PROTECTED]
To: Declude.Virus@declude.com
Sent: Monday, June 06, 2005 5:51 PM
Subject: Re: [Declude.Virus] what does this mean in the virus log file?
Vulnerability flags = 76
Thanks!
-Nick
---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL
- Original Message - From: NIck Hayer [EMAIL PROTECTED]
To: Declude.Virus@declude.com
Sent: Monday, June 06, 2005 5:51 PM
Subject: Re: [Declude.Virus] what does this mean in the virus log file?
Vulnerability flags = 76
Thanks!
-Nick
---
This E-mail came from the Declude.Virus mailing list
Vulnerability flags = 76
Thanks!
-Nick
---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.
By now most of you will have seen the recent
announcement by Ipswitch of their product repackaging. Like you, we are
disappointed by their decision to effectively impose a price increase to their base
product offerings and to burden existing and future customers who appreciate
the
Also,
ERROR: Could not open recip file F:\IMail\spool\_08dc4c3a0030129f.~MD
[2]
Please advise to what this is, thanks,
Keith
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Keith Johnson
Sent: Monday, October 25, 2004 10:24 AM
To: [EMAIL PROTECTED]
Also getting:
Q08b8153d00e2843a Couldn't rename SMD to SM$ [32]. Priority back to 32.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Keith Johnson
Sent: Monday, October 25, 2004 10:24 AM
To: [EMAIL PROTECTED]
Subject: [Declude.Virus] What are these
: [Declude.Virus] What are these
Also,
ERROR: Could not open recip file F:\IMail\spool\_08dc4c3a0030129f.~MD
[2]
Please advise to what this is, thanks,
Keith
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Keith Johnson
Sent: Monday, October 25, 2004
Q06634053002e6803 Error 183 creating temp directory
F:\IMail\spool\D06634053002e6803.vir\.
10/25/2004 10:26:26 Q06634053002e6803 Scanned: Error starting scanner
That error means that the .vir directory already exists -- this will happen
if IMail accidentally calls Declude multiple times.
PROTECTED]
Subject: RE: [Declude.Virus] What are these
Also,
ERROR: Could not open recip file F:\IMail\spool\_08dc4c3a0030129f.~MD
[2]
Please advise to what this is, thanks,
Keith
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Keith Johnson
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of R. Scott Perry
Sent: Monday, October 25, 2004 10:55 AM
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus] What are these
Q06634053002e6803 Error 183 creating temp directory
F:\IMail\spool\D06634053002e6803.vir
We are backing up in our Queue of about 8000 emails and we
started seeing the below messages as well:
Q08b8153d00e2843a Couldn't rename SMD to SM$ [32]. Priority back to 32.
ERROR: Could not open recip file F:\IMail\spool\_08dc4c3a0030129f.~MD
[2]
Are these related?
It almost certainly
Hi,
Actually why couldn't Declude run uudecode and reassemble the file before
hand, then have it scanned and determine if it is harmful or not??
Because the time between the e-mail with first part might be one second, one
day one week, etc. Declude now simply scans one e-mail, and when it's
Doug
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Bruce Loughlin
Sent: Friday, June 04, 2004 2:03 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] What is Partial Vulnerability on a PDF
Was there ever a way to put these emails back together?
I had
PROTECTED]
Subject: RE: [Declude.Virus] What is Partial Vulnerability on a PDF
Uuencode/Uudecode is what we used to use before the high speed world became
a reality.
You would type Uudecode and the file name and path. If I remember as long
as all the parts where in the same directory it would
03, 2004 4:26 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] What is Partial Vulnerability on a PDF
Yes I looked again and you are right. So Declude would have to keep
track of e-mail to e-mail and possible out of sequence and different
clients marking the split stuff in different ways
Declude Virus and F-Prot reported
X-Declude-Virus: Detected [Partial Vulnerability].
This is an e-mail that has been cut into 5 part and it has a PDF
attached to it.
That's the vulnerability -- a single attachment that has been split into
multiple E-mails. This was cool in the early 90's to
-Original Message-
From: [EMAIL PROTECTED] [mailto:Declude.Virus-
[EMAIL PROTECTED] On Behalf Of Matt
Sent: Thursday, June 03, 2004 3:28 PM
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus] What is Partial Vulnerability on a PDF
Goran,
Outlook/Outlook Express allows a sender to split
Of Goran Jovanovic
Sent: Thursday, June 03, 2004 12:37 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] What is Partial Vulnerability on a PDF
I guess it would be nice to say
BANPARTIAL EXE
BANPARTIAL COM
BANPARTIAL VBS
Etc
I don't think a PDF can be infected but then again
-Original Message-
From: [EMAIL PROTECTED] [mailto:Declude.Virus-
[EMAIL PROTECTED] On Behalf Of John Tolmachoff (Lists)
Sent: Thursday, June 03, 2004 4:05 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] What is Partial Vulnerability on a PDF
I think the problem is, that while
Another way to defend against these is with your desktop AV program.
McAfee Enterprise 7.x has some check boxes to turn on testing for these
pests.
(Because they're not exactly a virus, McAfee makes you turn on the
extra checking)
Some corporate tools, like remote control or intrusion
- Hostmaster
Sent: Friday, April 30, 2004 5:43 AM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] What is it?
I've had to fix two computers over the last two weeks because of
adware/spyware. Just logging into the computer and letting it sit would
make pop-ups all over the place. Sometimes
Try restarting the machine in Safe Mode and then deleting it. You can
also try to rename it and then reboot to see if you can break the
startup of it.
Goran Jovanovic
The LAN Shoppe
-Original Message-
From: [EMAIL PROTECTED] [mailto:Declude.Virus-
[EMAIL PROTECTED] On
: RE: [Declude.Virus] What is it?
Try restarting the machine in Safe Mode and then deleting it. You can
also try to rename it and then reboot to see if you can break the
startup of it.
Goran Jovanovic
The LAN Shoppe
-Original Message-
From: [EMAIL PROTECTED
I've been successful on similar junk by unchecking the pest's startup
commands in MSConfig.
(Also a good research tool)
Spybot Search and Destroy has an innoculate function.
At a quick glance they add 00's of entries into the HOSTS file. The idea
is that www.WorthlessTrash.com will resolve to
I am not sure about F-prot, but Mcafee updated their definition files last
night to catch this.
Mcafee calls it Proxy-Cidra
http://us.mcafee.com/virusInfo/default.asp?id=descriptionvirus_k=100939
Don
- Original Message -
From: Bennie [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent:
I've found several messages in my Declude Virus Log referring to Found
Potential dangerous stuff, yet no action is taken on these. I cannot find
these items in the spool\virus folder either.
Can somebody explain this for me?
Since you are using LOGLEVEL HIGH and PRESCAN ON, Declude Virus Pro
Read the manual at www.declude.com\virus\manual.htm.
Did you notice the [1/3] after the file
name?
That means the sender has his e-mail
client set to take on message and break it up into smaller ones. Very bad. Lets
viruses hide there.
John Tolmachoff
Engineer/Consultant/Owner
Seeing the subject line snr logo SRbwlogo.tif [1/3] I am thinking he has his email program
set to break attachments into multiple parts, thus a single file would be split
over 3 messages in this case. When that happens the virus scanner can't
tell which of the parts if any could have a virus
Thanks Jim and John!
From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of John Tolmachoff (Lists)
Sent: Wednesday, October 29, 2003
4:09 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] what?
Read the manual at www.declude.com\virus\manual.htm.
Did you
I'm still using 1.66i18 since I hadn't had any problems with it and hadn't
seen any reason to upgrade it. I don't remember 1.70 coming out and why I
didn't install it. Is there a good reason why I should go to the newer
version?
I would recommend upgrading to 1.70, as interim releases often
No big deal, I don't think, but can someone tell me what this is in my
virlog file? We're set up to level MID.
11/22/2002 06:13:59 Q117616cf0124f484 Warning: EOF in middle of MIME segment
[] [---f8de0acee6fc52cf1ab9eab27]
11/22/2002 06:13:59 Q117616cf0124f484 Scanned: Virus Free [MIME: 2 3512]
Declude filtered a virus, but the customer want's to have this mail.
What should I do now?
Can I copy the file to the spool directory?
Yes, you can.
Or does Declude filters this mail again?
No.
Are you really sure you know that you want this?
Most viruses do not attach to an email with
Declude filtered a virus, but the customer want's to have this mail.
What should I do now?
Can I copy the file to the spool directory? Or does Declude filters this
mail again?
I looked at manual.htm, but there is nothing mentioned.
If you need to deliver it, you will need to copy both the
33 matches
Mail list logo