RE: [Declude.Virus] Virus counts?

2004-04-27 Thread Rasmus Aaen
Anyone have counts for ClamAV when used with other scanners? Stats for yesterday: Scanner stats: F-Prot: 241 vira detected AVG : 236 vira detected ClamAV: 241 vira detected Virus stats: 134 W32/[EMAIL PROTECTED] 47 W32/[EMAIL PROTECTED] 25 W32/[EMAIL PROTECTED] 12

RE: [Declude.Virus] .CPL file blocked

2004-04-27 Thread John Tolmachoff \(Lists\)
Title: Message Here is my published policy, just revised yesterday: http://www.eservicesforyou.com/documents/emailattachments.pdf John Tolmachoff Engineer/Consultant/Owner eServices For You -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On

Re: [Declude.Virus] Virus counts?

2004-04-27 Thread Greg Little
Hopefully Greg H will answer your question for "counts" but, if you want to do it for notification e-mails. (using a % variable) You can set a rule in your e-mail to route ones with this phrase to a place where you will "see" them. We've had very few of these, but in this case one of the

[Declude.Virus] Banned Files

2004-04-27 Thread John Olden
Is there a variable that I can use in my BANnotify.eml that will report the name of the file that was banned? I'm looking form something more than the standard %BANEXT% I tried %VIRUSFILE% but that returns Unknown File Thanks, John Olden - Systems Administrator Champaign Park District --- [This

Re: [Declude.Virus] Banned Files

2004-04-27 Thread R. Scott Perry
Is there a variable that I can use in my BANnotify.eml that will report the name of the file that was banned? I'm looking form something more than the standard %BANEXT% No, that is not currently possible. Declude Virus only knows the extension, which is why it is not possible to use a variable

Re: [Declude.Virus] Virus counts?

2004-04-27 Thread Bob McGregor
thanks greg, if you are using unxutils, would you mind sharing how you put the incoming/outgoing together? We have very few infections (so far) from within our school distrcit but when they do occur, it would be nice to know it I t's a great add! bob On Tuesday, April 27, 2004 12:23 PM,

RE: [Declude.Virus] Virus counts?

2004-04-27 Thread Fritz Squib
Bob, See http://www.csonline.net/imailstuff/viruslog.htm It's a pre-packaged executable, NOT unxutils. Fritz Frederick P. Squib, Jr. Network Operations/Mail Administrator Citizens Telephone Company of Kecksburg http://www.wpa.net () ascii ribbon campaign - against html mail /\

[Declude.Virus] Copyall_account

2004-04-27 Thread Jay Calvert
Hi all, We use the copyall feature of email to keep tabs on a few users, but since we upgraded to Imail 8.1 all we see in Deccon is copyall_account in the list. We only ever see one of the sender / recipient pair now. Any clues? Thanks --- [This E-mail was scanned for viruses by Declude Virus

Re: [Declude.Virus] Copyall_account

2004-04-27 Thread R. Scott Perry
We use the copyall feature of email to keep tabs on a few users, but since we upgraded to Imail 8.1 all we see in Deccon is copyall_account in the list. We only ever see one of the sender / recipient pair now. It looks like Ipswitch made a slight change to the way that the Q*.SMD files are set

RE: [Declude.Virus] .CPL file blocked

2004-04-27 Thread Douglas Cohn
This is the most recent list I was given. (from this list). It has a few more than Johns. BANEXT ad BANEXT adp BANEXT asp BANEXT bas BANEXT bat BANEXT CEO BANEXT chm BANEXT cmd BANEXT com BANEXT cpl

Re: [Declude.Virus] Banned Files

2004-04-27 Thread Greg Little
I'll second the need and usefullness of seeing the full file name. (This becomes more complicated with files inside of zips) Whenever I get a banned e-mail, I get to decide if it is normal customer traffic (send an explaination of what extensions are blocked and how to work around the blocking)

Re: [Declude.Virus] Virus counts?

2004-04-27 Thread Greg Little
I use a much more low tech technique for this. Declude E-Mails me (and a couple of other techs) every time it finds a virus, Vulnerability or Banned Ext. . This is around a 1,000 per day lately. (Most of which are just more Netsky or Vulnerability junk to ignore) In the body of the e-mail I

RE: [Declude.Virus] Virus counts?

2004-04-27 Thread Donn Bly
Since almost all modern virus carry their own SMTP engine, almost none will be flagged as outgoing and will be caught as incoming when they try to send their payload to other users on the system. I use the SENDONLYIFIP in a series of .eml files to catch messages originating from local IP

Re: [Declude.Virus] Virus counts?

2004-04-27 Thread Bob McGregor
not sure if you can do this but I only allow smtp traffic(port 25) out of our network from our defined servers at the firewall... that way those that attempt with their own smtp engine go no where. however, we have had a couple infections that do use the known mail server. however with