Is anyone using ClamWin 0.90.2.1 with Declude AV? I was, using the following
line from the virus.cfg:
SCANFILE4 C:\Progra~1\ClamWin\bin\clamscan.exe --verbose
--database=C:\Docume~1\AllUse~1\.clamwin\db
--tempdir=C:\PROGRA~1\IPSWITCH\IMAIL\Declude\Scanners\ClamAV --no-summary -l
report.txt
All o
cAfee and have
no issues.
Darrell
---
Check out http://www.invariantsystems.com for utilities for Declude, Imail,
mxGuard, and ORF. IMail/Declude Overflow Queue Monitoring, SURBL/URI
integration, MRTG Integration, and Log Parsers.
John Shacklett writes:
> After loading 4.2.20
After loading 4.2.20 this afternoon, my AVG scanner is now finally detecting
viruses. Oh happy day. Now if I can just get scan.exe to work, I'll have a
full house.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of John Shacklett
Sent: Thursday, 11 May
't working
now that the lines are gone.
PS: I still haven't received a resolution on my problem with AVG not finding
any viruses.
--
John Shacklett
[EMAIL PROTECTED]
[EMAIL PROTECTED]
www.continentaloffice.com
---
This E-mail came from the Declude.Virus mailing list. To
unsubsc
what does your diags.txt? Did 4.2.3 in fact get fully
installed and running?
John C
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of John Shacklett
Sent: Thursday, May 11, 2006 6:56 AM
To: Declude.Virus@declude.com
Subject: RE: [Declude.Virus] 4.2.
I guess I should have been more dramatic. What I intended this to mean was
that I still don't see any evidence that AVG is working at all.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of John Shacklett
Sent: Tuesday, 09 May 2006 3:04 PM
To: Declude.
Just for fun, I completely commented out the three scanners in my virus.cfg
and resent the eicar plain test file, and it made it to my Inbox.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of John Shacklett
Sent: Tuesday, 09 May 2006 9:58 AM
To
ender http://www.declude.com/Articles.asp?ID=99
2. Check your virus logs
3. Declude\Scanners\AVG\DB
4. Check the date on the database files
David B
www.declude.com
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of John Shacklett
Sent: Tuesday, May 09, 2006
Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of John Shacklett
Sent: Tuesday, May 09, 2006 8:45 AM
To: Declude.Virus@declude.com
Subject: [Declude.Virus] 4.2.3 Built-in scanner
How do I determine if the built-in scanner is working? Where do the virus
signature files live? How
How do I determine if the built-in scanner is working? Where do the virus
signature files live? How do I tell if those files are being updated?
--
John S
---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe De
That won't work, I believe that anything with an eml extension gets
processed. Change the .eml to .hold instead.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of GlobalWeb.net
Webmaster
Sent: Wednesday, 19 April 2006 9:02 AM
To: Declude.Virus@declude.com
Su
Is anyone using an etrust product for scanning? We now have one of the
etrust products installed on our mailserver, and I don't have any feeling --
good OR bad -- about it. What are etrusters using for switches and
configuration? I'm running it as scanner3, behind f-prot and clamAV.
Thanks,
John
ages in my virus logs over the last several days. My virus scanner
#1 is scan-dot-exe from our good friends at McAfee. Have others been having
issues with scan-dot-exe? I don't see an engine update, and I don't see
anything else peculiar in my DAT updates, but this puppy isn't performing.
I've gotten a couple that were 1 byte sized [sorry, couldn't resist], kind
of like some of the corrupted ZIP files we've gotten this week.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of David Dodell
Sent: Wednesday, April 28, 2004 6:32 PM
To: [EMAIL PRO
I asked f-prot support about this and all they've told me so far is:
"This option was added to counteract the flow of worms inside password
protected zip archives."
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Fritz Squib
Sent: Tuesday, March 16, 200
riginal Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of John Shacklett
Sent: Tuesday, March 16, 2004 5:32 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] F-prot 3.14e
I didn't have 3.14d loaded in production long enough to form an opinion, but
3.14e seems to
I didn't have 3.14d loaded in production long enough to form an opinion, but
3.14e seems to be working perfectly.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of John Shacklett
Sent: Tuesday, March 16, 2004 12:12 PM
To: [EMAIL PROTECTED]
Su
Good morning. Here's a new twist.
I got one this morning that read:
The mail server for continentaloffice.com does not accept E-mail with
attachments that contain the readme.zip extension.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of John Shac
Thank you. Now that I've had to block ZIP files, this has become a larger
issue. After years of telling my users "just ZIP up anything you need to
send that would otherwise get blocked" I'm ready to scream.
I'm guessing I won't be screaming alone though.
-Original Message-
From: [EMAIL P
Is it possible to have messages containing attached files with banned
extensions land somewhere other than the \declude\virus folder?
--
John Shacklett
[EMAIL PROTECTED]
[EMAIL PROTECTED]
www.continentaloffice.com
---
[This E-mail was scanned for viruses by Declude Virus (http
This question sure seems to come up regularly. Here's my slant:
We are a smallish private company, and our clients span the spectrum from
private individuals to major multinational behemoths. We have one client in
particular that sends us electronic purchase orders generated by their
in-house purc
After reading your post I went in and looked at my server, and the
[expletive deleted] McAfee Autoupdater hadn't successfully processed an
update since the 19th when it pulled 4286. That meant that we were on 4286
DATs and not the current 4288. I forced an update manually, and it pulled
these new d
I'm running late catching up on my Declude lists today, so forgive me for
jumping in here - not only late but in the middle of the thread.
Twice today I have been sitting at local users machines for unrelated tasks,
and in both cases I noticed notifications in their local email inboxes
warning abo
I am doing it, thanks.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] Behalf Of R. Scott Perry
Sent: Thursday, 29 May 2003 9:27 AM
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus] IPBYPASS
>Does Declude Virus know how to handle IPBYPASS lines in the virus.cfg fil
addresses.
--
John Shacklett
www.continentaloffice.com
[EMAIL PROTECTED]
[EMAIL PROTECTED]
Living on Earth is expensive, but it does include a free trip around the sun
every year.
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
---
This E-mail came from the
I think I have things back to normal. I'm writing this off to a buggered
fpcmd.exe file. As soon as I reinstalled f-prot, things started working
properly. I even caught a klez by happenstance in the middle of the eicars,
all with both scanners, so I'm going home.
-Original Message-
From: [
Yep. I changed the name of the old one and dropped the new one right in its
place. I'm going to get a fresh copy of 3.12D and repeat the install, and do
some more Eicar testing and get this right.
Thanks for the insights.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTE
else seen this pattern occur?
--
John Shacklett
www.continentaloffice.com
[EMAIL PROTECTED]
[EMAIL PROTECTED]
You read about all these terrorists--most of them came here legally, but
they hung around on these expired visas, some for as long as 10 to 15 years.
Now, compare that to Blockbust
Nope, no c:\declude.gpx files, I looked for those first. And I agree with
your conclusion about what happened, I just wish I had looked at the task
manager to see if there were a boatload of smtp32.exe processes sitting in
limbo. I'll bet there were.
-Original Message-
From: [EMAIL PROTECT
[mailto:[EMAIL PROTECTED]] On Behalf Of John Shacklett
> Sent: Thursday, December 12, 2002 1:00 PM
> To: [EMAIL PROTECTED]
> Subject: RE: [Declude.Virus] OT: F-Prot definition updating
>
>
> Gosh, you have an actual Delete key? What a lucky, lucky man.
> What wonders to mine eyes
Gosh, you have an actual Delete key? What a lucky, lucky man. What wonders
to mine eyes appear.
To supplement my Delete key, I'm trying to add a line to the cmd file along
the lines of
IF EXIST %IMAILSPOOLDIR%/MAGICSYMBOLiCANTFIGUREOUT THEN DELETE
%IMAILSPOOLDIR/MAGICSYMBOLiCANTFIGUREOUT
-Or
on the command line that
IMail generates to invoke the script?
Thanks.
--
John Shacklett
www.continentaloffice.com
[EMAIL PROTECTED]
[EMAIL PROTECTED]
Before you criticize someone,
walk a mile in his shoes.
Then when you do criticize that
person, you'll be a mile away and
you'l
Scott, you'll have to start signing as J. Scott Perry to qualify in our new
secret society.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of John Carter
Sent: Friday, 06 December 2002 3:14 PM
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus] change in logs
Something is goofy here too. I have a fp-win_312c_m.exe file sure enough,
and if I open the installer with winzip and look at the contents everything
important has 12/2 or 12/4 modification dates [unlike my fp-win_312b_m.exe
file where everything has 9/27 & 9/30 dates], but my "new" FP-win.exe file
I can live with that.
NB: Don't change the behavior of SKIPEXT.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of R. Scott Perry
Sent: Wednesday, 04 December 2002 12:58 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] Ban/Allow extensions
>I don't s
Not yet, but I've only had it running for a half hour or so.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Bill Newberg
Sent: Wednesday, 04 December 2002 1:03 PM
To: [EMAIL PROTECTED]
Subject: [Declude.Virus] F-Prot 3.12c
Has anyone tested F-Prot 3.12c
Along the same lines as my argument a couple of weeks ago that the best
solution for "vulnerabilities" checking would be to allow either
declude.virus or declude.junkmail to handle them and allow the individual
administrator decide which handling best served the local interests, I'd
like to see a s
Same procedure.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Jim Rooth
Sent: Tuesday, 26 November 2002 9:26 AM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] Partial Vulnerability
Going back through her emails I see she is using Outlook Express 5.
Tools --> Accounts --> "account" --> Properties --> Advanced --> clear the
"break messages apart" checkbox
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Jim Rooth
Sent: Tuesday, 26 November 2002 9:18 AM
To: [EMAIL PROTECTED]
Subject: [Declude.Virus] Part
file send an email!!
HTH,
Russ
-Original Message-
From: John Shacklett [mailto:[EMAIL PROTECTED]]
Sent: Friday, November 22, 2002 2:23 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] installed.bin
But, if I don't have access to the machine, then I don't have access t
ve? Can the mailserver get to your c drive? Our is
>there a machine that both the mailserver, and your machine have access to??
>If so, you could make the batch file map a drive using a specified
>username/password.
>-Russ
>
>-Original Message-
>From: John Shacklett
declude.txt) and use
the NT at command to make it run every x hours... Then you could pull that
declude.txt file and know that it was last updated x hours ago... Just my
$0.02
-Russ
-Original Message-
From: John Shacklett [mailto:[EMAIL PROTECTED]]
Sent: Friday, November 22, 2002 1
lude.Virus] installed.bin
You could always setup terminal services or another remote access terminal
program on your server too.
Jim Matuska Jr.
Nez Perce Tribe
Information Systems
[EMAIL PROTECTED]
- Original Message -----
From: "John Shacklett" <[EMAIL PROTECTED]>
To: <[E
e.txt or where ever you want it.
John Tolmachoff MCSE, CSSA
IT Manager, Network Engineer
RelianceSoft, Inc.
Fullerton, CA 92835
www.reliancesoft.com
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of John Shacklett
Sent: Friday, November 22, 2002 8:27 AM
To
Right, but I'm routinely not close enough to the server to be able to
actually run the command.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of R. Scott Perry
Sent: Friday, 22 November 2002 11:34 AM
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus] instal
The installed.bin file in the Declude directory has the current version
info. Could that be expanded to include more of the declude -diag data?
--
John Shacklett
www.continentaloffice.com
[EMAIL PROTECTED]
[EMAIL PROTECTED]
Before you criticize someone,
walk a mile in his shoes.
Then when
I have
Sniffer set high enough to trigger my hold level all by itself, and Sniffer plus
six more points variously defined is enough to delete. [N.B.: I have heavily
customized the weights.]
-Original Message-From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On
Behalf Of Trent M. Dav
Depends on what you mean by old. No Spring Chicken. Certainly old enough to
invest a battery in, thanks for the suggestion.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Paul Navarre
Sent: Thursday, 26 September 2002 3:42 PM
To: [EMAIL PROTECTED]
Subjec
John Shacklett
Sent: Thursday, 26 September 2002 3:01 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] Scan Leak
Ugh.
I reloaded f-prot, and I also tried reverting to definitions from earlier in
the week, all so far without success. But I did notice that my
updatefprot.cmd fired off at just
Ugh.
I reloaded f-prot, and I also tried reverting to definitions from earlier in
the week, all so far without success. But I did notice that my
updatefprot.cmd fired off at just about 8:30 last night [surprise?], so I'll
keep trying.
Thanks for the instant and accurate analysis, as always.
---
Could someone please repost the latest and greatest version of the
usage.c-m-d file? I've been rooting around on mail-archives trying to track
it down, but the first of March is gaining on me and I need to patch mine.
--
John Shacklett
www.continentaloffice.com
[EMAIL PROTECTED]
[
I agree with Mike completely.
Somewhere way down near the bottom of the requested new features I'd like to
add: "ability to turn off some or all of the virus .eml notifications if the
Outlook 'CR' Vulnerability is the only test failed."
-Original Message-
From: [EMAIL PROTECTED]
[mailto:
Gee, Ric, good advice. Except that we consider this to be the point of the
betas.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Ric Stevenson
Sent: Tuesday, February 19, 2002 1:07 PM
To: [EMAIL PROTECTED]
Subject: RE: MISSING_REVERSE_DNS:RE: [Declude.Vi
Can I put XINHEADER and XOUTHEADER lines in the virus.cfg file, similar to
what is in global.cfg for JunkMail?
OK, I know I can put the lines in there, but will they work the same way?
--
John Shacklett
www.continentaloffice.com
[EMAIL PROTECTED]
[EMAIL PROTECTED]
A television may insult
:\IMail\spool\D892814c.vir\0.dat
12/18/2001 13:22:01 Q894714a Error opening TNEF file
C:\IMail\spool\D894714a.vir\0.dat
--
John Shacklett
www.continentaloffice.com
[EMAIL PROTECTED]
[EMAIL PROTECTED]
A Zen master once said to me "Do the opposite of whatever I
tell you." So I didn
Well, while they're debating business ethics, I'll bite:
How do I configure multiple virus scanning?
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of R. Scott Perry
Sent: Tuesday, December 18, 2001 1:12 PM
To: [EMAIL PROTECTED]
Subject: [Declude.Virus] De
ftp://ftp.nai.com/pub/antivirus/superdat/intel/sdat4164.exe
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Serge Dergham
Sent: Thursday, October 11, 2001 4:57 PM
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus] McAfee NetShield Upgrade
thanks
just t
My Declude/McAfee caught it straight away.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of R. Scott Perry
Sent: Monday, October 08, 2001 11:43 AM
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus] Magstr.39921
>Attached is the Imail Mailbox with a viru
another request
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Hirthe, Alexander
Sent: Thursday, October 04, 2001 9:20 AM
To: '[EMAIL PROTECTED]'
Subject: MISSING_REVERSE_DNS:RE: [Declude.Virus] two scanner Support
Hello Scott,
> >Scott, any chance of
It works for me, very well.
And thank you to everyone who suggested the kill.exe program. That works
very well as well. Well.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Gerald Woods
Sent: Thursday, September 06, 2001 11:39 AM
To: [EMAIL PROTECTED]
S
rsion
yesterday morning. The unsettling thing was when I tried to kill that
process in task manager, I was prevented. Told me I couldn't. And I was
logged in as administrator.
So I bounced the box and all seems better, but I think I'm going to put an
active watch on the machine today and see
Here's the top of today's log:
08/30/2001 00:01:16 Qba8b108 MIME file: [text/html][7bit]
08/30/2001 00:01:17 Qba8b108 Scanned: Virus Free [MIME: 2 14502]
08/30/2001 00:04:28 Qbb4b13a Scanned: Virus Free [MIME: 1 827]
08/30/2001 00:07:24 Qbbfc13c MIME file: [text/html][7bit]
08/30/2001 00:07:26 Qb
#
# Declude Virus configuration file
#
CODE
LOGFILE C:\IMail\spool\vir.log
LOGLEVELhigh
LOG_OK NONE
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of R. Scott Perry
Sent: Thursday, August 30, 2001 2:58 PM
I already had /ALL in my SCANFILE line, and I have the latest virus
definitions updated every morning at three o'clock, so I think I was trying
my best. And I am catching the great majority of SirCam-infected offerings,
but I've had at least a half dozen get past. Including two more this
morning.
I haven't had a chance to get v1.16 yet, but when I started having problems
with 1.15 I reverted back to 1.14. Then, for some unknown reason, I started
getting every e-mail notification message twice.
I'm going to hold off on 1.16 until someone clarifies the situation
mentioned in Gary Cuppett's
I show 1.12 as 246 kb.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of John Carter
Sent: Friday, February 16, 2001 1:40 PM
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus] Trouble with sender/recipient addresses
Far less scientific: my "old" copies o
66 matches
Mail list logo