Hello,
Wednesday, March 3, 2004, 11:54:36 PM, you wrote:
>> Do I need to do something on my end to hit this DB??
> Run recent version of declude
> and set AUTOFORGE ON in virus.cfg
Ok that was essy. Thanks.
--
Best regards,
~Paul~ mailto:[EMAIL PROTECTED]
---
{
Hello,
Sine I started using SOPHOS I have been getting the following lines
the Virus Analyzer. Is there away of having it log as the first line and not
the one ones with 'W32/Netsky-C' found in file
S:\spool\D98AC0~1.VIR\\0.com only?
Also i am getting alot of dxxx.vir folders in my sp
Hello,
Can someone share there SCANFILE line out of the virus.cfg file
with me for Sophos.
I have been using the following in my virus.cfg
SCANFILE1 C:\Progra~1\Common~1\networ~1\viruss~1\4.0.xx\scan.exe /ALL /NOMEM /NOBEEP
/NOBREAK /UNZIP /SILENT /NODDA /REPORT report.txt
VIRUSCODE1 13
Hello,
Monday, August 25, 2003, 9:57:08 AM, you wrote:
>>C:\>cd C:\Program Files\Sophos Sweep for NT
>>
>>This is what I got.
>>Seems to be right. Also i can start sav32cli.exe just fine.
RSP> I'm guessing that Sophos installed more than one directory. If you try this:
RSP> cd C:\Pr
Hello,
Monday, August 25, 2003, 8:43:50 AM, you wrote:
>>I am haveing a little problem getting Sophos added as a scanner. The
>>problem is it does not work. Can anyone see what I am missing
RSP> The problem seems to be:
>>SCANFILE C:\Progra~1\Sophos~1\sav32cli.exe -ns -p=report.txt -mac
Hello,
I am haveing a little problem getting Sophos added as a scanner. The
problem is it does not work. Can anyone see what I am missing
===Virus.cfg===
SCANFILE C:\Progra~1\Sophos~1\sav32cli.exe -ns -p=report.txt -mac -archive
VIRUSCODE 3
VIRUSCODE 6
REPORT1>
Hello,
It seems I am getting the Sobig email coming throught to my users
but with ot a payload. In other words tey are getting the message
with all chaistics of SoBig.f but no attachment.
Anyone know why this maybe. I can not filter on some of the subject
such as 'd e t a i l s ... o
CI Travel
X-CYBERsitter-NoXMail: Passed - Adult: 0 (Req: 18) Spam: 0 (Req: 18) Tot: 0 (Req: 20)
X-RBL-Warning: XBL: 163.41.34.208.xbl.selwerd.cx.
X-Declude-Sender: [EMAIL PROTECTED] [208.34.41.163]
X-Declude-Spoolname: D224c093f0600decb.SMD
X-Note: This E-mail was scanned for viruses by Declude Vir
CI Travel
X-CYBERsitter-NoXMail: Passed - Adult: 0 (Req: 18) Spam: 5 (Req: 18) Tot: 5 (Req: 20)
X-RBL-Warning: XBL: 163.41.34.208.xbl.selwerd.cx.
X-Declude-Sender: [EMAIL PROTECTED] [208.34.41.163]
X-Declude-Spoolname: D1cc9d50003ca5674.SMD
X-Note: This E-mail was scanned for viruses by Declude Vir
CI Travel
X-CYBERsitter-NoXMail: Passed - Adult: 0 (Req: 18) Spam: 5 (Req: 18) Tot: 5 (Req: 20)
X-RBL-Warning: XBL: 163.41.34.208.xbl.selwerd.cx.
X-Declude-Sender: [EMAIL PROTECTED] [208.34.41.163]
X-Declude-Spoolname: D13d62cb1066e5efd.SMD
X-Note: This E-mail was scanned for viruses by Declude Vir
CI Travel
X-CYBERsitter-NoXMail: Passed - Adult: 0 (Req: 18) Spam: 5 (Req: 18) Tot: 5 (Req: 20)
X-RBL-Warning: XBL: 163.41.34.208.xbl.selwerd.cx.
X-Declude-Sender: [EMAIL PROTECTED] [208.34.41.163]
X-Declude-Spoolname: D0b76652e03caa7c8.SMD
X-Note: This E-mail was scanned for viruses by Declude Vir
CI Travel
X-CYBERsitter-NoXMail: Passed - Adult: 0 (Req: 18) Spam: 8 (Req: 18) Tot: 8 (Req: 20)
X-RBL-Warning: XBL: 163.41.34.208.xbl.selwerd.cx.
X-Declude-Sender: [EMAIL PROTECTED] [208.34.41.163]
X-Declude-Spoolname: De15a241f01601738.SMD
X-Note: This E-mail was scanned for viruses by Declude Vir
CI Travel
X-CYBERsitter-NoXMail: Passed - Adult: 0 (Req: 18) Spam: 8 (Req: 18) Tot: 8 (Req: 20)
X-RBL-Warning: XBL: 163.41.34.208.xbl.selwerd.cx.
X-Declude-Sender: [EMAIL PROTECTED] [208.34.41.163]
X-Declude-Spoolname: Dd91876840160d2ac.SMD
X-Note: This E-mail was scanned for viruses by Declude Vir
CI Travel
X-CYBERsitter-NoXMail: FAILED - Score Adult: 0 (Req: 18) Spam: 23 (Req: 18) Tot: 23
(Req: 20)
X-RBL-Warning: XBL: 163.41.34.208.xbl.selwerd.cx.
X-Declude-Sender: [EMAIL PROTECTED] [208.34.41.163]
X-Declude-Spoolname: Dca28400503d87a5a.SMD
X-Note: This E-mail was scanned for viruses by De
CI Travel
X-CYBERsitter-NoXMail: FAILED - Score Adult: 0 (Req: 18) Spam: 23 (Req: 18) Tot: 23
(Req: 20)
X-RBL-Warning: XBL: 163.41.34.208.xbl.selwerd.cx.
X-Declude-Sender: [EMAIL PROTECTED] [208.34.41.163]
X-Declude-Spoolname: Dc78d1d02039e4f27.SMD
X-Note: This E-mail was scanned for viruses by De
CI Travel
X-CYBERsitter-NoXMail: Passed - Adult: 0 (Req: 18) Spam: 5 (Req: 18) Tot: 5 (Req: 20)
X-RBL-Warning: XBL: 163.41.34.208.xbl.selwerd.cx.
X-Declude-Sender: [EMAIL PROTECTED] [208.34.41.163]
X-Declude-Spoolname: Dc3476bc003729a9d.SMD
X-Note: This E-mail was scanned for viruses by Declude Vir
CI Travel
X-CYBERsitter-NoXMail: Passed - Adult: 0 (Req: 18) Spam: 0 (Req: 18) Tot: 0 (Req: 20)
X-RBL-Warning: XBL: 163.41.34.208.xbl.selwerd.cx.
X-Declude-Sender: [EMAIL PROTECTED] [208.34.41.163]
X-Declude-Spoolname: Dbdda852203a66978.SMD
X-Note: This E-mail was scanned for viruses by Declude Vir
CI Travel
X-CYBERsitter-NoXMail: FAILED - Score Adult: 0 (Req: 18) Spam: 23 (Req: 18) Tot: 23
(Req: 20)
X-RBL-Warning: XBL: 163.41.34.208.xbl.selwerd.cx.
X-Declude-Sender: [EMAIL PROTECTED] [208.34.41.163]
X-Declude-Spoolname: Dbc2bb2ae0160d644.SMD
X-Note: This E-mail was scanned for viruses by De
CI Travel
X-CYBERsitter-NoXMail: Passed - Adult: 0 (Req: 18) Spam: 0 (Req: 18) Tot: 0 (Req: 20)
X-RBL-Warning: XBL: 163.41.34.208.xbl.selwerd.cx.
X-Declude-Sender: [EMAIL PROTECTED] [208.34.41.163]
X-Declude-Spoolname: Db570efe303768cf1.SMD
X-Note: This E-mail was scanned for viruses by Declude Vir
Subject Change to "Scanner other then McAfee" was "MacAfee kosher or
not?"
I rather end that one.
>I am currently looking into Kaperseky and Command AV, plus a few
others.
Thanks let us know how it goes.
What about Sophos? I guess I could try that one. I bet it cost I
will let the list
>Although it could very easily be argued that the "per mailbox"
licensing
>scheme, if McAfee's license indeed requires it, would apply to *all*
>mailboxes on the Internet, requiring an unlimited number of licenses.
:)
Well the rep kept going back to "I would need to have a
>As a McAfee reseller, and by earlier threads, I had a long conversation
with a senior licensing
>person at McAfee, and the synopsis is that in the usage of scanning
incoming and outgoing e-mail
>messages REQUIRES a per mail box license.
I was just looking at that thread.
I had though there wa
Hello,
I need to renew MacAfee but I was wondering what the consensus on the
Total Virus Defense Suite.
Is it legal? For $98 I should would hate to give it up but the sales
rep is asking a million questions and is saying I will not be in
compliance.
I use F-Prot for the second scanner if I can no
Sheldon,
Does the windows updater work for you? I should say reliably? I have
found it does don't seem to work at all. I do use the scripts for the
server and that works. F-Prot 3.12a
~Paul~
> If you are using the DOS version, there are scripts available to check
and
> download automatically.
ports for Imail at which
time Imail will now be able to read the data and verify user.
Am I close? Any tips or suggested links would be great? Could you
share an overview of you setup?
Thanks,
Paul Ingram
CI Travel
888.461.0022 ext.826
mailto:[EMAIL PROTECTED]
-Original Message
Is there a way to add the footer to only outgoing messages?
I though this might be an easy way to put a company disclaimer in every
out going email. Unless someone else has a better way.
~Paul~
---
[This E-mail scanned for viruses by Declude Virus/McAfee]
---
[This E-mail was scanned for vir
Thanks For the great product and A++ support!!!
~Paul~
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of R. Scott Perry
Sent: Thursday, April 25, 2002 11:13 AM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] Another virus to skip notify
>Would the
Man I hate that. I can't put desktop AV here so Declude is it! They
scream they have to have Hotmail then scream they have a virus. I love
my job! Here come the men in white coats so I must go now!
~Paul~
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of
Would the notification emails be something like this:
SKIPIFVIRUSNAMEHAS Magistr
SKIPIFVIRUSNAMEHAS Kelz
ONLYSENDIFREMOTESENDER
From: postmaster@%LOCALHOST%
To: postmaster@%SENDERHOST%
Subject: Your mail server sent us a virus
Or
SKIPIFVIRUSNAMEHAS W32/Magistr.b@MM; W32/Klez.h@MM; W32/Hybris.wo
he viruses that come throuhg here
Thanks
Dustin
-Original Message-----
From: Paul Ingram [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, April 23, 2002 4:11 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] Huge amount of Klez going around?
I just ran VirusLog Analyzer this is what I have gotten
I just ran VirusLog Analyzer this is what I have gotten today. We have
around 300 users that's it. I looked at the last 7 days and each has
been pretty heavy.
Scott you are DMAN! Thanks for a great product
Count= 72 Virus Name= the W32/Klez.h@MM virus !!!
Count= 50
I have one user who has been sent a virus about 15 times today she is
getting tired of the auto coming to her. What would be the best solution
be. Ban the incoming IP with Imail rules?
Oh the other postmaster for the address is not responding. It is the
KLEZ.H so I know it is spoofing the Addres
., Suite 106
Fullerton, CA 92835
714-578-7999, ext. 104
[EMAIL PROTECTED]
www.reliancesoft.com
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of Paul Ingram
Sent: Thursday, March 21, 2002 10:33 AM
To: Declude. Virus
Subject: [Declude.Virus] Test
Test of
Test of list. Awful quite today?
~Paul~
---
[This E-mail scanned for viruses by Declude Virus/McAfee]
---
[This E-mail was scanned for viruses by Declude Viru
x27;t seem
to get it right
I think it's because there is an ENTER (/n,newline) in the virus command
line!?
--- Marcel ---
- Original Message -----
From: "Paul Ingram" <[EMAIL PROTECTED]>
To: "Declude. Virus" <[EMAIL PROTECTED]>
Sent: Thursday, January 31,
C:\Scanner\scan.exe /ALL
VIRUSCODE1 13
REPORT1 Found
SCANFILE2C:\Scanner2\scanner.exe
VIRUSCODE2 3
VIRUSCODE2 6
REPORT2 Infection
Paul Ingram
CI Travel, IT Systems Analyst
888.461.0022 ext.826
mailto
I changed the lines as you had in the email and still test virus comes
through. So I take out the line and works fine.
So here is a copy of the config again and the log with both scanners when it
is not catching and a log with the original setup that works
Paul Ingram
CI Travel, IT Systems
/ARCHIVE
/NOFLOPPY /NOBOOT /DUMB /REPORT=report.txt
VIRUSCODE 3
VIRUSCODE 6
VIRUSCODE 8
REPORT2Infection
Paul Ingram
CI Travel, IT Systems Analyst
888.461.0022 ext.826
mailto:[EMAIL PROTECTED]
---
[This E-mail scanned for viruses by Declude Virus/McAfee]
---
[This E-mail was scanned for
Seem thing happen to me yesterday after I installed extra.dat still didn't
catch a thing so I tried the install again then stopped and started all
McAfee services and it worked fine.
Good day,
Paul
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Michael
update can be automated via script.
I don't know of an easily automated, reliable source for a current
extra.dat.
Does anyone else?.
Jerry
- Original Message -
From: "Paul Ingram" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Monday, January 28
Thanks!!! Just got it and stop 5 more within 10 min.
Paul Ingram
CI Travel, IT Systems Analyst
888.461.0022 ext.826
mailto:[EMAIL PROTECTED]
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Michael Abbott
Sent: Monday, January 28, 2002 12:34 PM
To
Does anyone no if McAfee is up to date on this? I am running engine 4.1.60
and Defs 4.0.4183
But I just got hit and now have users calling me a five mintues!!!
Paul
---
[This E-mail scanned for viruses by Declude Virus/McAfee]
---
[This E-mail was scanned for viruses by Declude Virus (http://
outstanding product. Thanks!!
Paul Ingram
CI Travel, IT Systems Analyst
888.461.0022 ext.826
mailto:[EMAIL PROTECTED]
---
[This E-mail scanned for viruses by Declude Virus/McAfee]
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
This E-mail came from the
Thanks Scott! The windows version would not work but the DOS version works
like a champ.
Paul Ingram
CI Travel, IT Systems Analyst
888.461.0022 ext.826
mailto:[EMAIL PROTECTED]
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of R. Scott Perry
Sent
I do know this I download the fp-win_311b_m.exe installed and rebooted and
got stop error KMODE_EXCEPTION_NOT_HANDLED. Try to reboot to last know good
config. No luck still blue screen, could not even use safe mode to
uninstall. So I FFR the disk. I did this twice
Fortunately this is a new develop
This is probably the wrong list but here goes.
I would like to test my mail server to make sure I am not relaying or
incompliant with standards (RFC).
Anyone no of some resources I can look at and or should use to help me do
this.
Thanks,
Paul
---
[This E-mail was scanned for viruses by Decl
Ummwhat happens to the email does it get deleted or is it sitting in
file somewhere? I am assumeing it is in the \Imail\spool\virus(just looked
it is)
If this is the case then could still some how if need get the email
delivered?
Paul
-Original Message-
From: [EMAIL PROTECTED]
[mailto
Hello,
Hey it doe work. All get same message but that's ok. This is what I did
To: %ALLRECIPS%,%MAILFROM%,[EMAIL PROTECTED]
From: [EMAIL PROTECTED]
Subject: Delivery Failed due to Banned File Type
The mail server for %LOCALHOST% does not accept E-mail with attachments that
contain the %BANEXT% f
Thanks for the help.
Paul
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of R. Scott Perry
Sent: Monday, December 10, 2001 11:18 AM
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus] BANnotify
>Question I am trying to setup the BANEXT and everything works
bannotify email. And everything else works fine. What am
I missing?
Also please look at the list of files I am trying to ban and if you see some
I have missed that should be there please let me know.
Thanks,
Paul Ingram
-9206
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Paul Ingram
Sent: Tuesday, December 04, 2001 02:54 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] New W32/Goner-A virus
Is not the extra.dat only for the bootdisk for emergency recovery or did I
lo
You are right about F-Prot!!:) I just download and tried it again it it is
now catching it. But as of 45min ago the defs on frisk.is where not
cathching at least it didn't work here but all is rosey now:)
Thanks, Paul
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]O
Does anyone use
F-prot for workstations?
For $2 a system I
thought it might be worth looking into.
Also if I go to
F-Prot on my servers should I use the on demand scanner or just the command line
part?
Paul Ingram
IT Systems Analyst
CI Travel
1.888.461.0022 Ext:826
[EMAIL PROTECTED]
53 matches
Mail list logo