Re: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
Is this BS really necessary? If you don't like someone, can't you keep it to yourself? A simple philosophy, don't be annoying and don't be easily annoyed. John may have a big ego...so what?! I haven't met a computer engineer yet worth a darn that doesn't have a big ego. It take a lot of moxy to be responsible for hundreds/thousands of users computers/accounts when the crap is flying all around and you are the one getting yelled at. I've been on/watching this list for a long time. I don't always like the answers I get, but the people here DO HELP ME. That is the bottom line, isn't it? Or is it about hurting egos? Personally, I don't think there is room for ego in the business world. I don't think any of us are here for the fun of it, but to make money, right? If I have to supress my ego to get the answers I need and to get the job done, SO BE IT. Come to think of it, we are usually guilty of what we accuse others of. > In my experience it's people with bloated egos who attempt to publically ridicule and chastise. > Mike Tindor I think it would be helpful to remember that John and others like him are NOT GETTING PAID to help with your issues or mine. This IS THE SPIRIT of the Internet, all of us helping each other, the best we can. That's my 2 cents worth. And I've been in this business a long time, 16 years, 8 of it running ISP's and being responsible for corporate networks. I don't have to like John's approach to *respect* him and his efforts on this list. Now, can we all be nice to each other in this sand box...PLEASE?! Andrew Thumpernet - Original Message - From: "FIRST Internet Declude Virus Account" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Saturday, September 06, 2003 12:25 PM Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS > I'd have to agree. > > I guess all of the letters after John's name have gone to his head. > > In my experience it's people with bloated egos who attempt to publically ridicule and chastise. Seems to me a friendly note directly to the admin would have been more appropriate. > > Mike Tindor > > -- Original Message -- > From: "Tim Collins" <[EMAIL PROTECTED]> > Reply-To: [EMAIL PROTECTED] > Date: Sat, 30 Aug 2003 07:55:41 -0500 > > >John Tolmachoff, > > > >Personally, I have 2 months experience with my new ISP company and > >Declude. > >Not everyone is as smart as you. > >Maybe you should leave the List and start your own discussion group. > > > >The only stupid question is the one that is not asked. Often, there is > >more than one way to do something. > > > >Please keep your personal comments to yourself. > > > >Tim Collins > > > >-Original Message- > >From: [EMAIL PROTECTED] > >[mailto:[EMAIL PROTECTED] On Behalf Of John Tolmachoff > >(Lists) > >Sent: Saturday, August 30, 2003 12:19 AM > >To: [EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED]; > >[EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED] > >Cc: [EMAIL PROTECTED] > >Subject: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS > >Importance: High > > > > > >After all this has been talked about, that Sobig forges the sender, this > >pisses me off. > > > >Do you not know how to add FORGINGVIRUS and SKIPIFVIRUSNAMEHAS to the > >config and e-mail files? > > > >Get your bleeping act together or forfeit your Declude software to > >someone who knows how to use it. > > > >John Tolmachoff MCSE CSSA > >Engineer/Consultant > >eServices For You > >www.eservicesforyou.com > > > >> -Original Message- > >> From: Postmaster [mailto:[EMAIL PROTECTED] > >> Sent: Friday, August 29, 2003 7:58 PM > >> To: [EMAIL PROTECTED] > >> Subject: WARNING: YOU MAY HAVE A VIRUS > >> > >> The Declude Virus software on lcs.net has reported that you sent an > >> E-mail to [EMAIL PROTECTED], containing the Unknown Virus virus in > >the > >> Unknown File attachment. The subject of the E-mail was "Your > >> details". The E-mail containing the virus has been quarantined to > >> prevent further > >damage. > >> > >> Headers Follow: > >> Received: from ARNOLDS_ROOM [160.36.73.149] by lcs.net with ESMTP > >> (SMTPD32-7.07) id A2A72C08013C; Fri, 29 Aug 2003 22:57:43 -0400 > >> From: <[EMAIL PROTECTED]> > >> To: <[EMAIL PROTECTED]> > >> Subject: Your details > >> Date: Fri, 29 Aug 2003 22:59:36 --0400 > >> X-MailSca
RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
I'd have to agree. I guess all of the letters after John's name have gone to his head. In my experience it's people with bloated egos who attempt to publically ridicule and chastise. Seems to me a friendly note directly to the admin would have been more appropriate. Mike Tindor -- Original Message -- From: "Tim Collins" <[EMAIL PROTECTED]> Reply-To: [EMAIL PROTECTED] Date: Sat, 30 Aug 2003 07:55:41 -0500 >John Tolmachoff, > >Personally, I have 2 months experience with my new ISP company and >Declude. >Not everyone is as smart as you. >Maybe you should leave the List and start your own discussion group. > >The only stupid question is the one that is not asked. Often, there is >more than one way to do something. > >Please keep your personal comments to yourself. > >Tim Collins > >-Original Message- >From: [EMAIL PROTECTED] >[mailto:[EMAIL PROTECTED] On Behalf Of John Tolmachoff >(Lists) >Sent: Saturday, August 30, 2003 12:19 AM >To: [EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED]; >[EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED] >Cc: [EMAIL PROTECTED] >Subject: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS >Importance: High > > >After all this has been talked about, that Sobig forges the sender, this >pisses me off. > >Do you not know how to add FORGINGVIRUS and SKIPIFVIRUSNAMEHAS to the >config and e-mail files? > >Get your bleeping act together or forfeit your Declude software to >someone who knows how to use it. > >John Tolmachoff MCSE CSSA >Engineer/Consultant >eServices For You >www.eservicesforyou.com > >> -Original Message- >> From: Postmaster [mailto:[EMAIL PROTECTED] >> Sent: Friday, August 29, 2003 7:58 PM >> To: [EMAIL PROTECTED] >> Subject: WARNING: YOU MAY HAVE A VIRUS >> >> The Declude Virus software on lcs.net has reported that you sent an >> E-mail to [EMAIL PROTECTED], containing the Unknown Virus virus in >the >> Unknown File attachment. The subject of the E-mail was "Your >> details". The E-mail containing the virus has been quarantined to >> prevent further >damage. >> >> Headers Follow: >> Received: from ARNOLDS_ROOM [160.36.73.149] by lcs.net with ESMTP >> (SMTPD32-7.07) id A2A72C08013C; Fri, 29 Aug 2003 22:57:43 -0400 >> From: <[EMAIL PROTECTED]> >> To: <[EMAIL PROTECTED]> >> Subject: Your details >> Date: Fri, 29 Aug 2003 22:59:36 --0400 >> X-MailScanner: Found to be clean >> Importance: Normal >> X-Mailer: Microsoft Outlook Express 6.00.2600. >> X-MSMail-Priority: Normal >> X-Priority: 3 (Normal) >> MIME-Version: 1.0 >> Content-Type: multipart/mixed; >> boundary="_NextPart_000_7E49D478" >> Message-Id: <[EMAIL PROTECTED]> >> > > >--- >[This E-mail was scanned for viruses by Declude Virus >(http://www.declude.com)] > >--- >This E-mail came from the Declude.Virus mailing list. To unsubscribe, >just send an E-mail to [EMAIL PROTECTED], and >type "unsubscribe Declude.Virus".The archives can be found >at http://www.mail-archive.com. > > > >--- >[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] > >--- >This E-mail came from the Declude.Virus mailing list. To >unsubscribe, just send an E-mail to [EMAIL PROTECTED], and >type "unsubscribe Declude.Virus".The archives can be found >at http://www.mail-archive.com. > Sent via the WebMail system at 1st.net --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus".The archives can be found at http://www.mail-archive.com.
RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
1. If the message gets through because it is a corrupt version and non-viable, it will be delivered to the recipient, so no notification is sent. 2. If the virus scanner catches it but is not sure, it should report virus name Unknown. You can then add SKIPIFVIRUSNAMEHAS unknown in the appropriate .eml files. 3. If the message does not get picked up as infected, but has an banned attachment, it should be caught by that banned attachment. 4. You can also set up filter tests in JM to catch notifications/bounces from other servers. John Tolmachoff MCSE CSSA Engineer/Consultant eServices For You www.eservicesforyou.com > -Original Message- > From: [EMAIL PROTECTED] [mailto:Declude.Virus- > [EMAIL PROTECTED] On Behalf Of paul > Sent: Tuesday, September 02, 2003 12:55 PM > To: [EMAIL PROTECTED] > Subject: Re: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS > > John, Scott, everyone. > > Question to this. > > I have the SKIPIF lines in my eml files, but I was curious, what happens > to the corrupt versions of Sobig, etc that the attachments get through due > to no virus? Since these return addresses are no doubt bogus, is there a > guard against this? Do we have a SKIPIFATTACHMENTIS .scr option? > > Paul > > > --- > [This E-mail scanned for viruses by Declude Virus] > > --- > [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] > > --- > This E-mail came from the Declude.Virus mailing list. To > unsubscribe, just send an E-mail to [EMAIL PROTECTED], and > type "unsubscribe Declude.Virus".The archives can be found > at http://www.mail-archive.com. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus".The archives can be found at http://www.mail-archive.com.
Re: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
I have the SKIPIF lines in my eml files, but I was curious, what happens to the corrupt versions of Sobig, etc that the attachments get through due to no virus? Since these return addresses are no doubt bogus, is there a guard against this? Do we have a SKIPIFATTACHMENTIS .scr option? No, there is no way to do that. -Scott --- Declude JunkMail: The advanced anti-spam solution for IMail mailservers. Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection. Find out what you have been missing: Ask for a free 30-day evaluation. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus".The archives can be found at http://www.mail-archive.com.
Re: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
John, Scott, everyone. Question to this. I have the SKIPIF lines in my eml files, but I was curious, what happens to the corrupt versions of Sobig, etc that the attachments get through due to no virus? Since these return addresses are no doubt bogus, is there a guard against this? Do we have a SKIPIFATTACHMENTIS .scr option? Paul --- [This E-mail scanned for viruses by Declude Virus] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus".The archives can be found at http://www.mail-archive.com.
RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
> Personally, I have 2 months experience with my new ISP company and > Declude. > Not everyone is as smart as you. > Maybe you should leave the List and start your own discussion group. Excuse you, but unless you have been hiding under a rock, the fact the Sobig forges the sender has been discussed plenty in the last 2 weeks on this list, as well as others including the Imail list, which quite falls within the last 2 months. Get your facts straight before making a comment. Any AV software or admins that have it misconfigured that is continuing to send out notices at this time to forged senders deserves to be ridiculed. All they are doing is adding to the problem, of additional traffic on the internet, of confused users, of additional phone calls of help I am infected, of accusations that some one is spreading the virus erroneously. BTW, Sobig has been known to forge the sender for months, since the first version. Any one new to Declude would have downloaded the current .eml and config files, which have already included the proper lines to not send out notifications to forged senders. Therefore, these are people who have been running Declude for a while, and therefore are not new to it. John Tolmachoff MCSE CSSA Engineer/Consultant eServices For You www.eservicesforyou.com --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus".The archives can be found at http://www.mail-archive.com.
RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
John Tolmachoff, Personally, I have 2 months experience with my new ISP company and Declude. Not everyone is as smart as you. Maybe you should leave the List and start your own discussion group. The only stupid question is the one that is not asked. Often, there is more than one way to do something. Please keep your personal comments to yourself. Tim Collins -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of John Tolmachoff (Lists) Sent: Saturday, August 30, 2003 12:19 AM To: [EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED] Cc: [EMAIL PROTECTED] Subject: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS Importance: High After all this has been talked about, that Sobig forges the sender, this pisses me off. Do you not know how to add FORGINGVIRUS and SKIPIFVIRUSNAMEHAS to the config and e-mail files? Get your bleeping act together or forfeit your Declude software to someone who knows how to use it. John Tolmachoff MCSE CSSA Engineer/Consultant eServices For You www.eservicesforyou.com > -Original Message- > From: Postmaster [mailto:[EMAIL PROTECTED] > Sent: Friday, August 29, 2003 7:58 PM > To: [EMAIL PROTECTED] > Subject: WARNING: YOU MAY HAVE A VIRUS > > The Declude Virus software on lcs.net has reported that you sent an > E-mail to [EMAIL PROTECTED], containing the Unknown Virus virus in the > Unknown File attachment. The subject of the E-mail was "Your > details". The E-mail containing the virus has been quarantined to > prevent further damage. > > Headers Follow: > Received: from ARNOLDS_ROOM [160.36.73.149] by lcs.net with ESMTP > (SMTPD32-7.07) id A2A72C08013C; Fri, 29 Aug 2003 22:57:43 -0400 > From: <[EMAIL PROTECTED]> > To: <[EMAIL PROTECTED]> > Subject: Your details > Date: Fri, 29 Aug 2003 22:59:36 --0400 > X-MailScanner: Found to be clean > Importance: Normal > X-Mailer: Microsoft Outlook Express 6.00.2600. > X-MSMail-Priority: Normal > X-Priority: 3 (Normal) > MIME-Version: 1.0 > Content-Type: multipart/mixed; > boundary="_NextPart_000_7E49D478" > Message-Id: <[EMAIL PROTECTED]> > --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus".The archives can be found at http://www.mail-archive.com. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus".The archives can be found at http://www.mail-archive.com.
RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
I had to argue with an IMAIL admin with Declude for two days and had to e-mail him the damn otherpostmaster and sender eml files before he would change them. I hope my change took effect... : ) -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of John Tolmachoff (Lists) Sent: Saturday, August 30, 2003 2:19 AM To: [EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED] Cc: [EMAIL PROTECTED] Subject: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS Importance: High After all this has been talked about, that Sobig forges the sender, this pisses me off. Do you not know how to add FORGINGVIRUS and SKIPIFVIRUSNAMEHAS to the config and e-mail files? Get your bleeping act together or forfeit your Declude software to someone who knows how to use it. John Tolmachoff MCSE CSSA Engineer/Consultant eServices For You www.eservicesforyou.com > -Original Message- > From: Postmaster [mailto:[EMAIL PROTECTED] > Sent: Friday, August 29, 2003 7:58 PM > To: [EMAIL PROTECTED] > Subject: WARNING: YOU MAY HAVE A VIRUS > > The Declude Virus software on lcs.net has reported that you > sent an E-mail to [EMAIL PROTECTED], containing the Unknown Virus virus in the > Unknown File attachment. The subject of the E-mail was "Your details". > The E-mail containing the virus has been quarantined to prevent further damage. > > Headers Follow: > Received: from ARNOLDS_ROOM [160.36.73.149] by lcs.net with ESMTP > (SMTPD32-7.07) id A2A72C08013C; Fri, 29 Aug 2003 22:57:43 -0400 > From: <[EMAIL PROTECTED]> > To: <[EMAIL PROTECTED]> > Subject: Your details > Date: Fri, 29 Aug 2003 22:59:36 --0400 > X-MailScanner: Found to be clean > Importance: Normal > X-Mailer: Microsoft Outlook Express 6.00.2600. > X-MSMail-Priority: Normal > X-Priority: 3 (Normal) > MIME-Version: 1.0 > Content-Type: multipart/mixed; > boundary="_NextPart_000_7E49D478" > Message-Id: <[EMAIL PROTECTED]> > --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus".The archives can be found at http://www.mail-archive.com. --- [This E-mail scanned for viruses by Declude Virus] --- [This E-mail scanned for viruses by Declude Virus] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus".The archives can be found at http://www.mail-archive.com.
Re: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
>I sent off a couple of files to virustrap to see if they would get caught. >They did. However, they didn't get caught the first time I was sent them. >([EMAIL PROTECTED]) >I was wondering if they were not caught earlier because I sent a mailall and >the server was under load? Are there circumstances where this can happen >Scott? (Using McAfee) There shouldn't be. By default, Declude Virus will wait up to a full minute to scan the E-mail (from the time it starts the virus scanner until the time that it is done scanning the file(s)). Normally, this should only take 1-2 seconds, so it would require very heavy CPU usage for this to happen. If it *does* happen, there will be an error message in the log file mentioning it. -Scott --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com .
RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
Thanks. Ed Chabot The Marlin Firearms Company 100 Kenna Drive North Haven, CT 06473 (203)985-3254 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Craig Gittens Sent: Wednesday, August 22, 2001 10:02 AM To: [EMAIL PROTECTED] Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS Sorry, I misunderstood! :) That is a reporting function of the virus scanner. I use McAfee. If you want to set it up with yours, you can read more at: http://www.declude.com/virus/manual.htm You can edit the .eml files to say what you want. I use McAfee and point people to the Norton site because their site is a little more user friendly. Craig. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Ed Chabot Sent: Wednesday, August 22, 2001 9:18 AM To: [EMAIL PROTECTED] Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS Craig, I don't mean the header info but the following: The infected filename is "flight comfirmation.doc.pif", and the virus name was " the W32/SirCam@MM virus !!!" Armed with this information, you can try to clean it by updating your virus scanner. If you lack one, you can go to http://www.symantec.com/avcenter/tools.list.html and download a removal tool if it is available for your virus. You can learn more about the virus at http://www.symantec.com/avcenter/vinfodb.html When a virus is intercepted, the recipient, the sender and the postmaster for either domain is notified automatically. There is no need for you to take any action. Ed Chabot The Marlin Firearms Company 100 Kenna Drive North Haven, CT 06473 (203)985-3254 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Craig Gittens Sent: Tuesday, August 21, 2001 2:55 PM To: [EMAIL PROTECTED] Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS In outlook, when you have the message open, View>Options and in the window pane you will see the full headers, just copy and paste. Craig. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Ed Chabot Sent: Tuesday, August 21, 2001 2:41 PM To: [EMAIL PROTECTED] Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS How did you get all that info in the email from Declude? Mine only states the following: Declude Virus caught a virus with the subject "Snowhite and the Seven Dwarfs - The REAL story!" from <> to: [EMAIL PROTECTED] The spool file name is Daf9d0f8.SMD. Ed Chabot The Marlin Firearms Company 100 Kenna Drive North Haven, CT 06473 (203)985-3254 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Craig Gittens Sent: Tuesday, August 21, 2001 2:12 PM To: Declude. Virus List Subject: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS Guys, I have one domain on my Imail server running declude. My sales team has received multiple emails like the one below. Can anyone tell me why declude/Imail would do this? %localhost% is only supposed to send a sunbeach.net result. In addition the sales account is a valid account and not an alias. so why did mail destined for [EMAIL PROTECTED] get in his mailbox? Confused, Craig. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] Sent: Tuesday, August 21, 2001 1:45 PM To: [EMAIL PROTECTED] Subject: WARNING: YOU MAY HAVE A VIRUS Date: Tue, 21 Aug 2001 13:44:59 -0400 Message-Id: <[EMAIL PROTECTED]> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii From: <[EMAIL PROTECTED]> Reply-To: <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Subject: WARNING: YOU MAY HAVE A VIRUS X-Mailer: X-UIDL: 883329720 Status: U The Virus software on bicoltd.com has reported that you sent a virus with the subject "flight comfirmation" to: [EMAIL PROTECTED] The E-mail containing the virus has been quarantined on our servers to prevent further damage. The infected filename is "flight comfirmation.doc.pif", and the virus name was " the W32/SirCam@MM virus !!!" Armed with this information, you can try to clean it by updating your virus scanner. If you lack one, you can go to http://www.symantec.com/avcenter/tools.list.html and download a removal tool if it is available for your virus. You can learn more about the virus at http://www.symantec.com/avcenter/vinfodb.html When a virus is intercepted, the recipient, the sender and the postmaster for either domain is notified automatically. There is no need for you to take any action. Team SunBeach D9d8b10e.SMD This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com . This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL
RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
Sorry, I misunderstood! :) That is a reporting function of the virus scanner. I use McAfee. If you want to set it up with yours, you can read more at: http://www.declude.com/virus/manual.htm You can edit the .eml files to say what you want. I use McAfee and point people to the Norton site because their site is a little more user friendly. Craig. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Ed Chabot Sent: Wednesday, August 22, 2001 9:18 AM To: [EMAIL PROTECTED] Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS Craig, I don't mean the header info but the following: The infected filename is "flight comfirmation.doc.pif", and the virus name was " the W32/SirCam@MM virus !!!" Armed with this information, you can try to clean it by updating your virus scanner. If you lack one, you can go to http://www.symantec.com/avcenter/tools.list.html and download a removal tool if it is available for your virus. You can learn more about the virus at http://www.symantec.com/avcenter/vinfodb.html When a virus is intercepted, the recipient, the sender and the postmaster for either domain is notified automatically. There is no need for you to take any action. Ed Chabot The Marlin Firearms Company 100 Kenna Drive North Haven, CT 06473 (203)985-3254 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Craig Gittens Sent: Tuesday, August 21, 2001 2:55 PM To: [EMAIL PROTECTED] Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS In outlook, when you have the message open, View>Options and in the window pane you will see the full headers, just copy and paste. Craig. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Ed Chabot Sent: Tuesday, August 21, 2001 2:41 PM To: [EMAIL PROTECTED] Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS How did you get all that info in the email from Declude? Mine only states the following: Declude Virus caught a virus with the subject "Snowhite and the Seven Dwarfs - The REAL story!" from <> to: [EMAIL PROTECTED] The spool file name is Daf9d0f8.SMD. Ed Chabot The Marlin Firearms Company 100 Kenna Drive North Haven, CT 06473 (203)985-3254 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Craig Gittens Sent: Tuesday, August 21, 2001 2:12 PM To: Declude. Virus List Subject: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS Guys, I have one domain on my Imail server running declude. My sales team has received multiple emails like the one below. Can anyone tell me why declude/Imail would do this? %localhost% is only supposed to send a sunbeach.net result. In addition the sales account is a valid account and not an alias. so why did mail destined for [EMAIL PROTECTED] get in his mailbox? Confused, Craig. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] Sent: Tuesday, August 21, 2001 1:45 PM To: [EMAIL PROTECTED] Subject: WARNING: YOU MAY HAVE A VIRUS Date: Tue, 21 Aug 2001 13:44:59 -0400 Message-Id: <[EMAIL PROTECTED]> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii From: <[EMAIL PROTECTED]> Reply-To: <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Subject: WARNING: YOU MAY HAVE A VIRUS X-Mailer: X-UIDL: 883329720 Status: U The Virus software on bicoltd.com has reported that you sent a virus with the subject "flight comfirmation" to: [EMAIL PROTECTED] The E-mail containing the virus has been quarantined on our servers to prevent further damage. The infected filename is "flight comfirmation.doc.pif", and the virus name was " the W32/SirCam@MM virus !!!" Armed with this information, you can try to clean it by updating your virus scanner. If you lack one, you can go to http://www.symantec.com/avcenter/tools.list.html and download a removal tool if it is available for your virus. You can learn more about the virus at http://www.symantec.com/avcenter/vinfodb.html When a virus is intercepted, the recipient, the sender and the postmaster for either domain is notified automatically. There is no need for you to take any action. Team SunBeach D9d8b10e.SMD This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com . This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com . This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You
RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
Craig, I don't mean the header info but the following: The infected filename is "flight comfirmation.doc.pif", and the virus name was " the W32/SirCam@MM virus !!!" Armed with this information, you can try to clean it by updating your virus scanner. If you lack one, you can go to http://www.symantec.com/avcenter/tools.list.html and download a removal tool if it is available for your virus. You can learn more about the virus at http://www.symantec.com/avcenter/vinfodb.html When a virus is intercepted, the recipient, the sender and the postmaster for either domain is notified automatically. There is no need for you to take any action. Ed Chabot The Marlin Firearms Company 100 Kenna Drive North Haven, CT 06473 (203)985-3254 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Craig Gittens Sent: Tuesday, August 21, 2001 2:55 PM To: [EMAIL PROTECTED] Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS In outlook, when you have the message open, View>Options and in the window pane you will see the full headers, just copy and paste. Craig. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Ed Chabot Sent: Tuesday, August 21, 2001 2:41 PM To: [EMAIL PROTECTED] Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS How did you get all that info in the email from Declude? Mine only states the following: Declude Virus caught a virus with the subject "Snowhite and the Seven Dwarfs - The REAL story!" from <> to: [EMAIL PROTECTED] The spool file name is Daf9d0f8.SMD. Ed Chabot The Marlin Firearms Company 100 Kenna Drive North Haven, CT 06473 (203)985-3254 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Craig Gittens Sent: Tuesday, August 21, 2001 2:12 PM To: Declude. Virus List Subject: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS Guys, I have one domain on my Imail server running declude. My sales team has received multiple emails like the one below. Can anyone tell me why declude/Imail would do this? %localhost% is only supposed to send a sunbeach.net result. In addition the sales account is a valid account and not an alias. so why did mail destined for [EMAIL PROTECTED] get in his mailbox? Confused, Craig. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] Sent: Tuesday, August 21, 2001 1:45 PM To: [EMAIL PROTECTED] Subject: WARNING: YOU MAY HAVE A VIRUS Date: Tue, 21 Aug 2001 13:44:59 -0400 Message-Id: <[EMAIL PROTECTED]> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii From: <[EMAIL PROTECTED]> Reply-To: <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Subject: WARNING: YOU MAY HAVE A VIRUS X-Mailer: X-UIDL: 883329720 Status: U The Virus software on bicoltd.com has reported that you sent a virus with the subject "flight comfirmation" to: [EMAIL PROTECTED] The E-mail containing the virus has been quarantined on our servers to prevent further damage. The infected filename is "flight comfirmation.doc.pif", and the virus name was " the W32/SirCam@MM virus !!!" Armed with this information, you can try to clean it by updating your virus scanner. If you lack one, you can go to http://www.symantec.com/avcenter/tools.list.html and download a removal tool if it is available for your virus. You can learn more about the virus at http://www.symantec.com/avcenter/vinfodb.html When a virus is intercepted, the recipient, the sender and the postmaster for either domain is notified automatically. There is no need for you to take any action. Team SunBeach D9d8b10e.SMD This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com . This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com . This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com . This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com .
RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
Note that I use an external database, SQL 7 running on it's own server over a switched 100MB ethernet backbone. Craig. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of R. Scott Perry Sent: Tuesday, August 21, 2001 3:34 PM To: [EMAIL PROTECTED] Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS >I understand this Scott. It worked correctly and addressed the email to >[EMAIL PROTECTED] So why did it drop it into the [EMAIL PROTECTED] mailbox >instead of sending it out to THEIR server? That sounds like a problem with the IMail "imail1.exe" program. It's pretty strange, and requires that you tell it the host name of the sending server. It may have mangled the address somehow. I'll see if I can reproduce that here. Someone else had recently suggested that we add a setting to allow you to use other mailers, such as blat, that could be used instead of imail1.exe. -Scott This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com . This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com .
RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
>I understand this Scott. It worked correctly and addressed the email to >[EMAIL PROTECTED] So why did it drop it into the [EMAIL PROTECTED] mailbox >instead of sending it out to THEIR server? That sounds like a problem with the IMail "imail1.exe" program. It's pretty strange, and requires that you tell it the host name of the sending server. It may have mangled the address somehow. I'll see if I can reproduce that here. Someone else had recently suggested that we add a setting to allow you to use other mailers, such as blat, that could be used instead of imail1.exe. -Scott This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com .
RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
I understand this Scott. It worked correctly and addressed the email to [EMAIL PROTECTED] So why did it drop it into the [EMAIL PROTECTED] mailbox instead of sending it out to THEIR server? Craig. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of R. Scott Perry Sent: Tuesday, August 21, 2001 3:11 PM To: [EMAIL PROTECTED] Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS >I get that. But why did Imail drop the email into [EMAIL PROTECTED] account >which is the only domain on the server? Why did it not send it off to the >correct place? The %LOCALHOST% variable will return the domain of the local user (the one on your domain). If the person is relaying their mail (neither the sender nor the recipient are local), %LOCALHOST% will now use the master host name (so that it truly is local). -Scott This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com . This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com .
Re: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
You have to edit the default emails that come with Declude. Scott has instructions on his site. David Daniels System Administrator Starfish Internet Service [EMAIL PROTECTED] "Clicking my fingers to the bone" - Original Message - From: "Ed Chabot" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Tuesday, August 21, 2001 2:40 PM Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS > How did you get all that info in the email from Declude? Mine only states > the following: > > Declude Virus caught a virus with the subject "Snowhite and the Seven > Dwarfs - The REAL story!" > from <> to: [EMAIL PROTECTED] > > The spool file name is Daf9d0f8.SMD. > > Ed Chabot > The Marlin Firearms Company > 100 Kenna Drive > North Haven, CT 06473 > (203)985-3254 > > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED]]On Behalf Of Craig Gittens > Sent: Tuesday, August 21, 2001 2:12 PM > To: Declude. Virus List > Subject: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS > > > Guys, > > I have one domain on my Imail server running declude. My sales team has > received multiple emails like the one below. Can anyone tell me why > declude/Imail would do this? %localhost% is only supposed to send a > sunbeach.net result. In addition the sales account is a valid account and > not an alias. so why did mail destined for [EMAIL PROTECTED] get in his > mailbox? > > Confused, > > Craig. > > > -Original Message- > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] > Sent: Tuesday, August 21, 2001 1:45 PM > To: [EMAIL PROTECTED] > Subject: WARNING: YOU MAY HAVE A VIRUS > Date: Tue, 21 Aug 2001 13:44:59 -0400 > > Message-Id: <[EMAIL PROTECTED]> > Mime-Version: 1.0 > Content-Type: text/plain; charset=us-ascii > From: <[EMAIL PROTECTED]> > Reply-To: <[EMAIL PROTECTED]> > To: <[EMAIL PROTECTED]> > Subject: WARNING: YOU MAY HAVE A VIRUS > X-Mailer: > X-UIDL: 883329720 > Status: U > > The Virus software on bicoltd.com has reported that you sent > a virus with the subject "flight comfirmation" to: > [EMAIL PROTECTED] > > The E-mail containing the virus has been quarantined on our servers to > prevent further damage. > > The infected filename is "flight comfirmation.doc.pif", and the virus name > was " the W32/SirCam@MM virus !!!" > > Armed with this information, you can try to clean it by updating your virus > scanner. > If you lack one, you can go to > http://www.symantec.com/avcenter/tools.list.html > and download a removal tool if it is available for your virus. You can learn > more > about the virus at http://www.symantec.com/avcenter/vinfodb.html > > When a virus is intercepted, the recipient, the sender and the postmaster > for > either domain is notified automatically. There is no need for you to take > any > action. > > > Team SunBeach > > > D9d8b10e.SMD > > > > This E-mail came from the Declude.Virus mailing list. To > unsubscribe, just send an E-mail to [EMAIL PROTECTED], and > type "unsubscribe Declude.Virus". You can E-mail > [EMAIL PROTECTED] for assistance. You can visit our web > site at http://www.declude.com . > > This E-mail came from the Declude.Virus mailing list. To > unsubscribe, just send an E-mail to [EMAIL PROTECTED], and > type "unsubscribe Declude.Virus". You can E-mail > [EMAIL PROTECTED] for assistance. You can visit our web > site at http://www.declude.com . > This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com .
RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
>I get that. But why did Imail drop the email into [EMAIL PROTECTED] account >which is the only domain on the server? Why did it not send it off to the >correct place? The %LOCALHOST% variable will return the domain of the local user (the one on your domain). If the person is relaying their mail (neither the sender nor the recipient are local), %LOCALHOST% will now use the master host name (so that it truly is local). -Scott This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com .
RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
>How did you get all that info in the email from Declude? Mine only states >the following: > >Declude Virus caught a virus with the subject "Snowhite and the Seven >Dwarfs - The REAL story!" >from <> to: [EMAIL PROTECTED] > >The spool file name is Daf9d0f8.SMD. The E-mail template files are fully customizeable. You can look in the "E-mail Notifications" section of the manual for information on the variables you can use in there. I believe that the templates have recently been updated to include more information in them. -Scott This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com .
RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
In outlook, when you have the message open, View>Options and in the window pane you will see the full headers, just copy and paste. Craig. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Ed Chabot Sent: Tuesday, August 21, 2001 2:41 PM To: [EMAIL PROTECTED] Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS How did you get all that info in the email from Declude? Mine only states the following: Declude Virus caught a virus with the subject "Snowhite and the Seven Dwarfs - The REAL story!" from <> to: [EMAIL PROTECTED] The spool file name is Daf9d0f8.SMD. Ed Chabot The Marlin Firearms Company 100 Kenna Drive North Haven, CT 06473 (203)985-3254 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Craig Gittens Sent: Tuesday, August 21, 2001 2:12 PM To: Declude. Virus List Subject: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS Guys, I have one domain on my Imail server running declude. My sales team has received multiple emails like the one below. Can anyone tell me why declude/Imail would do this? %localhost% is only supposed to send a sunbeach.net result. In addition the sales account is a valid account and not an alias. so why did mail destined for [EMAIL PROTECTED] get in his mailbox? Confused, Craig. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] Sent: Tuesday, August 21, 2001 1:45 PM To: [EMAIL PROTECTED] Subject: WARNING: YOU MAY HAVE A VIRUS Date: Tue, 21 Aug 2001 13:44:59 -0400 Message-Id: <[EMAIL PROTECTED]> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii From: <[EMAIL PROTECTED]> Reply-To: <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Subject: WARNING: YOU MAY HAVE A VIRUS X-Mailer: X-UIDL: 883329720 Status: U The Virus software on bicoltd.com has reported that you sent a virus with the subject "flight comfirmation" to: [EMAIL PROTECTED] The E-mail containing the virus has been quarantined on our servers to prevent further damage. The infected filename is "flight comfirmation.doc.pif", and the virus name was " the W32/SirCam@MM virus !!!" Armed with this information, you can try to clean it by updating your virus scanner. If you lack one, you can go to http://www.symantec.com/avcenter/tools.list.html and download a removal tool if it is available for your virus. You can learn more about the virus at http://www.symantec.com/avcenter/vinfodb.html When a virus is intercepted, the recipient, the sender and the postmaster for either domain is notified automatically. There is no need for you to take any action. Team SunBeach D9d8b10e.SMD This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com . This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com . This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com .
RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
I get that. But why did Imail drop the email into [EMAIL PROTECTED] account which is the only domain on the server? Why did it not send it off to the correct place? Craig. Here is the header from the actual email: (196 is my dialup block) Received: from ezra [196.3.219.102] by sunbeach.net (SMTPD32-6.06) id AD8B2832010E; Tue, 21 Aug 2001 13:42:35 -0400 From: "Ezra Tull"<[EMAIL PROTECTED]> To: [EMAIL PROTECTED] Subject: flight comfirmation date: Tue, 21 Aug 2001 13:42:59 -0300 MIME-Version: 1.0 X-MIMEOLE: Produced By Microsoft MimeOLE V5.50.4133.2400 X-Mailer: Microsoft Outlook Express 5.50.4133.2400 Content-Type: multipart/mixed; boundary="09E443FE_Outlook_Express_message_boundary" Content-Disposition: Multipart message Message-Id: <200108211342781.SM01884@ezra> This message would get sent if [EMAIL PROTECTED] sent an E-mail to [EMAIL PROTECTED] with a virus in it. Did they not send an E-mail with the "flight confirmation.doc.pif" file attached? -Scott This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com . This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com .
RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
How did you get all that info in the email from Declude? Mine only states the following: Declude Virus caught a virus with the subject "Snowhite and the Seven Dwarfs - The REAL story!" from <> to: [EMAIL PROTECTED] The spool file name is Daf9d0f8.SMD. Ed Chabot The Marlin Firearms Company 100 Kenna Drive North Haven, CT 06473 (203)985-3254 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Craig Gittens Sent: Tuesday, August 21, 2001 2:12 PM To: Declude. Virus List Subject: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS Guys, I have one domain on my Imail server running declude. My sales team has received multiple emails like the one below. Can anyone tell me why declude/Imail would do this? %localhost% is only supposed to send a sunbeach.net result. In addition the sales account is a valid account and not an alias. so why did mail destined for [EMAIL PROTECTED] get in his mailbox? Confused, Craig. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] Sent: Tuesday, August 21, 2001 1:45 PM To: [EMAIL PROTECTED] Subject: WARNING: YOU MAY HAVE A VIRUS Date: Tue, 21 Aug 2001 13:44:59 -0400 Message-Id: <[EMAIL PROTECTED]> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii From: <[EMAIL PROTECTED]> Reply-To: <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Subject: WARNING: YOU MAY HAVE A VIRUS X-Mailer: X-UIDL: 883329720 Status: U The Virus software on bicoltd.com has reported that you sent a virus with the subject "flight comfirmation" to: [EMAIL PROTECTED] The E-mail containing the virus has been quarantined on our servers to prevent further damage. The infected filename is "flight comfirmation.doc.pif", and the virus name was " the W32/SirCam@MM virus !!!" Armed with this information, you can try to clean it by updating your virus scanner. If you lack one, you can go to http://www.symantec.com/avcenter/tools.list.html and download a removal tool if it is available for your virus. You can learn more about the virus at http://www.symantec.com/avcenter/vinfodb.html When a virus is intercepted, the recipient, the sender and the postmaster for either domain is notified automatically. There is no need for you to take any action. Team SunBeach D9d8b10e.SMD This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com . This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com .