RE: [Declude.Virus] F-Prot V3.13?

2003-04-03 Thread Trent M. Davenport
I thought that typically the Windows version also contained the DOS
executable.  Is this not the case in this version?  I haven't extracted it
yet.

Trent
---
Trent M. Davenport - Systems Administrator
Northern Television Systems Ltd - WHTV
203-4103 4th Avenue, Whitehorse, YT Y1A 1H6
(867) 393-2225 X204, (867) 393-2224 FAX
www.whtvcable.com http://www.whtvcable.com  (
[EMAIL PROTECTED] mailto:[EMAIL PROTECTED]  )



-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] Behalf Of Frederick P. Squib,
Jr.
Sent: April 2, 2003 7:02 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] F-Prot V3.13?


Rick,
 http://www.f-prot.com/news/gen_news/release313.html

Version 3.13 of F-Prot Antivirus for Windows released

FRISK Software International has now released version 3.13 of F-Prot
Antivirus for Windows, Linux, and BSD. Version 3.13 of F-Prot Antivirus for
DOS is expected to follow within the next few days.

Fritz

Frederick P. Squib, Jr.
Network Operations
Citizens Telephone Company
Citizens Internet Services
http://www.wpa.net


 -Original Message-
 From: [EMAIL PROTECTED]
 [mailto:[EMAIL PROTECTED] On Behalf Of Rick Leske
 Sent: Wednesday, April 02, 2003 5:29 PM
 To: [EMAIL PROTECTED]
 Subject: RE: [Declude.Virus] F-Prot V3.13?


 is this the dos version?

 ~Rick

  -Original Message-
  From: [EMAIL PROTECTED]
  [mailto:[EMAIL PROTECTED] Behalf Of Helpdesk
  Sent: Wednesday, April 02, 2003 11:42 AM - FamHost
  To: [EMAIL PROTECTED]
  Subject: Re: [Declude.Virus] F-Prot V3.13?
 
 
  on 4/2/03 12:23 PM, Dan Star wrote:
 
   Did anyone test F-Prot Version 3.13 that was recently
 released?  Any
   changes that need to be made to integrate with Declude AV?
 
  I've been running it for a few days. No problems.
 
  Greg

 ___
 Virus Scanned and Filtered by http://www.FamHost.com E-Mail System.

 ---
 [This E-mail was scanned for viruses by Declude Virus
(http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.
---
[This E-mail scanned for viruses by Citizens Internet Services with Declude
Virus v 1.68i1]


---
[This E-mail scanned for viruses by Citizens Internet Services with Declude
Virus v 1.68i1]

---
[This E-mail was scanned for viruses by Declude Virus
(http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.


[Declude.Virus] Missing Manual Stuff (WAS Template options)

2003-01-20 Thread Trent M. Davenport
Scott,

I was looking through the manual the other day for the command line option
to see which version I have and could not find it.  I tried every - / and ?
help info combination I could think of and couldn't find it.  Did I just
miss it?

Trent
---
Trent M. Davenport - Systems Administrator
Northern Television Systems Ltd - WHTV
203-4103 4th Avenue, Whitehorse, YT Y1A 1H6
(867) 393-2225 X204, (867) 393-2224 FAX
www.whtvcable.com http://www.whtvcable.com  (
[EMAIL PROTECTED] mailto:[EMAIL PROTECTED]  )



-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of R. Scott Perry
Sent: January 20, 2003 1:23 PM
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus] Template options



I hope you understand when I say.. its hard for me to concieve of renewing
a
support agreement when your product isn't even fully documented..

The manual ( http://www.declude.com/virus/manual.htm ) has been updated to
include all the commands that can be used in the E-mail notification
files.  We are not aware of any options that are available but not covered
in the manual; if anyone knows of any, please let me know.
 -Scott

---
[This E-mail was scanned for viruses by Declude Virus
(http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.



RE: [Declude.Virus] OT: . U R L Attachments

2002-12-13 Thread Trent M. Davenport
That's the only one I removed from their list.  I felt exactly the way you
do.

I even went so far as to include the following blurb in the bannotify email:
The WHTV email server blocks all attachments that have the file extensions:
ADE, ADP, BAS, BAT, CEO, CHM, CMD, COM, CPL, CRT, EXE, HLP, HTA, ING, INS,
ISP, JS, JSE, LNK, MDB, MDE, MSC, MSI, MSP, MST, PCD, PIF, REG, SCR, SCT,
SHS, VB, VBE, VBS, WSC, WSF,and WSH as an anti-virus measure.  This is the
same list the Microsoft blocks in their Outlook Security Patch found at
http://office.microsoft.com/assistance/2000/Out2ksecFAQ.aspx  Please visit
their link for explanations of the file extensions.

As you'll notice, URL Has been removed.
Trent
---
Trent M. Davenport - Systems Administrator
Northern Television Systems Ltd - WHTV
203-4103 4th Avenue, Whitehorse, YT Y1A 1H6
(867) 393-2225 X204, (867) 393-2224 FAX
www.whtvcable.com http://www.whtvcable.com  (
[EMAIL PROTECTED] mailto:[EMAIL PROTECTED]  )



-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Bill Beach
Sent: December 13, 2002 8:48 AM
To: [EMAIL PROTECTED]
Subject: [Declude.Virus] OT: . U R L Attachments


I find it funny that Microsoft recommends blocking attachments with . u r l
extensions per their unsafe attachment list in KB 291369
(http://support.microsoft.com/default.aspx?scid=KB;en-us;291369;), yet their
software (IE, Outlook, Outlook Express) automatically creates an attachment
with this extension when you attempt to send a link via e-mail.

I'm debating on removing this from BANEXT as quite a bit of legit mail is
being held. Anyone have any thoughts on this?

Bill Beach
Network Administrator
Wenger's Feed Mill, Inc.

---
[This E-mail was scanned for viruses by Declude Virus
(http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.



RE: [Declude.Virus] New virus: W95/CIH-1106 New variant of Chernobyl

2002-12-03 Thread Trent M. Davenport
The WHTV email server blocks all attachments that have the file extensions:
ADE, ADP, BAS, BAT, CEO, CHM, CMD, COM, CPL, CRT, EXE, HLP, HTA, ING, INS,
ISP, JS, JSE, LNK, MDB, MDE, MSC, MSI, MSP, MST, PCD, PIF, REG, SCR, SCT,
SHS, VB, VBE, VBS, WSC, WSF,and WSH as an anti-virus measure.  This is the
same list the Microsoft blocks in their Outlook Security Patch found at
http://office.microsoft.com/assistance/2000/Out2ksecFAQ.aspx  Please visit
their link for explanations of the file extensions.

---
Trent M. Davenport - Systems Administrator
Northern Television Systems Ltd - WHTV
203-4103 4th Avenue, Whitehorse, YT Y1A 1H6
(867) 393-2225 X204, (867) 393-2224 FAX
www.whtvcable.com http://www.whtvcable.com  (
[EMAIL PROTECTED] mailto:[EMAIL PROTECTED]  )



-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Kris McElroy
Sent: December 3, 2002 12:57 PM
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus] New virus: W95/CIH-1106 New variant of
Chernobyl


What is extensions is everyone blocking in general?  I am blocking scr, pif,
ceo ?   Should I be blocking any thing else?



Thanks,


Kris McElroy
[EMAIL PROTECTED]

Internet Systems Engineer
Duracom, INC.
www.duracom.net
- Original Message -
From: John Tolmachoff [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Tuesday, December 03, 2002 2:41 PM
Subject: RE: Re: [Declude.Virus] New virus: W95/CIH-1106 New variant of
Chernobyl


 I guess that goes in to banext

 I just added it.

 John Tolmachoff MCSE, CSSA
 IT Manager, Network Engineer
 RelianceSoft, Inc.
 Fullerton, CA  92835
 www.reliancesoft.com



 ---
 [This E-mail was scanned for viruses by Declude Virus
(http://www.declude.com)]

 ---
 This E-mail came from the Declude.Virus mailing list.  To
 unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
 type unsubscribe Declude.Virus.The archives can be found
 at http://www.mail-archive.com.


---
[This E-mail was scanned for viruses by Declude Virus
(http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.



[Declude.Virus] Message Sniffer Confidence

2002-11-08 Thread Trent M. Davenport



So, after seeing the 
last 2 months that message sniffer is around 90% accurate, what confidence has 
everyone put in it? We offer our clients 2 levels of SPAM blocking. 
Regular (using a WEIGHT20) and Aggressive (using a WEIGHT10). Because 
we're an ISP, we have to be really careful about deleting legitimate 
email. 

We purchased Message 
Sniffer and implemented it and it is catching a bunch of messages, but the 
default weight is 7. With the percentage as high as it is, I'd like to 
give it a 17 so that if a message fails it plus 1 other test, it'll fail the 
regular test. Need I be that cautious?

Just looking for 
feedback from other users of Sniffer.

Trent
---Trent M. 
Davenport - Systems AdministratorNorthern Television Systems Ltd - 
WHTV203-4103 4th Avenue, Whitehorse, YT Y1A 1H6(867) 393-2225 X204, 
(867) 393-2224 FAXwww.whtvcable.com( [EMAIL PROTECTED] 
)



RE: [Declude.Virus] Outlook Express Flaw Permits System Takeover Via E-mail

2002-10-18 Thread Trent M. Davenport
Yup, shore do gots patches.  Both knees be covered with dem.  An one on me
bum too.


-Original Message-
From: [EMAIL PROTECTED]
[mailto:Declude.Virus-owner;declude.com]On Behalf Of Bill Beach
Sent: October 17, 2002 1:01 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] Outlook Express Flaw Permits System
Takeover Via E-mail


those clients that cough don't keep their systems up to date.

Wait, you mean there are people who don't keep up to date with patches?

-Bill
---

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.



RE: [Declude.Virus] Junk mail module.

2002-10-10 Thread Trent M. Davenport
Title: Message



The 
manual outlines a test (on page 12 of 17 when I printed the manual). Just 
grab a free web based account and send the line 

rsp 
set off ORDB

And it 
will trigger the ORDB test, which will appear in the headers if the WARN default 
is used.

I've 
tried it from Hotmail and our server catches it.

Trent
---Trent M. 
Davenport - Systems AdministratorNorthern Television Systems Ltd - 
WHTV203-4103 4th Avenue, Whitehorse, YT Y1A 1H6(867) 393-2225 X204, 
(867) 393-2224 FAXwww.whtvcable.com( [EMAIL PROTECTED] 
)

  -Original Message-From: 
  [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On 
  Behalf Of Mitch IrvineSent: October 10, 2002 1:49 
  PMTo: [EMAIL PROTECTED]Cc: 
  [EMAIL PROTECTED]Subject: RE: [Declude.Virus] Junk mail 
  module.
  That's what I've been checking for, and have not seen 
  yet.
  
  Scott's instructions are fantastic, and my log files 
  indicate a lot of trapping, but no reference in any emails in this particular 
  user account.
  
  So 
  as of yet, not notice in the body, subject line, header, footer, 
  nothing.
  
  Is 
  there a test that can be performed? 
  
  I've 
  also cc'd the junkmail mailing list as requested.
  
  Regards,
  
  Mitch
  

-Original Message-From: 
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] 
On Behalf Of Trent M. DavenportSent: Thursday, October 10, 
2002 12:35 PMTo: [EMAIL PROTECTED]Subject: RE: 
[Declude.Virus] Junk mail module.
The default setup is WARN with will add header information. 
Check the headers and see if you get a line line X-Spam-Tests-Failed and it 
will tell you if it is seeing them as spam

Trent
---Trent 
M. Davenport - Systems AdministratorNorthern Television Systems Ltd - 
WHTV203-4103 4th Avenue, Whitehorse, YT Y1A 1H6(867) 393-2225 X204, 
(867) 393-2224 FAXwww.whtvcable.com( [EMAIL PROTECTED] 
)

  -Original Message-From: 
  [EMAIL PROTECTED] 
  [mailto:[EMAIL PROTECTED]]On Behalf Of Mitch 
  IrvineSent: October 10, 2002 12:16 PMTo: 
  [EMAIL PROTECTED]Subject: [Declude.Virus] Junk mail 
  module.
  Who has configured this in an optimal way? 
  
  I just purchased the standard version and 
  installed. My log files are indicating that emails are being found 
  as spam. I presently have a fantastic test case email account that 
  usually gets between 100-150 emails daily that are nothing but 
  junk.
  So far I've received nothing in the body of 
  these e-mail's to determine if junk mail module has properly flagged any 
  of these as spam mail.
  Can someone give me a guiding light regarding 
  this module, or at least point me to the correct forum? 
  I also use Delude virus engine and am extremely 
  happy with that module. 
  Regards, 
  Mitch