RE: [Declude.Virus] Is McAfee catching w32/Goner-A virus

2001-12-04 Thread Madscientist
Yes. We have caught quite a few since upgrading the virus defs. _M | -Original Message- | From: [EMAIL PROTECTED] | [mailto:[EMAIL PROTECTED]]On Behalf Of Michael Abbott | Sent: Tuesday, December 04, 2001 3:40 PM | To: [EMAIL PROTECTED] | Subject: [Declude.Virus] Is McAfee catching w32/Go

Re: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread R. Scott Perry
>So if you use the banext, the mail is not delivered if the attachment >matches the extension but there is no notification at all? That is correct. The E-mail will be quarantined, but no virus notifications will go out. >example >banext scr > >I get a message that has an scr attachment but n

Re: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread Bob McGregor
So if you use the banext, the mail is not delivered if the attachment matches the extension but there is no notification at all? example banext scr I get a message that has an scr attachment but not a virus. The message is not delivered and there is no notification as to the non-delivery? If

MISSING_REVERSE_DNS:Re: [Declude.Virus] Is McAfee catching w32/Goner-A virus

2001-12-04 Thread John Carter
Yes, caught one within 10 minutes of my update. You need the EXTRA.DAT or the SUPER EXTRA.DAT (this includes an engine update). Had to hunt for it. Go the virus alert page for Goner. It has links. John Michael Abbott wrote: > > Does anyone know if McAfee is catching the w32/Goner-A virus? >

Re: [Declude.Virus] Is McAfee catching w32/Goner-A virus

2001-12-04 Thread R. Scott Perry
>Does anyone know if McAfee is catching the w32/Goner-A virus? Yes. McAfee, F-Prot, Sophos, and others have new virus definitions that are catching it. -Scott --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] This E-mail c

Re: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread R. Scott Perry
>and will it scan first and if no virus isfound will it then ban it? thereby >sending the notification if it is known to be infected? That is correct -- the E-mail will still be scanned, and the notifications will be sent out if it contains a virus. -Sco

[Declude.Virus] MISSING_REVERSE_DNS:McAfee auto-update

2001-12-04 Thread John Carter
I've seen numerous auto-update batch files for most of the AV products, but don't remember seeing one for McAfee. Could someone help me out there? I know simple batch files, AT scheduler, but after looking at the ftp.nai.com site, I'm not sure which directory and update file to grab. Thanks,

[Declude.Virus] Is McAfee catching w32/Goner-A virus

2001-12-04 Thread Michael Abbott
Does anyone know if McAfee is catching the w32/Goner-A virus? Mike Abbott --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe D

Re: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread R. Scott Perry
>what version do i have to be running to use this feature? It is in v1.24 and higher (you can type "Declude -diag" from a command prompt to see the version number). -Scott --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] Th

Re: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread Jim Jones, Jr.
and will it scan first and if no virus isfound will it then ban it? thereby sending the notification if it is known to be infected? thanks again... and keep up the great work! I'd like to see ipswitc/sysmantec respond this quickly! Jim - Original Message - From: "R. Scott Perry" <[EMAI

Re: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread Jim Jones, Jr.
what version do i have to be running to use this feature? thanks, jim - Original Message - From: "R. Scott Perry" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Tuesday, December 04, 2001 2:24 PM Subject: Re: [Declude.Virus] New W32/Goner-A virus > > >Is there a way to kill all i

Re: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread R. Scott Perry
>Is there a way to kill all incoming .scr attachments? using declude or >something else? You can add a line "BANEXT scr" to your \IMail\Deculde\virus.cfg file, which will ban files with .scr attachments. Note, however, that no notifications will go out if you do this.

Re: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread Chris Hunt
In your virus.cfg file in your declude folder Works perfectly BANEXT lnk BANEXT vbs BANEXT scr BANEXT shs BANEXT wsh BANEXT vbx BANEXT bat BANEXT cab BANEXT nws BANEXT asp BANEXT dll BANEXT cmd BANEXT xml BANEXT sys BANEXT asd BANEXT chm BANEXT ocx BANEXT vbe BANEXT wsf BANEXT js Your vir*.log f

Re: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread Jim Matuska
The latest update for Fprot is catching Goner-A. I put the update in place about an hour ago and so far have caught about 30 copies of the virus. Jim Matuska Jr. Nez Perce Tribe Computer Services [EMAIL PROTECTED] - Original Message - From: "Dean Zingle, Ipswitch.ca" <[EMAIL PROTECTED]>

Re: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread Jim Jones, Jr.
Is there a way to kill all incoming .scr attachments? using declude or something else? i would prefer that it happen after the virus scan... just in case a new .scr virus comes out... thanks, jim - Original Message - From: "Jerry Murdock" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Se

Re: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread Jerry Murdock
I've caught about 30 with f-prot since noon-ish(EST) when the patterns were updated. Jerry Subject: Hi Incoming/Outgoing: incoming Number Recepients: 1 Message ID: <001401c17cf8$2ce20c70$6664a8c0@XX> Date: 12/04/2001 Time: 14:17:52 QueueFile Name: D215d228.SMD Infected File: gone.scr Virus N

Re: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread Jerry Murdock
The report should list these dates: SIGN.DEF created 4. December 2001 SIGN2.DEF created 4. December 2001 MACRO.DEF created 30. November 2001 - Original Message - From: "Grant Griffith" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Tuesday, December 04, 2001 2:40 PM Subject: RE: [Dec

[Declude.Virus] FW: EXTRA.DAT link

2001-12-04 Thread Andy Schmidt
I removed the EXTRA.DAT for copyright reasons - and it's available online for download. But you may find the document helpful. -Original Message- From: Virus Research [mailto:[EMAIL PROTECTED]] Network Associates McAfee AVERT, UK A Division of Network Associates UK, Aylesbury Customer re

RE: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread Andy Schmidt
http://www.mcafee.com/anti-virus/viruses/goner/default.asp?cid=2636 scroll down and follow the link to download the EXTRA.DAT. That's how McAfee handled last-minute updates. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Paul Ingram Sent: Tuesday, Dece

RE: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread Grant Griffith
OK, got the updates there. Have to start checking ftp2.complex.is instead. Sincerely, Grant Griffith, Vice President EI8HT LEGS Web Management Co., Inc. http://www.getafreewebsite.com 877-483-3393 ||-Original Message- ||From: [EMAIL PROTECTED] ||[mailto:[EMAIL PROTECTED]]On Behalf Of Bi

RE: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread Paul Ingram
Cool thanks -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Andy Schmidt Sent: Tuesday, December 04, 2001 3:02 PM To: [EMAIL PROTECTED] Subject: RE: [Declude.Virus] New W32/Goner-A virus Nope - has nothing to do with boot disks. EXTRA.DATs contain prote

RE: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread Paul Ingram
You are right about F-Prot!!:) I just download and tried it again it it is now catching it. But as of 45min ago the defs on frisk.is where not cathching at least it didn't work here but all is rosey now:) Thanks, Paul -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]O

RE: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread Andy Schmidt
Nope - has nothing to do with boot disks. EXTRA.DATs contain protection against a particular new virus strain before the regular scheduled .DAT file update becomes available. It's been this way for the longest time and works with all current VirusScan family products. Best Regards Andy Schmidt

RE: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread Chris Hunt
Would it not just be easier to BANEXT scr in your virus.cfg file? Chris At 02:48 PM 12/4/01 -0500, you wrote: >No F-Prot is not chaching it ..I have caught 68 since 2:15pm when a user >called me to ask could the install this screen saver. I am caching by >filtering the subject line and body text

RE: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread Madscientist
Just updated McAfee on our mail server (with declude). It caught 2 inbound within 30 seconds. _M | -Original Message- | From: [EMAIL PROTECTED] | [mailto:[EMAIL PROTECTED]]On Behalf Of R. Scott Perry | Sent: Tuesday, December 04, 2001 2:55 PM | To: [EMAIL PROTECTED] | Subject: RE: [Declud

Re: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread Bob McGregor
My copy of f-prot is catching the gomer-a. However, I logged into the login page at frisk.is and got them manually... On Tuesday, December 4, 2001 12:48 PM, Paul Ingram <[EMAIL PROTECTED]> wrote: >No F-Prot is not chaching it ..I have caught 68 since 2:15pm when a user >called me to ask could t

MISSING_REVERSE_DNS:RE: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread Giuseppe Foderaro
I got it from F-Prot site http://www.f-prot.com/f-prot/virusinfo/goner.html -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Bill Beach Sent: martedì 4 dicembre 2001 20.51 To: [EMAIL PROTECTED] Subject: RE: [Declude.Virus] New W32/Goner-A virus I just go

Re: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread Dean Zingle, Ipswitch.ca
Within the last hour there has been an update from F-Prot for sign.def and sign2.def. I do not know what has been added but the update is available. Dean Zingle Optrics Inc. - Original Message - From: "Grant Griffith" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Tuesday, December 0

MISSING_REVERSE_DNS:RE: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread Kenneth Bird
Trend Micro had an update out at 11:30am cst. Been catching them since. Had a few come through in the open window before they released dat earlier. Ken -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Paul Ingram Sent: Tuesday, December 04, 2001 1:49 PM

RE: [Declude.Virus] New W32/Goner-A virus

2001-12-04 Thread R. Scott Perry
>I just downloaded the files from F-Prot and they are what we already had. >F-Prot must either already catch it or has not updated the info yet. You can verify it by going to a command prompt, going to the directory F-Prot is in, and typing: F-Prot /virlist | find "goner" /i This sho