Re: [Declude.Virus] VBS.Redolf

2002-05-09 Thread R. Scott Perry
I have been notified by a client of ours that does secondary virus scanning on their internal server that it caught two messages that went through our mail server. The following message had attachment(s) which contained the viruses: From : [EMAIL PROTECTED] To: [EMAIL PROTECTED]

[Declude.Virus] Declude Virus v1.52 Released

2002-05-09 Thread R. Scott Perry
We have just released Declude Virus v1.52 (at http://www.declude.com/virus/manual.htm ). It has one fix since the last beta (allowing an on-access scanner to be used without a stub command-line scanner). It also includes some very minor fixes since the last released version (1.46), the

RE: [Declude.Virus] VBS.Redolf

2002-05-09 Thread John Tolmachoff
The notice says it was in an attachment called *.att. What kind of attachment is that? John Tolmachoff IT Manager, Network Engineer RelianceSoft, Inc. Fullerton, CA 92835 www.reliancesoft.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] On Behalf Of R. Scott

RE: [Declude.Virus] VBS.Redolf

2002-05-09 Thread R. Scott Perry
The notice says it was in an attachment called *.att. What kind of attachment is that? That sounds like it may be a Microsoft TNEF-encoded file (which usually come in winmail.dat, but I believe they can also be in *.att). -Scott --- [This E-mail was scanned for

RE: [Declude.Virus] DSN:New Version of Virus Log Analyzer

2002-05-09 Thread Steven Copeland
Something for the future? How about Inbound and outbound counts by domain for those of us who use the Pro version and need/want stats on a per domain basis. Steven -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of [EMAIL PROTECTED] Sent: Thursday,

RE: [Declude.Virus] DSN:New Version of Virus Log Analyzer

2002-05-09 Thread Jonathan
I've tried using this thing a few times .. and always come up with the same problem. Am I missing something? Relatively new version of declude installed (not the *latest* beta, but current), and all I get is: Log NameVirus Count Total Scanned vir0508.log 0

RE: [Declude.Virus] DSN:New Version of Virus Log Analyzer

2002-05-09 Thread smb
Something for the future? How about Inbound and outbound counts by domain for those of us who use the Pro version and need/want stats on a per domain basis. We run the pro version also. We have looked at this before but have stayed away from it as it may not be too accurate due to a few of

RE: [Declude.Virus] DSN:New Version of Virus Log Analyzer

2002-05-09 Thread Jonathan
Sorry -- wasn't set to MID, I must have overlooked something somewhere .. didn't see that documented. Thanks, Jonathan At 06:12 PM 5/9/2002 -0400, you wrote: Jonathan, What is the LOGLEVEL in your virus.cfg file set to ? It should be set to the MID Level LOGLEVEL MID If yours is curently

[Declude.Virus] Instalation Problems

2002-05-09 Thread Ron Rushing
New users here-- Trying to install the Declude Virus and JunkMail software. Virus software doesn't work. VIRus log file contains 100's of lines telling us the registration is invalid. We've tried changing the zero's to the letter O, ect. No luck. Is there something we're missing here ? Bad

Re: [Declude.Virus] SKIPIFVIRUSNAMEHAS

2002-05-09 Thread Eje Gustafsson
In the .eml file put in SKIPIFVIRUSNAMEHAS W32/Klez SKIPIFVIRUSNAMEHAS W32/SirCam I wouldn't do the SirCam but definitely the Klez since it spoofs the From address. Thursday, May 09, 2002, 17:58:29 PM, you wrote: W What is the format need to use SKIPIFVIRUSNAMEHAS W Here is how my virus

Re: [Declude.Virus] Instalation Problems

2002-05-09 Thread R. Scott Perry
Virus software doesn't work. VIRus log file contains 100's of lines telling us the registration is invalid. That will happen if the Official Host Name of your server doesn't match the one that we used to generate the activation code. You can double-check by going to Host Name on the General

Re: [Declude.Virus] SKIPIFVIRUSNAMEHAS

2002-05-09 Thread R. Scott Perry
What is the format need to use SKIPIFVIRUSNAMEHAS Here is how my virus scanner reports a virus: W32/Klez.h@MM virus !!! W32/SirCam@MM virus !!! You need to have SKIPIFVIRUSNAMEHAS, followed by one space or tab, and text that appears within the virus name (part of the name is OK, and it is

Re: [Declude.Virus] SKIPIFVIRUSNAMEHAS

2002-05-09 Thread Webmaster
I wouldn't do the SirCam but definitely the Klez I'm getting a bunch notifications of the SirCam virus from the same email address [EMAIL PROTECTED] but the email address is not valid. Delcude virus alert: Our Virus Scanner v1.52 caught the W32/SirCam@MM virus !!! in Enrollment.xls.lnk

Re: [Declude.Virus] SKIPIFVIRUSNAMEHAS

2002-05-09 Thread R. Scott Perry
How does declude send notifications ? It sends them using IMail's imail1.exe. Can we use imail rules to delete some messages (ie: if to adress is [EMAIL PROTECTED] ?) I believe that the IMail rules will work on E-mail sent with imail1.exe, so that should do the trick.

Re: [Declude.Virus] SKIPIFVIRUSNAMEHAS

2002-05-09 Thread Serge
Here is our virus analisis for the last 2 days our main problem is sircam from our customers this has been the case for months , we tried everything we can think of to make them clean their computers, it always come back, probably from hotmail, ..., accounts. anyone have any hints ? also, for