[Declude.Virus] ATTENTION: My E-mail address has changed

2009-05-12 Thread marc . catuogno
Please Change Your Address Book Thank you for emailing me.  Your email has been received, and I will respond as soon as possible. We are pleased to announce that Rand Realty has recently affiliated with Better Homes and Gardens Real Estate.  Accordingly, our email addresses have changed from

[Declude.Virus] ATTENTION: My E-mail address has changed

2009-04-24 Thread marc . catuogno
Please Change Your Address Book Thank you for emailing me.  Your email has been received, and I will respond as soon as possible. We are pleased to announce that Rand Realty has recently affiliated with Better Homes and Gardens Real Estate.  Accordingly, our email addresses have changed from

[Declude.Virus] ATTENTION: My E-mail address has changed

2009-04-23 Thread marc . catuogno
Please Change Your Address Book Thank you for emailing me.  Your email has been received, and I will respond as soon as possible. We are pleased to announce that Rand Realty has recently affiliated with Better Homes and Gardens Real Estate.  Accordingly, our email addresses have changed from

[Declude.Virus] automated response

2007-09-19 Thread Marc Catuogno
For today, 9/19/07, I will be out of the office with limited access to email. Please contact [EMAIL PROTECTED] or [EMAIL PROTECTED] for urgent computer issues. --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsu

RE: [Declude.Virus]

2007-07-12 Thread Marc Catuogno
o the point. > -Original Message- > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On > Behalf Of Marc Catuogno > Sent: Thursday, July 12, 2007 11:54 AM > To: Declude Virus > Subject: [Declude.Virus] > > > > Marc Catuogno > MIS Director > Prude

[Declude.Virus]

2007-07-12 Thread Marc Catuogno
Marc Catuogno MIS Director Prudential Rand Realty 845-825-8025 [EMAIL PROTECTED] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus".The archives can be found at http:

RE: [Declude.Virus] New Virus: zipped word doc with Macro-Virus

2006-06-28 Thread Marc Catuogno
Um, no making fun here - I opened it. I thought it was just spam someone forwarded it to my spam account. I didn't find the Trojan downloader on my PC. I'm ASSUMING that you have to hit the "check prices" macro button as no macro seemed to auto-execute... I just downloaded the intelligent updat

RE: [Declude.Virus] Changes @ Declude

2006-02-10 Thread Marc Catuogno
I didn’t get an e-mail.  Don’t you like me? : )~   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED] Sent: Friday, February 10, 2006 1:47 PM To: Declude.Virus@declude.com Subject: [Declude.Virus] Changes @ Declude   In the last 10 days we have

RE: [Declude.Virus] Blank folding vulnerablity help

2006-01-30 Thread Marc Catuogno
ismiss the latest 3.x release since others are happy with it, but since I run IMail 8.15HF2, there is little in that release that enhances my immediate use, and I am willing to wait a bit longer so that a period of stability can be established before I make the jump. Matt Marc Catuogno wrote:

RE: [Declude.Virus] Blank folding vulnerablity help

2006-01-30 Thread Marc Catuogno
2.0.6.14 and higher.  I think it came along somewhere after 2.0.6.0 Matt Marc Catuogno wrote: Matt thank you – What version of Declude is needed for these “allows”?   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] On Behalf Of Matt Sent: Monday, January 30, 2006 5:09 PM To

RE: [Declude.Virus] Blank folding vulnerablity help

2006-01-30 Thread Marc Catuogno
dress using the following line in your Virus.cfg: ALLOWVULNERABILITIESFROM   [EMAIL PROTECTED] Matt Marc Catuogno wrote: Somebody is sending e-mail that must get through (of course) and it is failing the blank folding Vulnerability test.  What can I tell this person they should do to not have

[Declude.Virus] Blank folding vulnerablity help

2006-01-30 Thread Marc Catuogno
Somebody is sending e-mail that must get through (of course) and it is failing the blank folding Vulnerability test.  What can I tell this person they should do to not have this e-mail get caught?  I don’t want to allow vulnerabilities through but….   01/20/2006 07:25:44 Qd6c809e500d45890

Re: [Declude.Virus] OT: Virus Backscatter

2005-11-23 Thread marc catuogno
ndle filtering >these out, but that worked well for us. > >Darin. > > >- Original Message - >From: "Marc Catuogno" <[EMAIL PROTECTED]> >To: >Sent: Wednesday, November 23, 2005 9:12 AM >Subject: [Declude.Virus] OT: Virus Backscatter > > &

[Declude.Virus] OT: Virus Backscatter

2005-11-23 Thread Marc Catuogno
The latest outbreak has caused me a great deal of backscatter. You sent a banned file, virus in an attachment sent by you, undeliverables and so. I am very hesitant to try to create rules in JM to stop all notices like this because some of them are necessary. I've pretty much told the users to i

RE: [Declude.Virus] Slightly OT: Encrypting or Securing Email Content

2005-10-11 Thread Marc Catuogno
You have a user base that is educated and that you trust enough to click a link that would send them a potential virus? I so envy you... I'm scared to let them open and send and receive regular e-mail. I had one user ready to open an account for someone in Nigera. -Original Message- Fro

RE: [Declude.Virus] OT: Online file check?

2005-07-26 Thread Marc Catuogno
Here is something we use on the agent machines to help block some common spyware sites we bought 150 licenses and set up WGET to update it automatically nightly. http://www.spywareguide.com/blockfile.php We also use spyware blaster, spybot, ms Anti-spy and have written some custom reg blocks that

RE: [Declude.Virus] New virus out?

2005-05-31 Thread Marc Catuogno
I've gotten a few: 26KB files named 1.zip, 7.zip and work.zip so far -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Darrell ([EMAIL PROTECTED]) Sent: Tuesday, May 31, 2005 11:22 AM To: Declude.Virus@declude.com Subject: Re: [Declude.Virus] New virus

RE: [Declude.Virus] EXITSCANONVIRUS

2005-05-30 Thread Marc Catuogno
John,   Sorry to hear about that – it sucks. There was something I heard once about having identical drives mirrored.  That if they were from the same vendor and the same model and lot number they can fail at the same time.  The IBM Deskstar was apparently notorious for this.  If I’m bu

[Declude.Virus] Bypassing whitelist (German Spam)

2005-05-21 Thread Marc Catuogno
I have this set in my global file: BYPASSWHITELIST bypasswhitelist 30 8 0 0 As I understand it, it will by pass the whitelist (whether it is due to whitelistauth or autowhitelist on) if the weight is at least 30 and there are 8 recipients. The German spam is getting through be

[Declude.Virus] A single attachment warning?

2005-03-11 Thread Marc Catuogno
Is there anyway to send one, and only one, warning to someone sending a banned file extension? Something like a vacation message where the sender is stored in a file and is only sent the warning that the server doesn't accept messages with the attachment sent once to prevent annoying people who ha

[Declude.Virus] WinZip Companion for Outlook (OT)

2005-02-28 Thread Marc Catuogno
This is going to a problem for me if it catches on people will think it is "cool" to password their zip files, and since I block them Just thought I'd "heads up" the group in case any of you automatically block encrypted files as well. A choice of Zip 2.0 or 128- or 256-bit AES encryption AE

RE: [Declude.Virus] wuaurlt.exe

2004-12-14 Thread marc catuogno
I also run crap cleaner - it can be set to clean the prefetch, temp Internet files, C:\Documents and Settings\User\Local Settings\Temp and more. It has helped me get virus/Trojan files that won't other wise delete. Also the online scan from Trend Micro is also a great help. It has been a great hel

RE: [Declude.Virus] Recommended Scanner

2004-10-07 Thread marc catuogno
I couldn't get Clamav to run on mine. May I ask what version of ClamAV you are using? When I installed it I couldn't figure out if it was in and Declude kept throwing me an error. What is your Declude config line ? Thanks - Marc -Original Message- From: [EMAIL PROTECTED] [mailto:[EM

RE: [Declude.Virus] GDI false Postive

2004-09-30 Thread marc catuogno
Can we advise anyone sending pictures from a MAC to zip them? Change the extension? Would either solution bypass the scanning? Marc -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of R. Scott Perry Sent: Thursday, September 30, 2004 7:53 AM To: [EMAIL PROT

RE: [Declude.Virus] GDI false Postive

2004-09-29 Thread marc catuogno
Thanks- Both jpgs held were sent by the same person - a graphic designer using a MAC. If that helps you change the code. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of R. Scott Perry Sent: Wednesday, September 29, 2004 10:52 AM To: [EMAIL PROTECTED] Sub

[Declude.Virus] GDI false Postive

2004-09-29 Thread marc catuogno
I had a JPG held by declude as: X-Declude-Virus: Detected [Microsoft GDIPlus.DLL JPEG Vulnerability]. However, this was a JPG sent from one of my users to another. I seriously doubt it was infected with anything. The only thing was that it was sent from a MAC. User-Agent: Microsoft-Entourage/

[Declude.Virus] OT: F prot as a desktop scanner

2004-08-01 Thread marc catuogno
I've been happy with F-prot on the mail server and since I know many people are using it on their servers as well, I was wondering if anyone has it deployed on their user's machines. If so I'd like to know, how well it does on regular windows XP machines. You can't beat the price Thanks - M

RE: [Declude.Virus] OT: Hello?

2004-07-29 Thread Marc Catuogno
Title: OT: Hello? Hi Sharyn.   I haven't seen anything today either, maybe everyone in the north-east is out looking at that strange yellow object in the sky (the sun) and trying to dry out. -Original Message-From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]On Behalf Of Shar

RE: [Declude.Virus] Blocking the files in mydoom

2004-07-26 Thread marc catuogno
http://www.informationweek.com/story/showArticle.jhtml?articleID=25600493 According to this it is double zipping so the only way I can think of stopping it is by banning .zip files completely. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Matt Sent: M

RE: [Declude.Virus] Blocking the files in mydoom

2004-07-26 Thread marc catuogno
Thanks Scott I'm not totally brain dead (only partially) it was definitely a zip file. I did mistype in my haste to ban the .zip files. I ran a manual F-protect update moments again and it is all up to date. I am now blocking all zip files for now. Any chance wild cards or double extensions ca

RE: [Declude.Virus] Blocking the files in MyDoom

2004-07-26 Thread marc catuogno
Also, I have temporarily blocked all zip files, as I am seeing quite a few that are not being caught by banned extension or F-Prot or AVG. I am investigating these. John Tolmachoff Engineer/Consultant/Owner eServices For You > -Original Message- > From: [EMAIL PROTECTED] [mailto:[EMAIL

RE: [Declude.Virus] Blocking the files in mydoom

2004-07-26 Thread marc catuogno
? CRAP. Maybe I should go back to the last beta... I am using F-protect and I updated it about noon and I'm using an interim downloaded about three days ago. Marc -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of marc catuogno Sent: Monday, July 26, 2

RE: [Declude.Virus] Another Varient??!

2004-07-26 Thread marc catuogno
Sorry - yes Virus defs are up to date. I have blocked .zip files for now. I think that they are non-viable files that are slipping through, but I need to stop them as all my users want to know what is going on... I will remove the erroneous entries from my config file. Marc -Original Messag

[Declude.Virus] Blocking the files in mydoom

2004-07-26 Thread marc catuogno
I am running Declude 1.79 and this is in my CFG file: BANEZIPEXTS ON BANEXT com In desperation I have added: BANNAME prudentialrand.com BANNAME prudentialrand.com.zip BANNAME prudentialrand.zip BANNAME [EMAIL PROTECTED] BANNAME *prudentialrand.com.zip The files are still getting through to my u

RE: [Declude.Virus] Another Varient??!

2004-07-26 Thread marc catuogno
They are still getting through to my users. Even though Anyway to banexten on this one? Something like BANNAME *prudentialrand.com.zip Or BANEXT com.zip It is creating some confusion and I'm not sure if it's a viable virus that is getting through or not. I'd like to stop it regardless. Marc

RE: Re[2]: [Declude.Virus] Bitdefender claims terror ties to virus

2004-07-22 Thread marc catuogno
Bonk Bonk on the head... (yes it was Miri) I'd just like to get more people thinking about securing their systems (as I have spent the last hour on a new agents machine removing Ncase and all the other spyware), at least minimally, because it really is scary thinking about what a determined hacker

RE: [Declude.Virus] Bitdefender claims terror ties to virus

2004-07-22 Thread marc catuogno
ets and duct tape away for the time being :) Matt marc catuogno wrote: >What do you guys think of this? > >http://antivirus.about.com/od/virusdescriptions/a/atakb.htm > >I've forwarded it to all my users, maybe they will take their computer >security more seriously. &g

[Declude.Virus] Bitdefender claims terror ties to virus

2004-07-21 Thread marc catuogno
What do you guys think of this? http://antivirus.about.com/od/virusdescriptions/a/atakb.htm I've forwarded it to all my users, maybe they will take their computer security more seriously. Marc --- [This E-mail scanned for viruses by Declude Virus] --- [This E-mail was scanned for viruses by

RE: [Declude.Virus] OT: "Animal" Messages with Viruses?

2004-07-21 Thread marc catuogno
I checked a few out and figured they weren't dangerous and told everyone that they were corrupted or "stripped" attachments... but the support calls and e-mails about the passworded zip files that everyone got, what a waste of time, sigh. I did a Baname on what was listed as possible file names f

RE: [Declude.Virus] OT: "Animal" Messages with Viruses?

2004-07-21 Thread marc catuogno
I am running 1.79 (I don't remember which interim but I wil D/l the latest) I have in my global config: BANEXT EZIP BANEZIPEXTS ON I am still getting some e-mails through. They are zip files 67 bytes or so and don't seem to have anything in them nor are they password protected. Any way to stop

RE: [Declude.Virus] Mcafee NetShield Problems

2004-04-28 Thread marc catuogno
Start;Programs;Imail;Imail release notes - I'm really shocked that they don't put this in Imail admin or help or something... -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Scott Hahn Sent: Wednesday, April 28, 2004 8:40 PM To: [EMAIL PROTECTED] Subject:

RE: [Declude.Virus] Deactivation

2004-04-07 Thread marc catuogno
I believe you are in the same exact situation you were before the trial. Imail would've passed on the spam and viruses too with out Declude. I would buy it, really, it is the only thing saving my butt... Marc -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf

RE: [Declude.Virus] OBJECT CODE vulnerability?

2004-03-19 Thread marc catuogno
Thank you, Scott. Over 600 real-estate agents on their individual workstations and laptops repeatedly told to do their own critical updates, I sent them all the link to the update page yesterday and warned them they could get infected by previewing a message - high risk... : ) I was wondering ab

RE: [Declude.Virus] NAV 2003 catches passworded virus??

2004-03-16 Thread marc catuogno
TECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Nick Sent: Tuesday, March 16, 2004 6:18 PM To: [EMAIL PROTECTED] Subject: Re: [Declude.Virus] NAV 2003 catches passworded virus?? On 16 Mar 2004 at 17:20, marc catuogno wrote: Marc, I do not have Norton so I cannot test it - have you sent to y

[Declude.Virus] NAV 2003 catches passworded virus??

2004-03-16 Thread marc catuogno
Sorry, I know I’ve brought this up before but I’m befuddled as to how plan old Norton Antivirus 2003 on my XP desktop using outlook 2002 can pick up this virus within a passworded file without the password.   This was held in the virus directory by Declude and I released it to see if it w

RE: [Declude.Virus] A different view of banned files

2004-03-16 Thread marc catuogno
I think this has been brought up a few times, I think it would be a good option as well once it is tweaked. You forgot PDF, txt, bmp, wks, wpd, ppt and maybe .zip : ) -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Dan Shadix Sent: Tuesday, March 16, 200

RE: [Declude.Virus] NAV 2003 catches beagleJ in encrypted zip?

2004-03-07 Thread marc catuogno
If you want I can send it to you, it isn't important but I found it curious. All I know is it is a virus, it is reported as beagle.j by NAV, it is in a passworded .Zip file, there in nothing but the word "test" in the body of the e-mail and it is caught by the e-mail scanning as it goes out. ---

RE: [Declude.Virus] NAV 2003 catches beagleJ in encrypted zip?

2004-03-07 Thread marc catuogno
Plain old NAV 2003 on my Win XP workstation that scans e-mail - sorry for not being specific. BUT the weird thing is there was no e-mail with a PW. I had saved the file from one that had gotten through and attached it to a e-mail with the only the word "test" in the body of the e-mail. I don't eve

[Declude.Virus] NAV 2003 catches beagleJ in encrypted zip?

2004-03-06 Thread marc catuogno
I was trying to test the latest interim and when I tried to send myself a copy of the virus, NAV outbound scanning caught it even though it was passworded. I tried to unzip it to make sure and it does require a password. I didn't think they could detect it like that... --- [This E-mail scanned fo

RE: [Declude.Virus] Bagle.J / news.com article on AV software opening zipped files.

2004-03-05 Thread marc catuogno
I hate to say it, because it sucks, but I had mentioned it before... A challenge/response system for attachments. It could cause a bunch of crap, but since all these viruses forge the return address a user is likely to say "no, I didn't send that" and that could reduce the number of viruses expone

RE: [Declude.Virus] Use Net Send to alert user of virus?

2004-03-05 Thread marc catuogno
For You > -Original Message- > From: [EMAIL PROTECTED] [mailto:Declude.Virus- > [EMAIL PROTECTED] On Behalf Of Marc Catuogno > Sent: Thursday, March 04, 2004 4:39 PM > To: [EMAIL PROTECTED] > Subject: [Declude.Virus] Use Net Send to alert user of virus? > > Does

[Declude.Virus] Use Net Send to alert user of virus?

2004-03-04 Thread Marc Catuogno
Does anyone have a way of using doing this? I mean if scumware people and pornographers can use the windows messenger service why can't I? I know it wouldn't always work, but most of the IP's I get in my virus notifications are from Road Runner or Cablevision. I'll bet more than half of those pe

RE: [Declude.Virus] marking subject line

2004-03-04 Thread marc catuogno
Scott - you may shoot me for suggesting this, especially if it has been suggested before. I am not a programmer so I suggest this not knowing how difficult it may be, but if both Virus and Junkmail use the declude.exe is it possible to have things like BANEZIP be defined as a test in the global fil

[Declude.Virus] Interium release 1.78i9 now blocking PWed zip files using BANEZIPEXTS ON!

2004-03-03 Thread marc catuogno
Thanks Scott!!! I just D/Led i9 and changed my config file to: #BANEXT EZIP BANEZIPEXTS ON I sent myself the virus, twice,and it held it in the /spool/virus directory. I am also seeing more files start to accumulate there. Marc --- [This E-mail scanned for viruses by Declude Virus] --- [Thi

RE: [Declude.Virus] New interim release to ban extensions in .ZIP files

2004-03-03 Thread marc catuogno
D:\IMail>declude -diag Declude 1.78i8 (C) Copyright 2000-2004 Computerized Horizons. Diagnostics ON (Declude v1.78i8). Declude JunkMail: Config file found (D:\IMail\Declude\global.CFG). Declude Virus: Config file found (D:\IMail\Declude\Virus.CFG). Declude Hijack:Not installed (no D:\IM

RE: [Declude.Virus] Passworded zip files still getting through!

2004-03-03 Thread marc catuogno
Confirmed. I commented out # BANEZIPEXTSON I left in: BANEXT EZIP And resent myself the virus and it was blocked. Marc -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Todd Ryan Sent: Wednesday, March 03, 2004 11:18 AM To: [EMAIL PROTECTED] Subje

RE: [Declude.Virus] Passworded zip files still getting through!

2004-03-03 Thread marc catuogno
Sorry for my incomplete message what I meant to say is that they are still getting PASSWORDED zip files. Even with the addition of BANEXT EZIP -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of R. Scott Perry Sent: Wednesday, March 03, 2004 10:48 AM To: [EM

[Declude.Virus] Passworded zip files still getting through!

2004-03-03 Thread marc catuogno
F.Y.I. I am running the latest interim release: 1.78i.8 and have BANEZIPEXTS ON In my config file but several people have complained to me that they are still getting the zipped files. I have added BANEXT EZIP In the hopes of stopping them all now. Marc --- [This E-mail scanned for vir

[Declude.Virus] Blocking attachments - feature request

2004-03-03 Thread marc catuogno
Scott - I know you have so much time on your hands... But what about a feature that allows only the attachments listed in the SKIPEXT? Though I imagine that would by pass virus scanning :( Or something like: ALLOWEXT .PDF ALLOWEXT .JPG Ect - I would be very happy to only allow a limited number

RE: [Declude.Virus] Update- New virus

2004-03-03 Thread marc catuogno
I didn't see your last e-mail? What virus? -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Kami Razvan Sent: Wednesday, March 03, 2004 8:32 AM To: [EMAIL PROTECTED] Subject: [Declude.Virus] Update- New virus Hi; Just to update my last email.

[Declude.Virus] OT: Netsky pronunciation?

2004-03-02 Thread marc catuogno
I saw a woefully inadequate report on this virus on Fox 5 NY last night - don't even get me started, do these reporters even talk to people who deal with viruses? Love how they report it as "new" yesterday - but anyway, the reported called it net-ski. I have been inclined to call it that as well.

[Declude.Virus] .PIF files being held instead of deleted?

2004-03-01 Thread Marc Catuogno
I am running the latest beta 1.78. I have the following in my virus.cfg file: BANEXT scr BANEXT pif BANEXT bat BANEXT exe DELETEVIRUSES ON Yet I am still seeing e-mails with .PIF extensions being held in the virus subfolder. I'm concerned that these are mak

RE: [Declude.Virus] BANEXT

2004-02-01 Thread marc catuogno
That was a great list. I have the following extensions blocked as well: BANEXT data BANEXT link BANEXT unk BANEXT uue I wish I remember why - but I imagine it won't hurt... -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf

RE: [Declude.Virus] A horrible idea - maybe it could work?

2004-01-31 Thread marc catuogno
bother to acutally read the statement and follows the information to deliver the mail whether she remembers it or not and cousin Fred is infected. Challenge/Response is ok for end users, but I don't see a real benefit for it with servers. Rich - Original Message - From: "marc

[Declude.Virus] A horrible idea - maybe it could work?

2004-01-31 Thread marc catuogno
I know everyone hates the challenge response system BUT what if there was a way to adapt it for attachments? If an e-mail is sent with an attachment the server sends a challenge to the supposed sender who can verify or deny having sent it. Denial would delete the e-mail, verification would allow

[Declude.Virus] FW: Your mail server sent us a virus

2004-01-30 Thread marc catuogno
Scott - did you ever find these guys? They still don't get it... -Original Message- From: Postmaster [mailto:[EMAIL PROTECTED] Sent: Friday, January 30, 2004 10:08 AM To: [EMAIL PROTECTED] Subject: Your mail server sent us a virus The Declude Virus software on our mail server detected t

RE: [Declude.Virus] new forging worm: Bagle

2004-01-19 Thread Marc Catuogno
AH! That is a nice feature that I must have missed! Gratzie! Marc -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of Markus Gufler Sent: Monday, January 19, 2004 09:42 AM To: [EMAIL PROTECTED] Subject: RE: [Declude.Virus] new forging worm: Bagle > Wouldn't

RE: [Declude.Virus] new forging worm: Bagle

2004-01-19 Thread Marc Catuogno
Wouldn't you want to also update your otherpostmater.eml and sender.eml with: SKIPIFVIRUSNAMEHAS Bagle SKIPIFVIRUSNAMEHAS Beagle To stop the bogus warnings? -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of Markus Gufler Sent: Monday, January 19, 2

[Declude.Virus] blocking mimail

2003-11-04 Thread Marc Catuogno
How is everyone blocking this virus? -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of R. Scott Perry Sent: Monday, November 03, 2003 1:41 PM To: [EMAIL PROTECTED] Subject: Re: [Declude.Virus] Zips are corrupt >They are regular emails, I just sent you an

RE: Re[2]: [Declude.Virus] SoBig more prolific now?

2003-09-08 Thread Marc Catuogno
I have been doing that, but I have heard that IMAIL's CAL can only handle 100 IPS and I am running at about 90 now. Most of the offenders are from Optimum online, I could block their whole IP range, but then I think my home Optimum users trying to POP or SMTP (maybe even Webmail)won't be able to c

[Declude.Virus] SoBig more prolific now?

2003-09-06 Thread Marc Catuogno
Last night I got hammered with about 3,000 "sobigs" in the course of about 2 hours from one infected computer - it seems this particular computer had almost every address from my domain on it. This morning I got about 100 from another computer - the strange thing was that all 100 were sent to a si

[Declude.Virus] Blocking SObig IPs

2003-09-05 Thread Marc Catuogno
This maybe a stupid observation so bear with me please. As I was adding more and more IPs to the control access list something occurred to me. It seems that most of the offending IPs are from cablevision companies. If I could get the range of their dynamic IPS I could block them all, permanently

[Declude.Virus] FW: Your mail server sent us a virus

2003-09-04 Thread Marc Catuogno
Scott can you bitch slap this moron? I've sent him three separate e-mails with detailed instructions (I think I even copied one to the list) on how to turn this off in Declude and he hasn't replied once. Maybe you have a better contact e-mail. Marc -Original Message- From: Postmaster [ma

RE: [Declude.Virus] Your mail server sent us a virus: SOBIG FORGES

2003-08-30 Thread Marc Catuogno
The sobig virus forges the sender, as you should know. The Declude software allows you to indicate this in the bounce message to yourself by putting the line "FORGINGVIRUS Sobig" in the virus.cfg fie. It also allows you not send this notification by putting the line "SKIPIFVIRUSNAMEHAS Sobig"

RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2003-08-30 Thread Marc Catuogno
I had to argue with an IMAIL admin with Declude for two days and had to e-mail him the damn otherpostmaster and sender eml files before he would change them. I hope my change took effect... : ) -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of John Tolmach

RE: [Declude.Virus] SoBig

2003-08-30 Thread Marc Catuogno
I've been sticking the IPs into IMAIL's control access list as fast as they have been coming in. Declude reports them and I'm popping them in there and I'm not sure I'm ever going to remove them. Under local host > SMTP > second tab SMTP security > Control access button You must stop and restart

RE: [Declude.Virus] No wonder viruses spread

2003-08-25 Thread Marc Catuogno
So if a forged user from my domain sends a message to another IMAIL machine to a user that doesn't exist and then their Imail Machine rejects the message. I'm assuming that postmaster gets the entire message (virus included) based upon the forged domain. So I would get the message, even though no

RE: [Declude.Virus] No wonder viruses spread

2003-08-24 Thread Marc Catuogno
But since the subject that you are receiving is "undeliverable : RE: Details" isn't that his server is just returning the message Unless the virus has more subjects then the list of subjects that I am aware of. Looks like the original message had the virus attached and that was Declude detected wh

RE: [Declude.Virus] No wonder viruses spread

2003-08-24 Thread Marc Catuogno
Um - I'm not sure, but I think he may be right. The declude virus catch looks like a bounce from his server, not sent through his server. As you said the e-mail address is forged - so if an infected computer has a user from your domain and a bad address from his, once his server can't deliver the

RE: [Declude.Virus] Notifying Postmasters/ISPs etc of viruses

2003-08-20 Thread Marc Catuogno
The Pentagon? REALLY??? That's friggin scary as hell -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of R. Scott Perry Sent: Wednesday, August 20, 2003 06:32 PM To: [EMAIL PROTECTED] Subject: Re: [Declude.Virus] Notifying Postmasters/ISPs etc of viruses

[Declude.Virus] Notifying Postmasters/ISPs etc of viruses

2003-08-20 Thread Marc Catuogno
Does anyone else bother to look at the header, do a who is on the IP and notify the responsible party of the possible problem on their IP? I see the IPs in the e-mail headers so if someone was notified do you think they can find the actually infected user? Would they bother? I checked some of my

RE: [Declude.Virus] BANEXT to delete all .pif?

2003-08-20 Thread Marc Catuogno
I just ran a manual scan on the spool virus directory with F-protect and it identified all the held viruses as [EMAIL PROTECTED] - BUT I did run an update immediately before that even though I ran it this morning. Marc -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] B

RE: [Declude.Virus] BANEXT to delete all .pif?

2003-08-20 Thread Marc Catuogno
I thought BANEXT worked before the scanner? DAMN... maybe my f-protect.exe is old and not catching viruses? -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of R. Scott Perry Sent: Wednesday, August 20, 2003 04:03 PM To: [EMAIL PROTECTED] Subject: Re: [Declude

[Declude.Virus] BANEXT to delete all .pif?

2003-08-20 Thread Marc Catuogno
Please excuse this if it has already been answered- Just like everyone else, we are getting hammered by Sobig.F. Declude seems to be catching and holding the virus e-mails with the attachments because of the BANEXT option. The potential exists to overload our hard drive. There were over 3,000 he

[Declude.Virus] Turing off .pif notifications? (sobig.F)

2003-08-19 Thread Marc Catuogno
I have BANEXT active, and as a courtesy I have a notification through Delcude going out in case someone is legitimately trying to send an .exe file. Is there anyway to turn this off for the .pif extension? The SOBIG.F Virus is sending this to all my users with fake e-mail addresses and then the n

Re: [Declude.Virus] Declude letting viruses through?

2002-11-06 Thread Marc Catuogno
Strictly paranoia. In case something does get through. In case one of my users sends out a virus through their webmail. I usually just do a full system scan once a week or so, I don't have the scanner running all the time. Marc - Original Message - From: "John Tolmachoff" <[EMAIL PROTECT

RE: [Declude.Virus] Declude letting viruses through?

2002-11-06 Thread Marc Catuogno
Declude has been installed for months, BUT you are right, these e-mails were delivered two days and a month before it seems that declude was installed (respectively). The weird thing is that the full system scan only reported them recently... one last week and another this week. Strange. Thank

[Declude.Virus] Declude letting viruses through?

2002-11-06 Thread Marc Catuogno
I do a weekly scan with of my Imail sever with F-protect and disturbingly enough it found two viruses in the main.mbx files of two of my users.  F-protect 3.12a reported them as klez.E@mm and the attachment was called logon [2].pif.  I copied the MBX file to a test user to see if I could fi