SV: Re: [Declude.Virus] MY Party not caught

2002-01-28 Thread ISPhuset Visual Web Norge
after getting the fp-def.zip from here ftp://ftp.f-prot.com/pub/ 5 minuttes ago i got to catch myparty > -Opprinnelig melding- > Fra: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED]]Pa vegne av [EMAIL PROTECTED] > Sendt: 28. januar 2002 22:34 > Til: [EMAIL PROTECTED] > Emne: DSN:Re: [Declu

Re: DSN:Re: [Declude.Virus] MY Party not caught

2002-01-28 Thread R. Scott Perry
>I just received a myparty e-mail which got through. Checking the spool file >in the virus log reports OK no virus found. Add "VIRUSCODE 8" to the \IMail\Declude\virus.cfg file, and it should get caught. F-Prot is incorrectly reporting it as a suspicious file, rather than a virus -- the VIRUS

DSN:Re: [Declude.Virus] MY Party not caught

2002-01-28 Thread smb
F-Prot 3.11b Updated the F-Prot files this am dated Jan 28th f-prot /virlist shows the files dated jan 28th I just received a myparty e-mail which got through. Checking the spool file in the virus log reports OK no virus found. This is stopped by banning com extensions but f-prot is not catchi

SV: [Declude.Virus] MY Party

2002-01-28 Thread ISPhuset Visual Web Norge
just downladed another zip from them and there it was corrected looks like som late updates here > -Opprinnelig melding- > Fra: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED]]Pa vegne av R. Scott Perry > Sendt: 28. januar 2002 21:14 > Til: [EMAIL PROTECTED] > Emne: RE: [Declude.Virus] MY

SV: [Declude.Virus] MY Party

2002-01-28 Thread ISPhuset Visual Web Norge
downloaded the latest def files for here ftp://ftp.f-prot.com/pub/ the files says 28.01.2002 but the result off of the virlist says sign.def 20 december sign2.def 24 december how can we trust such a company > -Opprinnelig melding- > Fra: [EMAIL PROTECTED] > [mailto:[EMAIL PROTEC

Re: [Declude.Virus] MY Party

2002-01-28 Thread Jim Jones, Jr.
does f-prot know about this problem? jim - Original Message - From: "R. Scott Perry" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Monday, January 28, 2002 1:32 PM Subject: RE: [Declude.Virus] MY Party : : >Nop that didn't help on my new def files : : F-Prot's new virus definitions

RE: [Declude.Virus] MY Party

2002-01-28 Thread R. Scott Perry
>VIRUSCODE 8 > >This dont catch the virus with the latest def files and 3.11a engine f-Prot It should. You should double-check that you have the latest definitions (you can type "F-Prot /VIRLIST > temp.txt"; the temp.txt file should have a date of "January 28" on one or more of the top

RE: [Declude.Virus] MY Party

2002-01-28 Thread Visual Web Norge
# The "" in the LOGFILE option gets replaced with the month/date LOGFILE E:\virus\vir.log LOGLEVELHIGH CONSOLE OFF # SCANFILE is the location of the command-line virus scanner. Note that it # must include the full path. VIRUSCODE is the code that scanner return

RE: [Declude.Virus] MY Party

2002-01-28 Thread R. Scott Perry
>Nop that didn't help on my new def files F-Prot's new virus definitions are slightly defective. To get them to work, you need to add "VIRUSCODE 8" to the \IMail\Declude\virus.cfg file. Otherwise, they will be treated as "suspicious files" that do not contain a virus, and will be delivered.

Re: [Declude.Virus] New Virus

2002-01-28 Thread R. Scott Perry
>Here is my log file > >01/28/2002 11:49:13 Q80fb476 Found a bogus .jpg file >01/28/2002 12:32:34 Q8b30100 Warning: EOF in middle of MIME segment [] >[--=_NextPart_000_00E2_66E63A4D.E5030B81] >01/28/2002 13:16:33 Q957e2ba Found an EXE posing as a non-EXE file! >01/28/2002 13:20:48 Q967f438 Fo

RE: [Declude.Virus] MY Party

2002-01-28 Thread Visual Web Norge
thanks > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED]]On Behalf Of Chris Hunt > Sent: 28. januar 2002 20:04 > To: [EMAIL PROTECTED] > Subject: RE: [Declude.Virus] MY Party > > > In your virus.cfg add these (edit to suit) > > SKIPEXT GIF > SKIPEXT

RE: [Declude.Virus] MY Party

2002-01-28 Thread Chris Hunt
In your virus.cfg add these (edit to suit) SKIPEXT GIF SKIPEXT PDF SKIPEXT TXT SKIPEXT JPG SKIPEXT MPG SKIPEXT PDF BANEXT lnk BANEXT vbs BANEXT scr BANEXT shs BANEXT wsh BANEXT vbx BANEXT bat BANEXT cab BANEXT nws BANEXT asp BANEXT dll BANEXT cmd B

RE: [Declude.Virus] MY Party

2002-01-28 Thread Paul Ingram
Do you have script already for doing the daily .dat update. Paul -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Jerry Murdock Sent: Monday, January 28, 2002 12:39 PM To: [EMAIL PROTECTED] Subject: Re: [Declude.Virus] MY Party The downside of McAfee upda

RE: [Declude.Virus] MY Party

2002-01-28 Thread Visual Web Norge
how do i bann i certain file ? > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED]]On Behalf Of Paul Ingram > Sent: 28. januar 2002 19:41 > To: [EMAIL PROTECTED] > Subject: RE: [Declude.Virus] MY Party > > > Do you have script already for doing the daily .dat

RE: [Declude.Virus] MY Party

2002-01-28 Thread Visual Web Norge
Nop that didn't help on my new def files looks like that its not caching all or only a few > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED]]On Behalf Of R. Scott Perry > Sent: 28. januar 2002 18:55 > To: [EMAIL PROTECTED] > Subject: Re: [Declude.Virus] MY Party

RE: Re[2]: [Declude.Virus] MY Party

2002-01-28 Thread Bill Beach
>Can you tell me what they do? It's specific to the scanner you're using. The following is from the command.txt file from F-Prot The program uses the following exit codes, which can be checked with the ERRORLEVEL command from a BAT file. 0 - Normal exit - nothing found 1 - Abnormal term

Re[2]: [Declude.Virus] MY Party

2002-01-28 Thread [EMAIL PROTECTED]
Hi, Scott, I've got VIRUSCODE 3 and 6 as well... Can you tell me what they do? I know this stuff is probably documented somewhere...looked on the Declude web page. Thanks, Andy Baldwin [EMAIL PROTECTED] http://www.thumpernet.com 315-282-0020 Monday, January 28, 2002, 12:54:45 PM, you wrote:

[Declude.Virus] New Virus

2002-01-28 Thread Andy Schmidt
Hi Scott: Here is my log file 01/28/2002 11:49:13 Q80fb476 Found a bogus .jpg file 01/28/2002 12:32:34 Q8b30100 Warning: EOF in middle of MIME segment [] [--=_NextPart_000_00E2_66E63A4D.E5030B81] 01/28/2002 13:16:33 Q957e2ba Found an EXE posing as a non-EXE file! 01/28/2002 13:20:48 Q967f438

RE: [Declude.Virus] MY Party

2002-01-28 Thread Paul Ingram
Thanks!!! Just got it and stop 5 more within 10 min. Paul Ingram CI Travel, IT Systems Analyst 888.461.0022 ext.826 mailto:[EMAIL PROTECTED] -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Michael Abbott Sent: Monday, January 28, 2002 12:34 PM To: [EMA

Re: [Declude.Virus] MY Party

2002-01-28 Thread R. Scott Perry
>My desktop F-Prot is on my Home Email which does not get scanned by >Declude. Weird part is that F-Prot Real-Time protector alert me but does >not offer to disinfect/delete That's because it isn't recognized as a virus -- it is only being seen as a suspicious file, so it has no idea what vi

Re: [Declude.Virus] MY Party

2002-01-28 Thread Chris Hunt
My desktop F-Prot is on my Home Email which does not get scanned by Declude. Weird part is that F-Prot Real-Time protector alert me but does not offer to disinfect/delete Chris At 12:44 PM 01/28/2002 -0500, you wrote: >Anyone catching these with Declude / F-Prot? > >We have seen dozens come in

Re: [Declude.Virus] MY Party

2002-01-28 Thread R. Scott Perry
>Anyone catching these with Declude / F-Prot? >Running F-Prot 3.11a with todays definitions (according to their site it >should detect the virus > >WARNING: Virus scanner reported an error #8. F-Prot isn't reporting them as a virus. You need to add a line "VIRUSCODE 8" to the \IMail\Declude\v

Re: [Declude.Virus] MY Party

2002-01-28 Thread Jim Jones, Jr.
I am not catching them and i have the latest declude and fprot and fprot defs... they are being stopped because of the banned .com extension, however. Jim - Original Message - From: "Mailing Lists" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Monday, January 28, 2002 11:44 AM Subjec

Re: [Declude.Virus] MY Party

2002-01-28 Thread Mailing Lists
Anyone catching these with Declude / F-Prot? We have seen dozens come in. Running F-Prot 3.11a with todays definitions (according to their site it should detect the virus 01/28/2002 11:32:47 Q7d2e104 uu file: www.myparty.yahoo.com [d:\spool\D7d2e104.vir\1_1.com] 01/28/2002 11:32:59 Q7d2e104 Cou

Re: [Declude.Virus] MY Party

2002-01-28 Thread Jerry Murdock
The downside of McAfee updates is that it takes an EXTREME event for them to budge from weekly updates of the release version of the dat file, which means the built-in auto update is slow to react in these situations. You either need to manually get the extra.dat file from their web site, or the

RE: [Declude.Virus] MY Party

2002-01-28 Thread Michael Abbott
Paul, McAfee has issued an Extra.dat that contains the update for MYParty. It can be found and downloaded at http://vil.mcafee.com/dispVirus.asp?virus_k=99332&#removal_instructions Michael Abbott [EMAIL PROTECTED] Network Administrator -Original Message- From: [EMAIL PROTECTED] [mailt

RE: [Declude.Virus] MY Party

2002-01-28 Thread Paul Ingram
Does anyone no if McAfee is up to date on this? I am running engine 4.1.60 and Defs 4.0.4183 But I just got hit and now have users calling me a five mintues!!! Paul --- [This E-mail scanned for viruses by Declude Virus/McAfee] --- [This E-mail was scanned for viruses by Declude Virus (http://

Re: [Declude.Virus] F-Prot definitions

2002-01-28 Thread R. Scott Perry
>How can you tell what definitions you have? F-Prot /VIRLIST That will show a list of all the known viruses. The first 3 lines show the dates of the virus definition files. -Scott --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.c

Re: [Declude.Virus] "My party" virus

2002-01-28 Thread R. Scott Perry
>what is the name of this virus as known by f-prot.. i did a f-prot /virlist >and got this one VBS/Party.A@mm but i don't think thats it. It looks like right now, it's just getting treated as a suspicious file. I don't see it in their list either, but we just had one come in that was caught.

[Declude.Virus] F-Prot definitions

2002-01-28 Thread John Tolmachoff
How can you tell what definitions you have? I know it is a command line, but I forgot the syntax. John Tolmachoff Network Engineer 211 E. Imperial Hwy., Suite 106 Fullerton, CA  92835 714-578-7999, ext. 104 [EMAIL PROTECTED] www.reliancesoft.com     --- [This E-mail was scanned for viruses by