after getting the fp-def.zip from here
ftp://ftp.f-prot.com/pub/ 5 minuttes ago i got to catch myparty
> -Opprinnelig melding-
> Fra: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]]Pa vegne av [EMAIL PROTECTED]
> Sendt: 28. januar 2002 22:34
> Til: [EMAIL PROTECTED]
> Emne: DSN:Re: [Declu
>I just received a myparty e-mail which got through. Checking the spool file
>in the virus log reports OK no virus found.
Add "VIRUSCODE 8" to the \IMail\Declude\virus.cfg file, and it should get
caught. F-Prot is incorrectly reporting it as a suspicious file, rather
than a virus -- the VIRUS
F-Prot 3.11b Updated the F-Prot files this am dated Jan 28th
f-prot /virlist shows the files dated jan 28th
I just received a myparty e-mail which got through. Checking the spool file
in the virus log reports OK no virus found.
This is stopped by banning com extensions but f-prot is not catchi
just downladed another zip from them and there it was corrected looks like som late
updates here
> -Opprinnelig melding-
> Fra: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]]Pa vegne av R. Scott Perry
> Sendt: 28. januar 2002 21:14
> Til: [EMAIL PROTECTED]
> Emne: RE: [Declude.Virus] MY
downloaded the latest def files for here
ftp://ftp.f-prot.com/pub/
the files says 28.01.2002
but the result off of the virlist says
sign.def 20 december
sign2.def 24 december
how can we trust such a company
> -Opprinnelig melding-
> Fra: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTEC
does f-prot know about this problem?
jim
- Original Message -
From: "R. Scott Perry" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Monday, January 28, 2002 1:32 PM
Subject: RE: [Declude.Virus] MY Party
:
: >Nop that didn't help on my new def files
:
: F-Prot's new virus definitions
>VIRUSCODE 8
>
>This dont catch the virus with the latest def files and 3.11a engine f-Prot
It should. You should double-check that you have the latest definitions
(you can type "F-Prot /VIRLIST > temp.txt"; the temp.txt file should have a
date of "January 28" on one or more of the top
# The "" in the LOGFILE option gets replaced with the month/date
LOGFILE E:\virus\vir.log
LOGLEVELHIGH
CONSOLE OFF
# SCANFILE is the location of the command-line virus scanner. Note that it
# must include the full path. VIRUSCODE is the code that scanner return
>Nop that didn't help on my new def files
F-Prot's new virus definitions are slightly defective.
To get them to work, you need to add "VIRUSCODE 8" to the
\IMail\Declude\virus.cfg file. Otherwise, they will be treated as
"suspicious files" that do not contain a virus, and will be delivered.
>Here is my log file
>
>01/28/2002 11:49:13 Q80fb476 Found a bogus .jpg file
>01/28/2002 12:32:34 Q8b30100 Warning: EOF in middle of MIME segment []
>[--=_NextPart_000_00E2_66E63A4D.E5030B81]
>01/28/2002 13:16:33 Q957e2ba Found an EXE posing as a non-EXE file!
>01/28/2002 13:20:48 Q967f438 Fo
thanks
> -Original Message-
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]]On Behalf Of Chris Hunt
> Sent: 28. januar 2002 20:04
> To: [EMAIL PROTECTED]
> Subject: RE: [Declude.Virus] MY Party
>
>
> In your virus.cfg add these (edit to suit)
>
> SKIPEXT GIF
> SKIPEXT
In your virus.cfg add these (edit to suit)
SKIPEXT GIF
SKIPEXT PDF
SKIPEXT TXT
SKIPEXT JPG
SKIPEXT MPG
SKIPEXT PDF
BANEXT lnk
BANEXT vbs
BANEXT scr
BANEXT shs
BANEXT wsh
BANEXT vbx
BANEXT bat
BANEXT cab
BANEXT nws
BANEXT asp
BANEXT dll
BANEXT cmd
B
Do you have script already for doing the daily .dat update.
Paul
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Jerry Murdock
Sent: Monday, January 28, 2002 12:39 PM
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus] MY Party
The downside of McAfee upda
how do i bann i certain file ?
> -Original Message-
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]]On Behalf Of Paul Ingram
> Sent: 28. januar 2002 19:41
> To: [EMAIL PROTECTED]
> Subject: RE: [Declude.Virus] MY Party
>
>
> Do you have script already for doing the daily .dat
Nop that didn't help on my new def files
looks like that its not caching all or only a few
> -Original Message-
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]]On Behalf Of R. Scott Perry
> Sent: 28. januar 2002 18:55
> To: [EMAIL PROTECTED]
> Subject: Re: [Declude.Virus] MY Party
>Can you tell me what they do?
It's specific to the scanner you're using. The
following is from the command.txt file from F-Prot
The program uses the following exit codes, which can be checked with the
ERRORLEVEL command from a BAT file.
0 - Normal exit - nothing found
1 - Abnormal term
Hi,
Scott, I've got VIRUSCODE 3 and 6 as well...
Can you tell me what they do?
I know this stuff is probably documented somewhere...looked on the
Declude web page.
Thanks,
Andy Baldwin
[EMAIL PROTECTED]
http://www.thumpernet.com
315-282-0020
Monday, January 28, 2002, 12:54:45 PM, you wrote:
Hi Scott:
Here is my log file
01/28/2002 11:49:13 Q80fb476 Found a bogus .jpg file
01/28/2002 12:32:34 Q8b30100 Warning: EOF in middle of MIME segment []
[--=_NextPart_000_00E2_66E63A4D.E5030B81]
01/28/2002 13:16:33 Q957e2ba Found an EXE posing as a non-EXE file!
01/28/2002 13:20:48 Q967f438
Thanks!!! Just got it and stop 5 more within 10 min.
Paul Ingram
CI Travel, IT Systems Analyst
888.461.0022 ext.826
mailto:[EMAIL PROTECTED]
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Michael Abbott
Sent: Monday, January 28, 2002 12:34 PM
To: [EMA
>My desktop F-Prot is on my Home Email which does not get scanned by
>Declude. Weird part is that F-Prot Real-Time protector alert me but does
>not offer to disinfect/delete
That's because it isn't recognized as a virus -- it is only being seen as a
suspicious file, so it has no idea what vi
My desktop F-Prot is on my Home Email which does not get scanned by
Declude. Weird part is that F-Prot Real-Time protector alert me but does
not offer to disinfect/delete
Chris
At 12:44 PM 01/28/2002 -0500, you wrote:
>Anyone catching these with Declude / F-Prot?
>
>We have seen dozens come in
>Anyone catching these with Declude / F-Prot?
>Running F-Prot 3.11a with todays definitions (according to their site it
>should detect the virus
>
>WARNING: Virus scanner reported an error #8.
F-Prot isn't reporting them as a virus. You need to add a line "VIRUSCODE
8" to the \IMail\Declude\v
I am not catching them and i have the latest declude and fprot and fprot
defs... they are being stopped because of the banned .com extension,
however.
Jim
- Original Message -
From: "Mailing Lists" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Monday, January 28, 2002 11:44 AM
Subjec
Anyone catching these with Declude / F-Prot?
We have seen dozens come in.
Running F-Prot 3.11a with todays definitions (according to their site it
should detect the virus
01/28/2002 11:32:47 Q7d2e104 uu file: www.myparty.yahoo.com
[d:\spool\D7d2e104.vir\1_1.com] 01/28/2002 11:32:59 Q7d2e104 Cou
The downside of McAfee updates is that it takes an EXTREME event for them to
budge from weekly updates of the release version of the dat file, which means
the built-in auto update is slow to react in these situations.
You either need to manually get the extra.dat file from their web site, or the
Paul,
McAfee has issued an Extra.dat that contains the update for MYParty. It can
be found and downloaded at
http://vil.mcafee.com/dispVirus.asp?virus_k=99332removal_instructions
Michael Abbott [EMAIL PROTECTED]
Network Administrator
-Original Message-
From: [EMAIL PROTECTED]
[mailt
Does anyone no if McAfee is up to date on this? I am running engine 4.1.60
and Defs 4.0.4183
But I just got hit and now have users calling me a five mintues!!!
Paul
---
[This E-mail scanned for viruses by Declude Virus/McAfee]
---
[This E-mail was scanned for viruses by Declude Virus (http://
>How can you tell what definitions you have?
F-Prot /VIRLIST
That will show a list of all the known viruses. The first 3 lines show the
dates of the virus definition files.
-Scott
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.c
>what is the name of this virus as known by f-prot.. i did a f-prot /virlist
>and got this one VBS/Party.A@mm but i don't think thats it.
It looks like right now, it's just getting treated as a suspicious file. I
don't see it in their list either, but we just had one come in that was
caught.
How can you tell what definitions you have?
I know it is a command line, but I forgot the syntax.
John Tolmachoff
Network Engineer
211 E. Imperial Hwy., Suite 106
Fullerton, CA 92835
714-578-7999, ext. 104
[EMAIL PROTECTED]
www.reliancesoft.com
---
[This E-mail was scanned for viruses by
30 matches
Mail list logo