Re: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2003-09-06 Thread andyb
Is this BS really necessary?  If you don't like someone, can't you keep it
to yourself?

A simple philosophy, don't be annoying and don't be easily annoyed.

John may have a big ego...so what?!  I haven't met a computer engineer yet
worth a darn that doesn't have a big ego.  It take a lot of moxy to be
responsible for hundreds/thousands of users computers/accounts when the crap
is flying all around and you are the one getting yelled at.

I've been on/watching this list for a long time.  I don't always like the
answers I get, but the people here DO HELP ME.  That is the bottom line,
isn't it?

Or is it about hurting egos?  Personally, I don't think there is room for
ego in the business world.  I don't think any of us are here for the fun of
it, but to make money, right?  If I have to supress my ego to get the
answers I need and to get the job done, SO BE IT.

Come to think of it, we are usually guilty of what we accuse others of.

> In my experience it's people with bloated egos who attempt to publically
ridicule and chastise.
> Mike Tindor

I think it would be helpful to remember that John and others like him are
NOT GETTING PAID to help with your issues or mine.  This IS THE SPIRIT of
the Internet, all of us helping each other, the best we can.

That's my 2 cents worth.  And I've been in this business a long time, 16
years, 8 of it running ISP's and being responsible for corporate networks.
I don't have to like John's approach to *respect* him and his efforts on
this list.

Now, can we all be nice to each other in this sand box...PLEASE?!

Andrew
Thumpernet

- Original Message -
From: "FIRST Internet Declude Virus Account" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Saturday, September 06, 2003 12:25 PM
Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS


> I'd have to agree.
>
> I guess all of the letters after John's name have gone to his head.
>
> In my experience it's people with bloated egos who attempt to publically
ridicule and chastise.  Seems to me a friendly note directly to the admin
would have been more appropriate.
>
> Mike Tindor
>
> -- Original Message --
> From: "Tim Collins" <[EMAIL PROTECTED]>
> Reply-To: [EMAIL PROTECTED]
> Date:  Sat, 30 Aug 2003 07:55:41 -0500
>
> >John Tolmachoff,
> >
> >Personally, I have 2 months experience with my new ISP company and
> >Declude.
> >Not everyone is as smart as you.
> >Maybe you should leave the List and start your own discussion group.
> >
> >The only stupid question is the one that is not asked.  Often, there is
> >more than one way to do something.
> >
> >Please keep your personal comments to yourself.
> >
> >Tim Collins
> >
> >-Original Message-
> >From: [EMAIL PROTECTED]
> >[mailto:[EMAIL PROTECTED] On Behalf Of John Tolmachoff
> >(Lists)
> >Sent: Saturday, August 30, 2003 12:19 AM
> >To: [EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED];
> >[EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED]
> >Cc: [EMAIL PROTECTED]
> >Subject: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
> >Importance: High
> >
> >
> >After all this has been talked about, that Sobig forges the sender, this
> >pisses me off.
> >
> >Do you not know how to add FORGINGVIRUS and SKIPIFVIRUSNAMEHAS to the
> >config and e-mail files?
> >
> >Get your bleeping act together or forfeit your Declude software to
> >someone who knows how to use it.
> >
> >John Tolmachoff MCSE CSSA
> >Engineer/Consultant
> >eServices For You
> >www.eservicesforyou.com
> >
> >> -Original Message-
> >> From: Postmaster [mailto:[EMAIL PROTECTED]
> >> Sent: Friday, August 29, 2003 7:58 PM
> >> To: [EMAIL PROTECTED]
> >> Subject: WARNING: YOU MAY HAVE A VIRUS
> >>
> >> The Declude Virus software on lcs.net has reported that you sent an
> >> E-mail to [EMAIL PROTECTED], containing the Unknown Virus virus in
> >the
> >> Unknown File attachment.  The subject of the E-mail was "Your
> >> details". The E-mail containing the virus has been quarantined to
> >> prevent further
> >damage.
> >>
> >> Headers Follow:
> >> Received: from ARNOLDS_ROOM [160.36.73.149] by lcs.net with ESMTP
> >>   (SMTPD32-7.07) id A2A72C08013C; Fri, 29 Aug 2003 22:57:43 -0400
> >> From: <[EMAIL PROTECTED]>
> >> To: <[EMAIL PROTECTED]>
> >> Subject: Your details
> >> Date: Fri, 29 Aug 2003 22:59:36 --0400
> >> X-MailSca

RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2003-09-06 Thread FIRST Internet Declude Virus Account
I'd have to agree.

I guess all of the letters after John's name have gone to his head.

In my experience it's people with bloated egos who attempt to publically ridicule and 
chastise.  Seems to me a friendly note directly to the admin would have been more 
appropriate.

Mike Tindor

-- Original Message --
From: "Tim Collins" <[EMAIL PROTECTED]>
Reply-To: [EMAIL PROTECTED]
Date:  Sat, 30 Aug 2003 07:55:41 -0500

>John Tolmachoff,
>
>Personally, I have 2 months experience with my new ISP company and
>Declude.
>Not everyone is as smart as you.
>Maybe you should leave the List and start your own discussion group.
>
>The only stupid question is the one that is not asked.  Often, there is
>more than one way to do something.
>
>Please keep your personal comments to yourself.
>
>Tim Collins
>
>-Original Message-
>From: [EMAIL PROTECTED]
>[mailto:[EMAIL PROTECTED] On Behalf Of John Tolmachoff
>(Lists)
>Sent: Saturday, August 30, 2003 12:19 AM
>To: [EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED];
>[EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED]
>Cc: [EMAIL PROTECTED]
>Subject: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
>Importance: High
>
>
>After all this has been talked about, that Sobig forges the sender, this
>pisses me off.
>
>Do you not know how to add FORGINGVIRUS and SKIPIFVIRUSNAMEHAS to the
>config and e-mail files?
>
>Get your bleeping act together or forfeit your Declude software to
>someone who knows how to use it.
>
>John Tolmachoff MCSE CSSA
>Engineer/Consultant
>eServices For You
>www.eservicesforyou.com
>
>> -Original Message-
>> From: Postmaster [mailto:[EMAIL PROTECTED]
>> Sent: Friday, August 29, 2003 7:58 PM
>> To: [EMAIL PROTECTED]
>> Subject: WARNING: YOU MAY HAVE A VIRUS
>> 
>> The Declude Virus software on lcs.net has reported that you sent an 
>> E-mail to [EMAIL PROTECTED], containing the Unknown Virus virus in
>the
>> Unknown File attachment.  The subject of the E-mail was "Your 
>> details". The E-mail containing the virus has been quarantined to 
>> prevent further
>damage.
>> 
>> Headers Follow:
>> Received: from ARNOLDS_ROOM [160.36.73.149] by lcs.net with ESMTP
>>   (SMTPD32-7.07) id A2A72C08013C; Fri, 29 Aug 2003 22:57:43 -0400
>> From: <[EMAIL PROTECTED]>
>> To: <[EMAIL PROTECTED]>
>> Subject: Your details
>> Date: Fri, 29 Aug 2003 22:59:36 --0400
>> X-MailScanner: Found to be clean
>> Importance: Normal
>> X-Mailer: Microsoft Outlook Express 6.00.2600.
>> X-MSMail-Priority: Normal
>> X-Priority: 3 (Normal)
>> MIME-Version: 1.0
>> Content-Type: multipart/mixed;
>>  boundary="_NextPart_000_7E49D478"
>> Message-Id: <[EMAIL PROTECTED]>
>> 
>
>
>---
>[This E-mail was scanned for viruses by Declude Virus
>(http://www.declude.com)]
>
>---
>This E-mail came from the Declude.Virus mailing list.  To unsubscribe,
>just send an E-mail to [EMAIL PROTECTED], and
>type "unsubscribe Declude.Virus".The archives can be found
>at http://www.mail-archive.com.
>
>
>
>---
>[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
>
>---
>This E-mail came from the Declude.Virus mailing list.  To
>unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
>type "unsubscribe Declude.Virus".The archives can be found
>at http://www.mail-archive.com.
>
 





Sent via the WebMail system at 1st.net


 
   
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".The archives can be found
at http://www.mail-archive.com.


RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2003-09-02 Thread John Tolmachoff \(Lists\)
1. If the message gets through because it is a corrupt version and
non-viable, it will be delivered to the recipient, so no notification is
sent.

2. If the virus scanner catches it but is not sure, it should report virus
name Unknown. You can then add SKIPIFVIRUSNAMEHAS unknown in the appropriate
.eml files.

3. If the message does not get picked up as infected, but has an banned
attachment, it should be caught by that banned attachment.

4. You can also set up filter tests in JM to catch notifications/bounces
from other servers.

John Tolmachoff MCSE CSSA
Engineer/Consultant
eServices For You
www.eservicesforyou.com

> -Original Message-
> From: [EMAIL PROTECTED] [mailto:Declude.Virus-
> [EMAIL PROTECTED] On Behalf Of paul
> Sent: Tuesday, September 02, 2003 12:55 PM
> To: [EMAIL PROTECTED]
> Subject: Re: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
> 
> John, Scott, everyone.
> 
> Question to this.
> 
> I have the SKIPIF lines in my eml files, but I was curious, what
happens
> to the corrupt versions of Sobig, etc that the attachments get through due
> to no virus? Since these return addresses are no doubt bogus, is there a
> guard against this? Do we have a SKIPIFATTACHMENTIS .scr option?
> 
> Paul
> 
> 
> ---
> [This E-mail scanned for viruses by Declude Virus]
> 
> ---
> [This E-mail was scanned for viruses by Declude Virus
(http://www.declude.com)]
> 
> ---
> This E-mail came from the Declude.Virus mailing list.  To
> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
> type "unsubscribe Declude.Virus".The archives can be found
> at http://www.mail-archive.com.

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".The archives can be found
at http://www.mail-archive.com.


Re: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2003-09-02 Thread R. Scott Perry

I have the SKIPIF lines in my eml files, but I was curious, what happens
to the corrupt versions of Sobig, etc that the attachments get through due
to no virus? Since these return addresses are no doubt bogus, is there a
guard against this? Do we have a SKIPIFATTACHMENTIS .scr option?
No, there is no way to do that.

   -Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver 
vulnerability detection.
Find out what you have been missing: Ask for a free 30-day evaluation.

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".The archives can be found
at http://www.mail-archive.com.


Re: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2003-09-02 Thread paul
John, Scott, everyone.

Question to this.

I have the SKIPIF lines in my eml files, but I was curious, what happens
to the corrupt versions of Sobig, etc that the attachments get through due
to no virus? Since these return addresses are no doubt bogus, is there a
guard against this? Do we have a SKIPIFATTACHMENTIS .scr option?

Paul


---
[This E-mail scanned for viruses by Declude Virus]

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".The archives can be found
at http://www.mail-archive.com.


RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2003-08-30 Thread John Tolmachoff \(Lists\)
> Personally, I have 2 months experience with my new ISP company and
> Declude.
> Not everyone is as smart as you.
> Maybe you should leave the List and start your own discussion group.

Excuse you, but unless you have been hiding under a rock, the fact the Sobig
forges the sender has been discussed plenty in the last 2 weeks on this
list, as well as others including the Imail list, which quite falls within
the last 2 months. Get your facts straight before making a comment.

Any AV software or admins that have it misconfigured that is continuing to
send out notices at this time to forged senders deserves to be ridiculed.
All they are doing is adding to the problem, of additional traffic on the
internet, of confused users, of additional phone calls of help I am
infected, of accusations that some one is spreading the virus erroneously.

BTW, Sobig has been known to forge the sender for months, since the first
version. Any one new to Declude would have downloaded the current .eml and
config files, which have already included the proper lines to not send out
notifications to forged senders. Therefore, these are people who have been
running Declude for a while, and therefore are not new to it.

John Tolmachoff MCSE CSSA
Engineer/Consultant
eServices For You
www.eservicesforyou.com


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".The archives can be found
at http://www.mail-archive.com.


RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2003-08-30 Thread Tim Collins
John Tolmachoff,

Personally, I have 2 months experience with my new ISP company and
Declude.
Not everyone is as smart as you.
Maybe you should leave the List and start your own discussion group.

The only stupid question is the one that is not asked.  Often, there is
more than one way to do something.

Please keep your personal comments to yourself.

Tim Collins

-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of John Tolmachoff
(Lists)
Sent: Saturday, August 30, 2003 12:19 AM
To: [EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED];
[EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED]
Cc: [EMAIL PROTECTED]
Subject: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
Importance: High


After all this has been talked about, that Sobig forges the sender, this
pisses me off.

Do you not know how to add FORGINGVIRUS and SKIPIFVIRUSNAMEHAS to the
config and e-mail files?

Get your bleeping act together or forfeit your Declude software to
someone who knows how to use it.

John Tolmachoff MCSE CSSA
Engineer/Consultant
eServices For You
www.eservicesforyou.com

> -Original Message-
> From: Postmaster [mailto:[EMAIL PROTECTED]
> Sent: Friday, August 29, 2003 7:58 PM
> To: [EMAIL PROTECTED]
> Subject: WARNING: YOU MAY HAVE A VIRUS
> 
> The Declude Virus software on lcs.net has reported that you sent an 
> E-mail to [EMAIL PROTECTED], containing the Unknown Virus virus in
the
> Unknown File attachment.  The subject of the E-mail was "Your 
> details". The E-mail containing the virus has been quarantined to 
> prevent further
damage.
> 
> Headers Follow:
> Received: from ARNOLDS_ROOM [160.36.73.149] by lcs.net with ESMTP
>   (SMTPD32-7.07) id A2A72C08013C; Fri, 29 Aug 2003 22:57:43 -0400
> From: <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Subject: Your details
> Date: Fri, 29 Aug 2003 22:59:36 --0400
> X-MailScanner: Found to be clean
> Importance: Normal
> X-Mailer: Microsoft Outlook Express 6.00.2600.
> X-MSMail-Priority: Normal
> X-Priority: 3 (Normal)
> MIME-Version: 1.0
> Content-Type: multipart/mixed;
>   boundary="_NextPart_000_7E49D478"
> Message-Id: <[EMAIL PROTECTED]>
> 


---
[This E-mail was scanned for viruses by Declude Virus
(http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To unsubscribe,
just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".The archives can be found
at http://www.mail-archive.com.



---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".The archives can be found
at http://www.mail-archive.com.


RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2003-08-30 Thread Marc Catuogno
I had to argue with an IMAIL admin with Declude for two days and had to
e-mail him the damn otherpostmaster and sender eml files before he would
change them.

I hope my change took effect...  : )

-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of John Tolmachoff
(Lists)
Sent: Saturday, August 30, 2003 2:19 AM
To: [EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED];
[EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED]
Cc: [EMAIL PROTECTED]
Subject: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
Importance: High

After all this has been talked about, that Sobig forges the sender, this
pisses me off.

Do you not know how to add FORGINGVIRUS and SKIPIFVIRUSNAMEHAS to the
config
and e-mail files?

Get your bleeping act together or forfeit your Declude software to
someone
who knows how to use it.

John Tolmachoff MCSE CSSA
Engineer/Consultant
eServices For You
www.eservicesforyou.com

> -Original Message-
> From: Postmaster [mailto:[EMAIL PROTECTED]
> Sent: Friday, August 29, 2003 7:58 PM
> To: [EMAIL PROTECTED]
> Subject: WARNING: YOU MAY HAVE A VIRUS
> 
> The Declude Virus software on lcs.net has reported that you
> sent an E-mail to [EMAIL PROTECTED], containing the Unknown Virus virus
in
the
> Unknown File attachment.  The subject of the E-mail was "Your
details".
> The E-mail containing the virus has been quarantined to prevent
further
damage.
> 
> Headers Follow:
> Received: from ARNOLDS_ROOM [160.36.73.149] by lcs.net with ESMTP
>   (SMTPD32-7.07) id A2A72C08013C; Fri, 29 Aug 2003 22:57:43 -0400
> From: <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Subject: Your details
> Date: Fri, 29 Aug 2003 22:59:36 --0400
> X-MailScanner: Found to be clean
> Importance: Normal
> X-Mailer: Microsoft Outlook Express 6.00.2600.
> X-MSMail-Priority: Normal
> X-Priority: 3 (Normal)
> MIME-Version: 1.0
> Content-Type: multipart/mixed;
>   boundary="_NextPart_000_7E49D478"
> Message-Id: <[EMAIL PROTECTED]>
> 


---
[This E-mail was scanned for viruses by Declude Virus
(http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".The archives can be found
at http://www.mail-archive.com.
---
[This E-mail scanned for viruses by Declude Virus]



---
[This E-mail scanned for viruses by Declude Virus]

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".The archives can be found
at http://www.mail-archive.com.


Re: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2002-02-21 Thread R. Scott Perry


>I sent off a couple of files to virustrap to see if they would get caught.
>They did. However, they didn't get caught the first time I was sent them.
>([EMAIL PROTECTED])

>I was wondering if they were not caught earlier because I sent a mailall and
>the server was under load? Are there circumstances where this can happen
>Scott? (Using McAfee)

There shouldn't be.

By default, Declude Virus will wait up to a full minute to scan the E-mail 
(from the time it starts the virus scanner until the time that it is done 
scanning the file(s)).  Normally, this should only take 1-2 seconds, so it 
would require very heavy CPU usage for this to happen.  If it *does* 
happen, there will be an error message in the log file mentioning it.
 -Scott

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .



RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2001-08-22 Thread Ed Chabot

Thanks.

Ed Chabot
The Marlin Firearms Company
100 Kenna Drive
North Haven, CT 06473
(203)985-3254

-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Craig Gittens
Sent: Wednesday, August 22, 2001 10:02 AM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS


Sorry, I misunderstood! :) That is a reporting function of the virus
scanner. I use McAfee. If you want to set it up with yours, you can read
more at: http://www.declude.com/virus/manual.htm You can edit the .eml files
to say what you want. I use McAfee and point people to the Norton site
because their site is a little more user friendly.


Craig.

-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Ed Chabot
Sent: Wednesday, August 22, 2001 9:18 AM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS


Craig,
I don't mean the header info but the following:

The infected filename is "flight comfirmation.doc.pif", and the virus name
was " the W32/SirCam@MM virus !!!"

Armed with this information, you can try to clean it by updating your virus
scanner.
If you lack one, you can go to
http://www.symantec.com/avcenter/tools.list.html
and download a removal tool if it is available for your virus. You can learn
more
about the virus at http://www.symantec.com/avcenter/vinfodb.html

When a virus is intercepted, the recipient, the sender and the postmaster
for
either domain is notified automatically. There is no need for you to take
any
action.

Ed Chabot
The Marlin Firearms Company
100 Kenna Drive
North Haven, CT 06473
(203)985-3254

-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Craig Gittens
Sent: Tuesday, August 21, 2001 2:55 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS


In outlook, when you have the message open, View>Options and in the window
pane you will see the full headers, just copy and paste.

Craig.

-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Ed Chabot
Sent: Tuesday, August 21, 2001 2:41 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS


How did you get all that info in the email from Declude?  Mine only states
the following:

Declude Virus caught a virus with the subject "Snowhite and the Seven
Dwarfs - The REAL story!"
from <> to:  [EMAIL PROTECTED]

The spool file name is Daf9d0f8.SMD.

Ed Chabot
The Marlin Firearms Company
100 Kenna Drive
North Haven, CT 06473
(203)985-3254

-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Craig Gittens
Sent: Tuesday, August 21, 2001 2:12 PM
To: Declude. Virus List
Subject: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS


Guys,

I have one domain on my Imail server running declude. My sales team has
received multiple emails like the one below. Can anyone tell me why
declude/Imail would do this? %localhost% is only supposed to send a
sunbeach.net result. In addition the sales account is a valid account and
not an alias. so why did mail destined for [EMAIL PROTECTED] get in his
mailbox?

Confused,

Craig.


-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, August 21, 2001 1:45 PM
To: [EMAIL PROTECTED]
Subject: WARNING: YOU MAY HAVE A VIRUS
Date: Tue, 21 Aug 2001 13:44:59 -0400

Message-Id: <[EMAIL PROTECTED]>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
From: <[EMAIL PROTECTED]>
Reply-To: <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Subject: WARNING: YOU MAY HAVE A VIRUS
X-Mailer: 
X-UIDL: 883329720
Status: U

The Virus software on bicoltd.com has reported that you sent
a virus with the subject "flight comfirmation" to:
[EMAIL PROTECTED]

The E-mail containing the virus has been quarantined on our servers to
prevent further damage.

The infected filename is "flight comfirmation.doc.pif", and the virus name
was " the W32/SirCam@MM virus !!!"

Armed with this information, you can try to clean it by updating your virus
scanner.
If you lack one, you can go to
http://www.symantec.com/avcenter/tools.list.html
and download a removal tool if it is available for your virus. You can learn
more
about the virus at http://www.symantec.com/avcenter/vinfodb.html

When a virus is intercepted, the recipient, the sender and the postmaster
for
either domain is notified automatically. There is no need for you to take
any
action.


Team SunBeach


D9d8b10e.SMD



This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL 

RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2001-08-22 Thread Craig Gittens

Sorry, I misunderstood! :) That is a reporting function of the virus
scanner. I use McAfee. If you want to set it up with yours, you can read
more at: http://www.declude.com/virus/manual.htm You can edit the .eml files
to say what you want. I use McAfee and point people to the Norton site
because their site is a little more user friendly.


Craig.

-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Ed Chabot
Sent: Wednesday, August 22, 2001 9:18 AM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS


Craig,
I don't mean the header info but the following:

The infected filename is "flight comfirmation.doc.pif", and the virus name
was " the W32/SirCam@MM virus !!!"

Armed with this information, you can try to clean it by updating your virus
scanner.
If you lack one, you can go to
http://www.symantec.com/avcenter/tools.list.html
and download a removal tool if it is available for your virus. You can learn
more
about the virus at http://www.symantec.com/avcenter/vinfodb.html

When a virus is intercepted, the recipient, the sender and the postmaster
for
either domain is notified automatically. There is no need for you to take
any
action.

Ed Chabot
The Marlin Firearms Company
100 Kenna Drive
North Haven, CT 06473
(203)985-3254

-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Craig Gittens
Sent: Tuesday, August 21, 2001 2:55 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS


In outlook, when you have the message open, View>Options and in the window
pane you will see the full headers, just copy and paste.

Craig.

-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Ed Chabot
Sent: Tuesday, August 21, 2001 2:41 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS


How did you get all that info in the email from Declude?  Mine only states
the following:

Declude Virus caught a virus with the subject "Snowhite and the Seven
Dwarfs - The REAL story!"
from <> to:  [EMAIL PROTECTED]

The spool file name is Daf9d0f8.SMD.

Ed Chabot
The Marlin Firearms Company
100 Kenna Drive
North Haven, CT 06473
(203)985-3254

-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Craig Gittens
Sent: Tuesday, August 21, 2001 2:12 PM
To: Declude. Virus List
Subject: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS


Guys,

I have one domain on my Imail server running declude. My sales team has
received multiple emails like the one below. Can anyone tell me why
declude/Imail would do this? %localhost% is only supposed to send a
sunbeach.net result. In addition the sales account is a valid account and
not an alias. so why did mail destined for [EMAIL PROTECTED] get in his
mailbox?

Confused,

Craig.


-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, August 21, 2001 1:45 PM
To: [EMAIL PROTECTED]
Subject: WARNING: YOU MAY HAVE A VIRUS
Date: Tue, 21 Aug 2001 13:44:59 -0400

Message-Id: <[EMAIL PROTECTED]>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
From: <[EMAIL PROTECTED]>
Reply-To: <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Subject: WARNING: YOU MAY HAVE A VIRUS
X-Mailer: 
X-UIDL: 883329720
Status: U

The Virus software on bicoltd.com has reported that you sent
a virus with the subject "flight comfirmation" to:
[EMAIL PROTECTED]

The E-mail containing the virus has been quarantined on our servers to
prevent further damage.

The infected filename is "flight comfirmation.doc.pif", and the virus name
was " the W32/SirCam@MM virus !!!"

Armed with this information, you can try to clean it by updating your virus
scanner.
If you lack one, you can go to
http://www.symantec.com/avcenter/tools.list.html
and download a removal tool if it is available for your virus. You can learn
more
about the virus at http://www.symantec.com/avcenter/vinfodb.html

When a virus is intercepted, the recipient, the sender and the postmaster
for
either domain is notified automatically. There is no need for you to take
any
action.


Team SunBeach


D9d8b10e.SMD



This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You

RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2001-08-22 Thread Ed Chabot

Craig,
I don't mean the header info but the following:

The infected filename is "flight comfirmation.doc.pif", and the virus name
was " the W32/SirCam@MM virus !!!"

Armed with this information, you can try to clean it by updating your virus
scanner.
If you lack one, you can go to
http://www.symantec.com/avcenter/tools.list.html
and download a removal tool if it is available for your virus. You can learn
more
about the virus at http://www.symantec.com/avcenter/vinfodb.html

When a virus is intercepted, the recipient, the sender and the postmaster
for
either domain is notified automatically. There is no need for you to take
any
action.

Ed Chabot
The Marlin Firearms Company
100 Kenna Drive
North Haven, CT 06473
(203)985-3254

-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Craig Gittens
Sent: Tuesday, August 21, 2001 2:55 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS


In outlook, when you have the message open, View>Options and in the window
pane you will see the full headers, just copy and paste.

Craig.

-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Ed Chabot
Sent: Tuesday, August 21, 2001 2:41 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS


How did you get all that info in the email from Declude?  Mine only states
the following:

Declude Virus caught a virus with the subject "Snowhite and the Seven
Dwarfs - The REAL story!"
from <> to:  [EMAIL PROTECTED]

The spool file name is Daf9d0f8.SMD.

Ed Chabot
The Marlin Firearms Company
100 Kenna Drive
North Haven, CT 06473
(203)985-3254

-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Craig Gittens
Sent: Tuesday, August 21, 2001 2:12 PM
To: Declude. Virus List
Subject: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS


Guys,

I have one domain on my Imail server running declude. My sales team has
received multiple emails like the one below. Can anyone tell me why
declude/Imail would do this? %localhost% is only supposed to send a
sunbeach.net result. In addition the sales account is a valid account and
not an alias. so why did mail destined for [EMAIL PROTECTED] get in his
mailbox?

Confused,

Craig.


-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, August 21, 2001 1:45 PM
To: [EMAIL PROTECTED]
Subject: WARNING: YOU MAY HAVE A VIRUS
Date: Tue, 21 Aug 2001 13:44:59 -0400

Message-Id: <[EMAIL PROTECTED]>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
From: <[EMAIL PROTECTED]>
Reply-To: <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Subject: WARNING: YOU MAY HAVE A VIRUS
X-Mailer: 
X-UIDL: 883329720
Status: U

The Virus software on bicoltd.com has reported that you sent
a virus with the subject "flight comfirmation" to:
[EMAIL PROTECTED]

The E-mail containing the virus has been quarantined on our servers to
prevent further damage.

The infected filename is "flight comfirmation.doc.pif", and the virus name
was " the W32/SirCam@MM virus !!!"

Armed with this information, you can try to clean it by updating your virus
scanner.
If you lack one, you can go to
http://www.symantec.com/avcenter/tools.list.html
and download a removal tool if it is available for your virus. You can learn
more
about the virus at http://www.symantec.com/avcenter/vinfodb.html

When a virus is intercepted, the recipient, the sender and the postmaster
for
either domain is notified automatically. There is no need for you to take
any
action.


Team SunBeach


D9d8b10e.SMD



This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .



RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2001-08-21 Thread Craig Gittens

Note that I use an external database, SQL 7 running on it's own server over
a switched 100MB ethernet backbone.

Craig.

-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of R. Scott Perry
Sent: Tuesday, August 21, 2001 3:34 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS



>I understand this Scott. It worked correctly and addressed the email to
>[EMAIL PROTECTED] So why did it drop it into the [EMAIL PROTECTED]
mailbox
>instead of sending it out to THEIR server?

That sounds like a problem with the IMail "imail1.exe" program.  It's
pretty strange, and requires that you tell it the host name of the sending
server.  It may have mangled the address somehow.  I'll see if I can
reproduce that here.

Someone else had recently suggested that we add a setting to allow you to
use other mailers, such as blat, that could be used instead of imail1.exe.
  -Scott

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .



RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2001-08-21 Thread R. Scott Perry


>I understand this Scott. It worked correctly and addressed the email to
>[EMAIL PROTECTED] So why did it drop it into the [EMAIL PROTECTED] mailbox
>instead of sending it out to THEIR server?

That sounds like a problem with the IMail "imail1.exe" program.  It's 
pretty strange, and requires that you tell it the host name of the sending 
server.  It may have mangled the address somehow.  I'll see if I can 
reproduce that here.

Someone else had recently suggested that we add a setting to allow you to 
use other mailers, such as blat, that could be used instead of imail1.exe.
  -Scott

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .



RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2001-08-21 Thread Craig Gittens

I understand this Scott. It worked correctly and addressed the email to
[EMAIL PROTECTED] So why did it drop it into the [EMAIL PROTECTED] mailbox
instead of sending it out to THEIR server?

Craig.

-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of R. Scott Perry
Sent: Tuesday, August 21, 2001 3:11 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS



>I get that. But why did Imail drop the email into [EMAIL PROTECTED]
account
>which is the only domain on the server? Why did it not send it off to the
>correct place?

The %LOCALHOST% variable will return the domain of the local user (the one
on your domain).  If the person is relaying their mail (neither the sender
nor the recipient are local), %LOCALHOST% will now use the master host name
(so that it truly is local).
-Scott

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .



Re: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2001-08-21 Thread David Daniels

You have to edit the default emails that come with Declude. Scott has
instructions on his site.

David Daniels
System Administrator
Starfish Internet Service
[EMAIL PROTECTED]
"Clicking my fingers to the bone"
- Original Message -
From: "Ed Chabot" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Tuesday, August 21, 2001 2:40 PM
Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS


> How did you get all that info in the email from Declude?  Mine only states
> the following:
>
> Declude Virus caught a virus with the subject "Snowhite and the Seven
> Dwarfs - The REAL story!"
> from <> to:  [EMAIL PROTECTED]
>
> The spool file name is Daf9d0f8.SMD.
>
> Ed Chabot
> The Marlin Firearms Company
> 100 Kenna Drive
> North Haven, CT 06473
> (203)985-3254
>
> -Original Message-
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]]On Behalf Of Craig Gittens
> Sent: Tuesday, August 21, 2001 2:12 PM
> To: Declude. Virus List
> Subject: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS
>
>
> Guys,
>
> I have one domain on my Imail server running declude. My sales team has
> received multiple emails like the one below. Can anyone tell me why
> declude/Imail would do this? %localhost% is only supposed to send a
> sunbeach.net result. In addition the sales account is a valid account and
> not an alias. so why did mail destined for [EMAIL PROTECTED] get in his
> mailbox?
>
> Confused,
>
> Craig.
>
>
> -Original Message-
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]
> Sent: Tuesday, August 21, 2001 1:45 PM
> To: [EMAIL PROTECTED]
> Subject: WARNING: YOU MAY HAVE A VIRUS
> Date: Tue, 21 Aug 2001 13:44:59 -0400
>
> Message-Id: <[EMAIL PROTECTED]>
> Mime-Version: 1.0
> Content-Type: text/plain; charset=us-ascii
> From: <[EMAIL PROTECTED]>
> Reply-To: <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Subject: WARNING: YOU MAY HAVE A VIRUS
> X-Mailer: 
> X-UIDL: 883329720
> Status: U
>
> The Virus software on bicoltd.com has reported that you sent
> a virus with the subject "flight comfirmation" to:
> [EMAIL PROTECTED]
>
> The E-mail containing the virus has been quarantined on our servers to
> prevent further damage.
>
> The infected filename is "flight comfirmation.doc.pif", and the virus name
> was " the W32/SirCam@MM virus !!!"
>
> Armed with this information, you can try to clean it by updating your
virus
> scanner.
> If you lack one, you can go to
> http://www.symantec.com/avcenter/tools.list.html
> and download a removal tool if it is available for your virus. You can
learn
> more
> about the virus at http://www.symantec.com/avcenter/vinfodb.html
>
> When a virus is intercepted, the recipient, the sender and the postmaster
> for
> either domain is notified automatically. There is no need for you to take
> any
> action.
>
>
> Team SunBeach
>
>
> D9d8b10e.SMD
>
>
>
> This E-mail came from the Declude.Virus mailing list.  To
> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
> type "unsubscribe Declude.Virus".  You can E-mail
> [EMAIL PROTECTED] for assistance.  You can visit our web
> site at http://www.declude.com .
>
> This E-mail came from the Declude.Virus mailing list.  To
> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
> type "unsubscribe Declude.Virus".  You can E-mail
> [EMAIL PROTECTED] for assistance.  You can visit our web
> site at http://www.declude.com .
>

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .



RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2001-08-21 Thread R. Scott Perry


>I get that. But why did Imail drop the email into [EMAIL PROTECTED] account
>which is the only domain on the server? Why did it not send it off to the
>correct place?

The %LOCALHOST% variable will return the domain of the local user (the one 
on your domain).  If the person is relaying their mail (neither the sender 
nor the recipient are local), %LOCALHOST% will now use the master host name 
(so that it truly is local).
-Scott

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .



RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2001-08-21 Thread R. Scott Perry


>How did you get all that info in the email from Declude?  Mine only states
>the following:
>
>Declude Virus caught a virus with the subject "Snowhite and the Seven
>Dwarfs - The REAL story!"
>from <> to:  [EMAIL PROTECTED]
>
>The spool file name is Daf9d0f8.SMD.

The E-mail template files are fully customizeable.  You can look in the 
"E-mail Notifications" section of the manual for information on the 
variables you can use in there.  I believe that the templates have recently 
been updated to include more information in them.
 -Scott

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .



RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2001-08-21 Thread Craig Gittens

In outlook, when you have the message open, View>Options and in the window
pane you will see the full headers, just copy and paste.

Craig.

-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Ed Chabot
Sent: Tuesday, August 21, 2001 2:41 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS


How did you get all that info in the email from Declude?  Mine only states
the following:

Declude Virus caught a virus with the subject "Snowhite and the Seven
Dwarfs - The REAL story!"
from <> to:  [EMAIL PROTECTED]

The spool file name is Daf9d0f8.SMD.

Ed Chabot
The Marlin Firearms Company
100 Kenna Drive
North Haven, CT 06473
(203)985-3254

-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Craig Gittens
Sent: Tuesday, August 21, 2001 2:12 PM
To: Declude. Virus List
Subject: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS


Guys,

I have one domain on my Imail server running declude. My sales team has
received multiple emails like the one below. Can anyone tell me why
declude/Imail would do this? %localhost% is only supposed to send a
sunbeach.net result. In addition the sales account is a valid account and
not an alias. so why did mail destined for [EMAIL PROTECTED] get in his
mailbox?

Confused,

Craig.


-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, August 21, 2001 1:45 PM
To: [EMAIL PROTECTED]
Subject: WARNING: YOU MAY HAVE A VIRUS
Date: Tue, 21 Aug 2001 13:44:59 -0400

Message-Id: <[EMAIL PROTECTED]>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
From: <[EMAIL PROTECTED]>
Reply-To: <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Subject: WARNING: YOU MAY HAVE A VIRUS
X-Mailer: 
X-UIDL: 883329720
Status: U

The Virus software on bicoltd.com has reported that you sent
a virus with the subject "flight comfirmation" to:
[EMAIL PROTECTED]

The E-mail containing the virus has been quarantined on our servers to
prevent further damage.

The infected filename is "flight comfirmation.doc.pif", and the virus name
was " the W32/SirCam@MM virus !!!"

Armed with this information, you can try to clean it by updating your virus
scanner.
If you lack one, you can go to
http://www.symantec.com/avcenter/tools.list.html
and download a removal tool if it is available for your virus. You can learn
more
about the virus at http://www.symantec.com/avcenter/vinfodb.html

When a virus is intercepted, the recipient, the sender and the postmaster
for
either domain is notified automatically. There is no need for you to take
any
action.


Team SunBeach


D9d8b10e.SMD



This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .



RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2001-08-21 Thread Craig Gittens

I get that. But why did Imail drop the email into [EMAIL PROTECTED] account
which is the only domain on the server? Why did it not send it off to the
correct place?

Craig.

Here is the header from the actual email: (196 is my dialup block)

Received: from ezra [196.3.219.102] by sunbeach.net
  (SMTPD32-6.06) id AD8B2832010E; Tue, 21 Aug 2001 13:42:35 -0400
From: "Ezra Tull"<[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
Subject: flight comfirmation
date: Tue, 21 Aug 2001 13:42:59 -0300
MIME-Version: 1.0
X-MIMEOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
X-Mailer: Microsoft Outlook Express 5.50.4133.2400
Content-Type: multipart/mixed;
boundary="09E443FE_Outlook_Express_message_boundary"
Content-Disposition: Multipart message
Message-Id: <200108211342781.SM01884@ezra>


This message would get sent if [EMAIL PROTECTED] sent an E-mail to
[EMAIL PROTECTED] with a virus in it.

Did they not send an E-mail with the "flight confirmation.doc.pif" file
attached?
  -Scott

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .



RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2001-08-21 Thread Ed Chabot

How did you get all that info in the email from Declude?  Mine only states
the following:

Declude Virus caught a virus with the subject "Snowhite and the Seven
Dwarfs - The REAL story!"
from <> to:  [EMAIL PROTECTED]

The spool file name is Daf9d0f8.SMD.

Ed Chabot
The Marlin Firearms Company
100 Kenna Drive
North Haven, CT 06473
(203)985-3254

-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Craig Gittens
Sent: Tuesday, August 21, 2001 2:12 PM
To: Declude. Virus List
Subject: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS


Guys,

I have one domain on my Imail server running declude. My sales team has
received multiple emails like the one below. Can anyone tell me why
declude/Imail would do this? %localhost% is only supposed to send a
sunbeach.net result. In addition the sales account is a valid account and
not an alias. so why did mail destined for [EMAIL PROTECTED] get in his
mailbox?

Confused,

Craig.


-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, August 21, 2001 1:45 PM
To: [EMAIL PROTECTED]
Subject: WARNING: YOU MAY HAVE A VIRUS
Date: Tue, 21 Aug 2001 13:44:59 -0400

Message-Id: <[EMAIL PROTECTED]>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
From: <[EMAIL PROTECTED]>
Reply-To: <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Subject: WARNING: YOU MAY HAVE A VIRUS
X-Mailer: 
X-UIDL: 883329720
Status: U

The Virus software on bicoltd.com has reported that you sent
a virus with the subject "flight comfirmation" to:
[EMAIL PROTECTED]

The E-mail containing the virus has been quarantined on our servers to
prevent further damage.

The infected filename is "flight comfirmation.doc.pif", and the virus name
was " the W32/SirCam@MM virus !!!"

Armed with this information, you can try to clean it by updating your virus
scanner.
If you lack one, you can go to
http://www.symantec.com/avcenter/tools.list.html
and download a removal tool if it is available for your virus. You can learn
more
about the virus at http://www.symantec.com/avcenter/vinfodb.html

When a virus is intercepted, the recipient, the sender and the postmaster
for
either domain is notified automatically. There is no need for you to take
any
action.


Team SunBeach


D9d8b10e.SMD



This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .