RE: [Declude.Virus] list of viruses that forge header

2003-06-04 Thread Rasmus Aaen
>From the declude website: SKIPIFVIRUSNAMEHAS Yaha SKIPIFVIRUSNAMEHAS Lentin SKIPIFVIRUSNAMEHAS Magistr SKIPIFVIRUSNAMEHAS Klez SKIPIFVIRUSNAMEHAS Vulnerability SKIPIFVIRUSNAMEHAS Bugbear SKIPIFVIRUSNAMEHAS Bridex SKIPIFVIRUSNAMEHAS Braid SKIPIFVIRUSNAMEHAS

Re: [Declude.Virus] list of viruses that forge header

2003-06-04 Thread R. Scott Perry
I've been remiss in keeping up to date as to which viruses forge the from field, so I'm afraid that the 'FORGINGVIRUS' section of my virus.cfg, and the SKIPIFVIRUSNAMEHAS section of my notification emails is behind on the times. Would anyone care to share the virus names that you have populated

[Declude.Virus] list of viruses that forge header

2003-06-04 Thread Jeff Lesperance
I've been remiss in keeping up to date as to which viruses forge the from field, so I'm afraid that the 'FORGINGVIRUS' section of my virus.cfg, and the SKIPIFVIRUSNAMEHAS section of my notification emails is behind on the times. Would anyone care to share the virus names that you have populated

[Declude.Virus] Server 2003- F-Prot

2003-06-04 Thread Kami Razvan
Title: Message Hi;   We posted a request to F-Prot for a problem we are having and this is the reply.  Just FYI:   Hello and thank you for your mail. We have not yet tested our product on 2003 Server Standard. We will need some time to do so. Best regards,Kolbru

RE: [Declude.Virus] Sobig.C virus seems to always route through backup email server first

2003-06-04 Thread John Tolmachoff \(Lists\)
> Has anyone else noticed the Sobig.C virus routing through backup email > servers and not straight to the primary one. I have noticed that ever other > virus that declude catches goes straight to our primary mailserver but in > every case, the sobig.c virus always hits our backup mail server firs

RE: [Declude.Virus] Log File

2003-06-04 Thread R. Scott Perry
We have had a lot of viruses get through today (new Backdoor AVF), seems McAffee is the only one that has it available (sig file). Luckily we already alter .exe files so that can't be executed. Should I be concerned with these Content-Disposition, I just started to see a lot (100's a day)

RE: [Declude.Virus] Log File

2003-06-04 Thread Keith Johnson
Scott, We have had a lot of viruses get through today (new Backdoor AVF), seems McAffee is the only one that has it available (sig file). Luckily we already alter .exe files so that can't be executed. Should I be concerned with these Content-Disposition, I just started to see a lot (100's

[Declude.Virus] Declude on RAM Drive

2003-06-04 Thread David Sullivan
I just noticed on Declude site that it is compatible for use on a RAM drive. Haven't used one of these since DOS but trying to squeeze every last bit of performance out of Declude. Anyone doing this or have additional perfomance tuning tips? Thanks -David --- [This E-mail was scanned for viruse

Re: [Declude.Virus] Log File

2003-06-04 Thread Joshua Levitsky
I get those too. I just assumed that it was spam that had fudged MIME headers. -Josh > From: "Keith Johnson" <[EMAIL PROTECTED]> > Reply-To: [EMAIL PROTECTED] > Date: Tue, 3 Jun 2003 16:20:39 -0400 > To: <[EMAIL PROTECTED]> > Subject: [Declude.Virus] Log File > > We have started to get numerous

Re: [Declude.Virus] Log File

2003-06-04 Thread R. Scott Perry
We have started to get numerous of these in our log file, do you know what these may be. 06/02/2003 09:02:09 Q4acf0c270148af58 No filename in disp Content-Disposition: attachment. That's quite unusual -- it indicates that the E-mail has an attachment, but no name was given to it. Technically,

Re: [Declude.Virus] What version should I be using?

2003-06-04 Thread R. Scott Perry
I'm still using 1.66i18 since I hadn't had any problems with it and hadn't seen any reason to upgrade it. I don't remember 1.70 coming out and why I didn't install it. Is there a good reason why I should go to the newer version? I would recommend upgrading to 1.70, as interim releases often c

[Declude.Virus] Log File

2003-06-04 Thread Keith Johnson
We have started to get numerous of these in our log file, do you know what these may be. 06/02/2003 09:02:09 Q4acf0c270148af58 No filename in disp Content-Disposition: attachment. 06/02/2003 09:02:09 Q4acf0c270148af58 No filename in disp Content-Disposition: attachment. 06/02/2003 09:07:09 Q4b

[Declude.Virus] What version should I be using?

2003-06-04 Thread Dan Shadix
I'm still using 1.66i18 since I hadn't had any problems with it and hadn't seen any reason to upgrade it. I don't remember 1.70 coming out and why I didn't install it. Is there a good reason why I should go to the newer version? Dan -- Original Message

RE: [Declude.Virus] F-Prot & Windows 2003

2003-06-04 Thread R. Scott Perry
I have done many tests... virus gets caught but none of the scanners report the name. Eicar comes as unknown. Does the log file show "Unknown"? From the settings you have, it *should* work. -Scott --- Declude JunkMail: The advanced anti-spam

RE: [Declude.Virus] F-Prot & Windows 2003

2003-06-04 Thread Kami Razvan
Title: Message Hi Josh:   this is our setting:   SCANFILE1   C:\Progra~1\FSI\F-Prot\fpcmd.exe /TYPE /SILENT /NOMEM /ARCHIVE /NOBOOT /DUMB /REPORT=report.txtVIRUSCODE1  3VIRUSCODE1  6REPORT1    Infection:   So we are not using code 8.  This is per Declude site.   I have done many tests...