[Declude.Virus] Skipifforging not working on Mytob

2005-04-15 Thread John Carter
Shortly after adding ClamAV to the Imail Server a few days ago, my system started sending virus notices on Mytob (and so far, only Mytob) even though I have SKIPIFFORGING in the sender.eml, recip.eml and postmaster.eml, plus I have Mytob in the list of forging viruses in the virus.cfg. In the

RE: [Declude.Virus] Skipifforging not working on Mytob

2005-04-15 Thread Shayne Embry
I have also been experiencing this, for over a week. I'm only using F-Prot, but have added the appropriate lines to eml and virus.cfg files as John has. The only other difference is that I'm using SmarterMail. Shayne -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL

[Declude.Virus] BANnotify.eml

2005-04-15 Thread Robert Perez
I know this is a rookie question but anyway: Does BANnotify.eml file send the email with or without the attachment/s?

Re: [Declude.Virus] BANnotify.eml

2005-04-15 Thread Darrell \([EMAIL PROTECTED])
Without the attachments. Darrell Check out http://www.invariantsystems.com for utilities for Declude And Imail. IMail/Declude Overflow Queue Monitoring, SURBL/URI integration, MRTG Integration, and Log Parsers.

RE: [Declude.Virus] Skipifforging not working on Mytob

2005-04-15 Thread John Carter
Shayne: I haven't heard anything from anyone else. To the existing SKIPIFFORGING, I have added the following to sender, recip, and postmaster eml's. I know it is just covering up the underlying problem, but a cure is a cure. Will let you know if it helps. SKIPIFVIRUSNAMEHAS Mytob John

Re: [Declude.Virus] Skipifforging not working on Mytob

2005-04-15 Thread Scott Fisher
I also had to add the SKIPIFVIRUSNAMEHAS Mytob to my eml files. - Original Message - From: John Carter [EMAIL PROTECTED] To: Declude.Virus@declude.com Sent: Friday, April 15, 2005 2:53 PM Subject: RE: [Declude.Virus] Skipifforging not working on Mytob Shayne: I haven't heard anything

[Declude.Virus] Another new virus

2005-04-15 Thread John Tolmachoff \(Lists\)
I am getting lots of banned attachment notices and lots of bounces in the last 90 minutes. THANKFULLY, I am blocking zip files which contain executables otherwise these would have all be delivered to users. Any one have an idea of what this one is, it is kind of acting like Bagle. John T

[Declude.Virus] Attachment=[Unknown: Err] ?

2005-04-15 Thread Andy Schmidt
Hi, Any particular subject/attachment name that we can recognize it by? Also, for half a day I've seen lots of no subject and the attachmen of Unknown Err. Seems as if Declude is choking on something here: 04/15/2005 16:43:42 Q275DA0790152A6BF Warning: file#=123456 (123456.EXE ... ) 04/15/2005

RE: [Declude.Virus] Another new virus

2005-04-15 Thread John Carter
Looks like yesterday's RAR's coming in as ZIPs. And my F-Prot/ClamAV and desktop Trend Micro still don't see anything!! Deleting them nevertheless. John -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of John Tolmachoff (Lists) Sent: Friday, April 15,

Re: [Declude.Virus] Another new virus

2005-04-15 Thread Matt
You guys are all pretty funny with your "thankfully" stuff. Remember, this is all just a collection of opinions. I have no issues, and haven't for some time. Anyway, I don't bounce messages for any tagged virus so I haven't been having issues with Mytob causing backscatter since Declude

RE: [Declude.Virus] Another new virus

2005-04-15 Thread Colbeck, Andrew
I've seen one sample in the last few minutes. It arrives as jokes.zip, and www.virustotal.com describes the enclosed 123456.exe as: This is a report processed by VirusTotal on 04/16/2005 at 00:11:32 (CET) after scanning the file 123456.exe file. Antivirus Version Update Result AntiVir