Hi All... when did Frisk start with this Windows Email Server licensing
nonsense??? Did I miss something? We picked up FProt becuase we could get
away with their Corporate license for our Imail / Declude installation. Now
they want thousands yearly? What other anti-virus engines are good,
] On Behalf Of Chris
Anton
Sent: Friday, October 06, 2006 4:50 PM
To: declude.virus@declude.com
Subject: [Declude.Virus] FProt License Structure
Hi All... when did Frisk start with this Windows Email Server licensing
nonsense??? Did I miss something? We picked up FProt becuase we could get
away
installed 1.80 declude virus (restart imail smtp) and sending the infected
JPEG jpegcompoc.zip (http://www.gulftech.org/?node=downloads) it was not
automatically detect and goes trough, using F-Prot 3.15B updated.
virus.cfg:
SCANFILE C:\Progra~1\FSI\F-Prot\fpcmd.exe /TYPE /SILENT /NOMEM
Dear Marc,
where did you get the dos scanner for f-prot? On the page of F-prot there is
still only Version 3.15A available.
Bye,
Uwe
- Original Message -
From: marc [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Tuesday, September 28, 2004 1:39 PM
Subject: RE: [Declude.Virus] Fprot GDI
Could it be that the vulnerability detection doesn't work when enclosed
in a zip file? That might be too big of a leap for Declude at the
moment. I just tested the same and Declude missed it when zipped,
F-Prot gave an error 8 which is a heuristic hit, and McAfee did in fact
tag the virus
, 2004 2:09 PM
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus] Fprot GDI Scanner lines.
Could it be that the vulnerability detection doesn't work
when enclosed in a zip file? That might be too big of a leap
for Declude at the moment. I just tested the same and
Declude missed it when
Uwe is right: http://www.f-prot.com/news/gen_news/040924_release_all.html
New versions of F-Prot Antivirus for Exchange and of F-Prot Antivirus for
DOS will be released in the next few days.
3.15B just windows upgraded.
but i understand, that the new release of Declude Virus will automatically
It seems fairly certain that this virus will be released within an
encrypted zip
Maybe, maybe not. The easiest way to get a payload delivered via
e-mail right now is certainly to just pop a JPEG directly into an HTML
message and rely on unpatched Outlook to render it;
On 27 Sep 2004 at 17:31, R. Scott Perry wrote:
The latest release of Declude Virus will automatically detect the
GDIPlus.dll JPEG exploit.
How can I confirm this? When I send myself the exploit I do not
receive the email - good- but in my virus logs all I see is 'error
in scannerx' and
Yes, I doubt that in the early examples, there will be a need to do
anything but pump out automatically executing E-mails with bogus
JPG's. Over time infected JPG's might very well become a standard
method of infection in along with all of the various forms which may
include infected JPG's
, is this true?
Thanks for the aid,
Keith
-Original Message-
From: [EMAIL PROTECTED] on behalf of Nick
Sent: Tue 9/28/2004 9:40 AM
To: [EMAIL PROTECTED]
Cc:
Subject: RE: [Declude.Virus] Fprot GDI Scanner lines
As I recall, IF a virus scanner calls it bad, there is no further checking.
(So, if your AV vender is doing their job right, you would have to
disable the AV scanner(s) to test.)
Greg
Keith Johnson wrote:
I too am seeing this same behavior. I am running HIGH logging and 1.80 version. All
I
On 28 Sep 2004 at 10:43, Greg Little wrote:
Greg,
As I recall, IF a virus scanner calls it bad, there is no further
checking.
Is this for an individual scanner or multiple scanners?
All the scanners run (sic) even if the one before discovers a virus
on my system.
-Nick
.
---
[This E-mail
Good catch.
ALL AV scanners will run.
If one or serveral scanners finds a virus, then I belive the new JPEG
tests in 1.80 will be ignored.
(This would complicate confirmation testing for the new JPEG test)
Greg
Nick wrote:
On 28 Sep 2004 at 10:43, Greg Little wrote:
Greg,
As I
: Tue, 28 Sep 2004 13:18:15 -0500
From: Terry Fritts [EMAIL PROTECTED]
Organization: Smart Business Solutions, Inc.
To: Nick [EMAIL PROTECTED]
Subject:Re: [Declude.Virus] Fprot GDI Scanner lines.
Send reply to: [EMAIL PROTECTED
] On Behalf Of Bill Landry
Sent: Saturday, September 25, 2004 11:22 AM
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus] Fprot GDI Scanner lines.
- Original Message -
From: Mark Smith [EMAIL PROTECTED]
Actually
To: [EMAIL PROTECTED]
Cc:
Subject: RE: [Declude.Virus] Fprot GDI Scanner lines.
Mark,
What did you use to generate the GDI Exploit test file? Thanks
Keith
-Original Message-
From: [EMAIL
Title: RE: [Declude.Virus] Fprot GDI Scanner lines.
Same here. Is there a way to make f-prot w\Declude
catch these?
-Original Message-
From: Keith Johnson
[mailto:[EMAIL PROTECTED] On
Behalf Of Keith Johnson
Sent: Monday, September 27, 2004
12:51 PM
To: [EMAIL PROTECTED
Same here. Is there a way to make f-prot w\Declude catch these?
The latest release of Declude Virus will automatically detect the
GDIPlus.dll JPEG exploit.
-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers
] On Behalf Of R. Scott Perry
Sent: Monday, September 27, 2004 05:32 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] Fprot GDI Scanner lines.
Same here. Is there a way to make f-prot w\Declude catch these?
The latest release of Declude Virus will automatically detect the
GDIPlus.dll JPEG exploit
Which one is considered the latest.
Unless otherwise specified, latest refers to a beta or release. In this
case, it is specifically the v1.80 release.
Is that the mysterious latest interim 20 that end-users have announced on
this list?
There's nothing mysterious about interims. We do not
Just did some testing with the POC and noticed that Fprot now is adding a
new line to the report.txt:
e:\imail\test\poc.jpg Contains the exploit named W32/[EMAIL PROTECTED]
So I had to add the line:
REPORT Contains the exploit named
To my virus.cfg file.
My complete setup for F-Prot
: Saturday, September 25, 2004 2:49 AM
To: [EMAIL PROTECTED]
Subject: [Declude.Virus] Fprot GDI Scanner lines.
Just did some testing with the POC and noticed that Fprot now
is adding a new line to the report.txt:
e:\imail\test\poc.jpg Contains the exploit named W32/[EMAIL PROTECTED]
So I had
My complete setup for F-Prot is now:
SCANFILE c:\progra~1\fsi\f-prot\FPcmd.exe /TYPE /SILENT /NOMEM
/ARCHIVE=5 /NOBOOT /DUMB /SERVER /REPORT=report.txt
VIRUSCODE 3
VIRUSCODE 6
VIRUSCODE 8
REPORTInfection:
REPORTContains the exploit named
- Original Message -
From: Mark Smith [EMAIL PROTECTED]
Actually this breaks Declude because Declude Virus can't look for multiple
REPORT lines.
Scott,
How can we setup Declude Virus to look for multiple lines in the
report.txt
file?
I've been running F-Prot Version 3.15b since
How can we setup Declude Virus to look for multiple lines in the
report.txt file?
Perhaps two almost-but-not-quite-identical SCANFILE entries with
different REPORT entries...?
Yes, double the resource utilization. Only a stopgap and not tested
yet.
--Sandy
] On Behalf Of Panda Consulting S.A.
Luis Alberto Arango
Sent: Tuesday, March 16, 2004 1:46 AM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] Fprot 3.14d
I installed in the server. So far so good.. I will report again in 24 hours.
Regards
Luis Arango
-Original Message-
From: [EMAIL
- Original Message -
From: Frederick P. Squib, Jr. [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] fprot 3.12b and declude?
SCANFILE X:\Progra~1\FSI\F-Prot\fpcmd.EXE -TYPE -SILENT -NOMEM -ARCHIVE
-NOBOOT -DUMB -REPORT=report.txt
---
[This E-mail was scanned for viruses by Declude Virus
A client did get an email with the Klez virus
today.
I had them forward me the email and it Fprot missed
it again but my desktop NAV2002 stopped it.
Any suggestion on how to find out why Fprot missed
it?
H.
A client did get an email with the Klez virus today.
I had them forward me the email and it Fprot missed it again but my
desktop NAV2002 stopped it.
Any suggestion on how to find out why Fprot missed it?
The first step is to check the Declude Virus log file, to see what was
reported for the
Looks like that fixed this problem. Thanks..
Mike
-Original Message-
For Win32 FPCMD.EXE remove the -NOFLOPPY option, it isn't supported by
that version.
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
---
This E-mail came from the Declude.Virus
AM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] fprot 3.12b and declude?
For Win32 FPCMD.EXE remove the -NOFLOPPY option, it isn't supported by
that
version.
-
Franco Celli
[EMAIL PROTECTED]
---
[Quipo ISP - Questa E-mail e' stata controllata dal programma Declude
://www.wpa.net
-Original Message-From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] On
Behalf Of Scott MacLeanSent: Thursday, October 03, 2002 5:40
PMTo: [EMAIL PROTECTED]Subject: Re:
[Declude.Virus] fprot 3.12b and declude?I've
been getting a lot (2-3/day) of these pop-up boxes
07, 2002 11:20 AM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] fprot 3.12b and Declude?
I may have missed this if it was posted earlier, but the fine folks a
f-prot said...
Dear Frederick,
Please use FPCMD.EXE instead of F-Prot.EXE with the same
command line switches.
Best regards,
Arnar
: Monday, October 07, 2002 11:57 AM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] fprot 3.12b and Declude?
Along the same lines, it looks as though they've finally made the DOS
version on 3.12b available.
-Bill
---
[This E-mail was scanned for viruses by Declude Virus
(http://www.declude.com
.
Jerry
- Original Message -
From: John Tolmachoff [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Monday, October 07, 2002 2:58 PM
Subject: RE: [Declude.Virus] fprot 3.12b and Declude?
fpcmd ships with the Windows version. It's a Win32 console command line
version of F-Prot
Thanks
:
[Declude.Virus] fprot 3.12b and declude?
I
may have missed this if ti was posted earlier, but the fine folks a f-prot
said...
Dear Frederick,
Please use FPCMD.EXE instead of F-Prot.EXE with the
same
command line switches.
Best regards,
Arnar Thor
At 22:40 3.10.2002 -0400
Subject: RE: [Declude.Virus] fprot 3.12b
and declude?
I
was having this problem so I went back to 3.12a. I updated again and
changed my virus.cfg to fpcmd.exe. I ran the test EICAR_Test_File
and the log reported that is was clean and it did sent the com test file.
Changed the line
: [Declude.Virus] fprot 3.12b and declude?
The switches for the executable change from /option to -option. We
made the change and so far so good.
John Dobbin
Pen Publishing Interactive
- Original Message -
*From:* Mike Wiegers mailto:[EMAIL
: Friday, January 18, 2002 9:46 AM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] FPROT
Any ideas or thoughts?
I would recommend just running the DOS version on a server. The Windows
version isn't very server friendly (although I've never heard of it causing
a BSOD). Windows AV programs need
user version of F-Prot Antivirus for
Windows
(size: 6331904 bytes, dated: Fri Jan 18 10:44:23 2002)
Anyone knows the difference ?
- Original Message -
From: R. Scott Perry [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Thursday, January 17, 2002 8:55 PM
Subject: Re: [Declude.Virus] FPROT
- Original Message -
From: R. Scott Perry [EMAIL PROTECTED]
Sent: Thursday, January 17, 2002 3:55 PM
Subject: Re: [Declude.Virus] FPROT
What is the difference between the multi-user and the single user Fprot
for
windows ?
The last I checked, there was only one version of F-Prot
When I logged in 2 weeks ago I saw a multi and a single and wondered the
same thing.
It looks like they now have a Private Users version, that is for personal
use only (similar to the free DOS version for personal use). They require
that companies use the Commercial Users version, so you
What is the difference between the multi-user and the single user Fprot for
windows ?
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type
What is the difference between the multi-user and the single user Fprot for
windows ?
The last I checked, there was only one version of F-Prot for Windows, and
it required a minimum 20 user license (at $2/year per user).
-Scott
---
[This E-mail was scanned for viruses
AM
Subject: MISSING_REVERSE_DNS:Rif: [Declude.Virus] Fprot
Hi Serge,
we are running Fprot 3.11b without the can only run one instance...
problem...
I've installed 3.11b few days ago, downloaded file is dated 18/12/01.
Bruno
Serge Dergham [EMAIL PROTECTED] il 08/01/2002 05.33.30
Did anyone find an updated bug free 3.11b ?
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus. You can E-mail
)
Oggetto: [Declude.Virus] Fprot
, ext. 104
[EMAIL PROTECTED]
www.reliancesoft.com
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of Geoffrey Myers
Sent: Tuesday, September 25, 2001 4:49 PM
To: [EMAIL PROTECTED]
Subject: [Declude.Virus] fprot list
Does anyone know if there is an fprot list
49 matches
Mail list logo