declude.Virus] Declude Virus v1.79 (beta) released

2004-04-05 Thread Hermann Strassner
I just found the reason: i made a new virus.cfg file because of the
changes (mostly in documentation). I included the scanner command line
for f-prot and did by mistake add the /NOFLOPPY parameter. This
parameter causes this behaviour, double checked.

The wrong message at first was because i did not update the declude.exe
in the right place, so there was still 1.76b in place.

Hermann

 -Original Message-
 From: [EMAIL PROTECTED] 
 [mailto:[EMAIL PROTECTED] On Behalf Of R. Scott Perry
 Sent: Monday, April 05, 2004 9:02 PM
 To: [EMAIL PROTECTED]
 Subject: RE: [Declude.Virus] Declude Virus v1.79 (beta) released
 
 
 
 No, i changed nothing in the virus scanner. I do not have on access
 scanning on before and not after the new declude.
 I just copied the new delude.exe over the old one.
 
 Every message has this or similar lines (1 of 2 not deleted, 
 2 of 3 not
 deleted, 4 of 5 not deleted), except those with only skipped 
 extensions.
 
 I'm guessing the debug mode will be needed here.  To do this, 
 change the 
 LOGLEVEL LOW line in \IMail\Declude\virus.cfg to LOGLEVEL 
 DEBUG.  Then, 
 send the test eicar.com file through (using our Test Virus Sender at 
 http://www.declude.com/tools ), and then switch back to 
 LOGLEVEL LOW (the 
 debug mode adds huge amounts of information to the log file). 
  You can then 
 send me the \IMail\spool\vir.log file off-list (as an 
 attachment, NOT 
 sent from web messaging), and I can take a look at it to see 
 what is happening.
 
 -Scott
 ---
 Declude JunkMail: The advanced anti-spam solution for IMail 
 mailservers 
 since 2000.
 Declude Virus: Ultra reliable virus detection and the leader 
 in mailserver 
 vulnerability detection.
 Find out what you've been missing: Ask for a free 30-day evaluation.
 
 ---
 [This E-mail was scanned for viruses by Declude Virus 
(http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.


RE: [Declude.Virus] [Declude.JunkMail] F-Prot Update

2004-02-16 Thread Hermann Strassner
 Although this question is better asked on the Virus list,

You are right, i put in on this list by mistake.

 I assume you are using the 32bit Windows version, correct?

Yes i do.

 How do you have the update configured?

I run the scheduler from f-prot, and i do an update hourly.

If nobody is logged in, the scheduler does not run. Is there an other
way?

Hermann

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.


[Declude.Virus] Different directories for viruses and blocked extensions

2003-11-21 Thread Hermann Strassner
Hello Scott!

A few months ago there were a few viruses and some mails with blocked
extension (at our site). They all go to the same directory
(\Imail\spool\virus). I get through the blocked mails (not the mails
with virus) once a day and decided which one to forward and which one to
delete.

Now there are much more viruses, a few hundred a day, so it is hard to
locate the mails with blocked extensions in this directory.

Is it possible to put the mails with blocked extension in a separate
directory than the mails with a virus? The directory name could be
\Imail\spool\ext.

Hermann

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.


RE: [Declude.Virus] Nameserver 24.107.232.14

2003-10-23 Thread Hermann Strassner
 Since i installed V 1.76b of Declude it tries to connect to IP 
 24.107.232.14 Port 53 UDP every few minutes to seconds. This 
 nameserver is not configered, not in System nor in Imail.
 
 That is forging.declude.com, which is used by the latest beta to 
 automatically detect forging viruses.  If you do not wish to 
 use this new 
 feature, you can add a line AUTOFORGE OFF to your 
 \IMail\Declude\virus.cfg file.

Thank you!

Hermann

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.


RE: [Declude.Virus] Did SOBIG REALLY stop?

2003-09-11 Thread Hermann Strassner
Not 1 sobig.f in the last 38 hours.

Hermann

 -Original Message-
 From: [EMAIL PROTECTED]
 [mailto:[EMAIL PROTECTED] Behalf Of Donn Bly
 Sent: Thursday, September 11, 2003 4:43 PM
 To: [EMAIL PROTECTED]
 Subject: RE: [Declude.Virus] Did SOBIG REALLY stop?
 
 
 Every SoBig.F virus I have received in the past 32 hours has been 
 part of a
 failure notification, where the message is returned because it 
 never reached
 its intended recipient.
 
 The biggest offenders I blocked at our border routers, and I'm not seeing
 the counters on the access list go up anymore.

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.


RE: [Declude.Virus] New Virus?

2003-08-14 Thread Hermann Strassner
Look in the mail from this mailing list on 12.08.2003 at 6:47 subject
Blaster worm!

Hermann

 -Original Message-
 From: [EMAIL PROTECTED]
 [mailto:[EMAIL PROTECTED] Behalf Of Sheldon Koehler
 Sent: Wednesday, August 13, 2003 9:10 AM
 To: [EMAIL PROTECTED]
 Subject: [Declude.Virus] New Virus?


 I had a customer email meflamingour server because a message
 keeps poping up
 saying the system is shutting down and then reboots their PC. I searched
 Sophos and a couple others, but cannot find a virus that fits this
 description. But I thought I saw something on the news this last weekend.

 Anyone have any ideas on this?


 Sheldon

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.


[Declude.Virus] Virus Notification

2003-06-30 Thread Hermann Strassner
Hello!

Although my configuration should not send notifications if the virus forges
the sender, it does. Does someone else have this effect?

My config is as follows:

E:\IMail\declude\otherpostmaster.eml


ONLYSENDIFREMOTESENDER
SKIPIFVIRUSNAMEHAS  Yaha
SKIPIFVIRUSNAMEHAS  Lentin
SKIPIFVIRUSNAMEHAS  Magistr
SKIPIFVIRUSNAMEHAS  Klez
SKIPIFVIRUSNAMEHAS  Vulnerability
SKIPIFVIRUSNAMEHAS  Bugbear
SKIPIFVIRUSNAMEHAS  Bridex
SKIPIFVIRUSNAMEHAS  Braid
SKIPIFVIRUSNAMEHAS  Sobig
SKIPIFVIRUSNAMEHAS  Palyh
SKIPIFVIRUSNAMEHAS  Fizzer
SKIPIFVIRUSNAMEHAS  Ganda
From: [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Subject: Your mail server sent us a virus

E:\IMail\declude\sender.eml

---
SKIPIFVIRUSNAMEHAS  Yaha
SKIPIFVIRUSNAMEHAS  Lentin
SKIPIFVIRUSNAMEHAS  Magistr
SKIPIFVIRUSNAMEHAS  Klez
SKIPIFVIRUSNAMEHAS  Vulnerability
SKIPIFVIRUSNAMEHAS  Bugbear
SKIPIFVIRUSNAMEHAS  Bridex
SKIPIFVIRUSNAMEHAS  Braid
SKIPIFVIRUSNAMEHAS  Sobig
SKIPIFVIRUSNAMEHAS  Palyh
SKIPIFVIRUSNAMEHAS  Fizzer
SKIPIFVIRUSNAMEHAS  Ganda
From: [EMAIL PROTECTED]
To: %MAILFROM%
Subject: WARNING: YOU MAY HAVE A VIRUS

Is there anything wrong?


Hermann

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.


RE: [Declude.Virus] Order of scanning

2003-03-25 Thread Hermann Strassner
  found at http://www.declude.com/junkmail/manual.htm :-) -
 Processing Order
 Both IMail and Declude have a number of different tests that they run on
 E-mail. The order used is as follows:

 1. IMail's Control Access file (to block IPs)
 2. IMail's Kill List (to block return addresses)
 3. Declude Hijack
 4. Declude Virus
 5. Declude JunkMail
 6. IMail's filters
 ---
 so Spam Virus would be found ;-)


What makes me worrying is that quarantined emails (declude virus) have the
X-Declude Headers from Declude Junkmail. This means that they must have been
scanned by junkmail, before declude virus comes in place. Am i right?

Is it possible that there are emails in the junkmail directory, which are
not scanned for virus? I have to put some of them back to spool because they
are false positives from junkmail, and i can`t afford unscanned mails go
through our mailserver.

Hermann

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.


RE: [Declude.Virus] Order of scanning

2003-03-25 Thread Hermann Strassner
 E-mails quarantined by Declude JunkMail will have been scanned
 for viruses,
 unless you change the default settings (using the AVAFTERJM
 setting).  Here
 are the possible orders:

 With v1.67 and earlier, default settings:
  [1] Declude Hijack
  [2] Declude Virus
  [3] Declude JunkMail

 With v1.67 and earlier, using AVAFTERJM setting:
  [1] Declude Hijack
  [2] Declude JunkMail
  [3] Declude Virus

 With v1.68 and later, default settings:
  [1] Declude Virus
  [2] Declude Hijack
  [3] Declude JunkMail

 With v1.68 and later, using AVAFTERJM setting:
  [1] Declude JunkMail
  [2] Declude Virus
  [3] Declude Hijack

I have V 1.65 in place and i do not have the term AVAFTERJM in any config
file.

So, are spam mails scanned for viri although the AV quarantined emails have
the Junkmail headers?

Hermann

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.


RE: [Declude.Virus] What to do with a virus Mail?

2002-10-16 Thread Hermann Strassner

 Declude filtered a virus, but the customer want's to have this mail.
 What should I do now?
 Can I copy the file to the spool directory?

Yes, you can.

 Or does Declude filters this mail again?

No.
Are you really sure you know that you want this?
Most viruses do not attach to an email with content, instead make an own
mail, maybe with a subject from an old mail. So there is nothing useful in
this email.

Hermann

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.



RE: [Declude.Virus] Banned extension

2002-07-04 Thread Hermann Strassner

Hello Scott!

 It will get bigger, but not nearly as much as the debug mode (which can 
 easily create log files 10-100 times their current size).  At 
 most, I would 
 guess that the log files would increase about 20% by using HIGH.

OK, i will set it as default, 20% don`t bother me.

 You can find it at http://www.declude.com/virus/manual.htm .

Thanks, i bookmarked it now.

Hermann

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .



RE: [Declude.Virus] New Version Of Declude

2002-01-08 Thread Hermann Strassner

On this Web page there is V 1.31 still in beta ...
Is it released now. Where can i find this version`?

Hermann

  Where can I download the new version of declude, and how much
 does it cost to upgrade?
 
 You can always find the latest versions at 
 http://www.declude.com/virus/manual.htm .  You are entitled to free 
 upgrades for a full year after your initial purchase.
 -Scott

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .