[Declude.Virus] HiJack Question

2005-02-06 Thread Marc
Scenario: Dialup ISP using dynamic IP allocation. Customer #1 using IP address of 1.2.3.4 trips threshold #2. Logs off. Customer #2 logs on and obtains the same IP that customer #1 had (1.2.3.4)   My understanding is that HiJack will block Customer #2's outbound email as well. At least until

[Declude.Virus] Hijack Question

2006-10-31 Thread Mario Antonio
Does anyone know if you have to restart the declude process after you have moved back files from the HOLD2 folder into the spool ---Declude 3.0.5/Imail 8.22? In the Declude 2.X you had to close the foreground screen/console (which restarts Hijack) in order to clean all the IP addresses that have

RE: [Declude.Virus] HiJack Question

2005-02-07 Thread John Tolmachoff \(Lists\)
move them.   John Tolmachoff Engineer/Consultant/Owner eServices For You   -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Marc Sent: Sunday, February 06, 2005 11:12 PM To: declude.virus@declude.com Subject: [Declude.Virus] HiJack Question

Re: [Declude.Virus] HiJack Question

2005-02-07 Thread Marc
thes." -- Henry J. Kaiser - Original Message - From: John Tolmachoff (Lists) To: Declude.Virus@declude.com Sent: Monday, February 07, 2005 2:53 AM Subject: RE: [Declude.Virus] HiJack Question First, you should be actively monitoring the HOLD2 directory.

RE: [Declude.Virus] Hijack Question

2006-10-31 Thread David Barker
Stop/Start the decludeproc will reset the hijack counter. David B www.declude.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mario Antonio Sent: Tuesday, October 31, 2006 9:42 AM To: declude.virus@declude.com Subject: [Declude.Virus] Hijack Question

Re: [Declude.Virus] Hijack Question

2006-10-31 Thread Mike N
- From: "Mario Antonio" <[EMAIL PROTECTED]> To: Sent: Tuesday, October 31, 2006 9:42 AM Subject: [Declude.Virus] Hijack Question Does anyone know if you have to restart the declude process after you have moved back files from the HOLD2 folder into the spool ---Declude 3.0.5/Ima

Re: [Declude.Virus] Hijack Question

2006-10-31 Thread Mario Antonio
Mike, Thanks a lot for your prompt response. Regards Mario Antonio - Original Message - From: "Mike N" <[EMAIL PROTECTED]> To: Sent: Tuesday, October 31, 2006 10:16 AM Subject: Re: [Declude.Virus] Hijack Question > For 4.x, you have to either restart the dec

Re: [Declude.Virus] Hijack Question

2006-10-31 Thread Mario Antonio
D]> To: Sent: Tuesday, October 31, 2006 10:18 AM Subject: RE: [Declude.Virus] Hijack Question > Stop/Start the decludeproc will reset the hijack counter. > > David B > www.declude.com > > -Original Message- > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Beha

RE: [Declude.Virus] Hijack Question

2006-10-31 Thread David Barker
, October 31, 2006 11:50 AM To: declude.virus@declude.com Subject: Re: [Declude.Virus] Hijack Question David, One more question, I am seeing that some Q files remain in the spool\proc\work folder, is this normal? why? Should I clean them manually? Where are the corresponding D files? Regards Mario

Re: [Declude.Virus] Hijack Question

2006-10-31 Thread Mario Antonio
- Original Message - From: "David Barker" <[EMAIL PROTECTED]> To: Sent: Tuesday, October 31, 2006 1:58 PM Subject: RE: [Declude.Virus] Hijack Question > There should not be orphan files I would think you are running some type of > virus scanner that is removing the D*.sm

RE: [Declude.Virus] Hijack Question

2006-10-31 Thread David Barker
Subject: Re: [Declude.Virus] Hijack Question David, I am running f-prot 3.16f Take a look at my configs SCANFILE C:\f-prot_windows\fpcmd.exe /TYPE /SILENT /NOMEM /ARCHIVE=5 /PACKED /NOBOOT /DUMB /REPORT=report.txt VIRUSCODE 3 VIRUSCODE 6 VIRUSCODE 8 REPORT Infection: Any

RE: [Declude.Virus] Hijack Question

2006-10-31 Thread Kevin Bilbee
: declude.virus@declude.com > Subject: Re: [Declude.Virus] Hijack Question > > David, > > I am running f-prot 3.16f > Take a look at my configs > > SCANFILE C:\f-prot_windows\fpcmd.exe /TYPE /SILENT /NOMEM /ARCHIVE=5 > /PACKED /NOBOOT /DUMB /REPORT=report.txt >

Re: [Declude.Virus] Hijack Question

2006-10-31 Thread Scott Fisher
logs for that message for anything unusual. - Original Message - From: "David Barker" <[EMAIL PROTECTED]> To: Sent: Tuesday, October 31, 2006 1:52 PM Subject: RE: [Declude.Virus] Hijack Question 1. Make sure that the Real-Time scanner of F-prot is disabled 2. At a m

RE: [Declude.Virus] Hijack Question

2006-10-31 Thread David Barker
DEBUG logs for this would be extremely helpful David -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Scott Fisher Sent: Tuesday, October 31, 2006 3:23 PM To: declude.virus@declude.com Subject: Re: [Declude.Virus] Hijack Question -David Since it is out