In your virus.cfg file in your declude folder
Works perfectly

BANEXT lnk
BANEXT vbs
BANEXT scr
BANEXT shs
BANEXT wsh
BANEXT vbx
BANEXT bat
BANEXT cab
BANEXT nws
BANEXT asp
BANEXT dll
BANEXT cmd
BANEXT xml
BANEXT sys
BANEXT asd
BANEXT chm
BANEXT ocx
BANEXT vbe
BANEXT wsf
BANEXT js

Your vir*.log file will show
12/04/2001 15:17:03 Q2f3f104 Scanned: Virus Free [MIME: 3 2951]
12/04/2001 15:17:31 Q2f58104 MIME file: 3D Maze.scr [base64]
12/04/2001 15:17:32 Q2f58104 Banning file with scr extension.
12/04/2001 15:17:33 Q2f58104 Scanned: Banned file extension. [MIME: 2 478133]
12/04/2001 15:17:56 Q2f72104 Scanned: Virus Free [MIME: 1 210]
12/04/2001 15:18:02 Q2f79104 Scanned: Virus Free

Chris

At 02:17 PM 12/4/01 -0600, you wrote:
Is there  a way to kill all incoming .scr attachments?  using declude or
something else?  i would prefer that it happen after the virus scan... just
in case a new .scr virus comes out...

thanks,

jim
----- Original Message -----
From: "Jerry Murdock" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Tuesday, December 04, 2001 1:54 PM
Subject: Re: [Declude.Virus] New W32/Goner-A virus


> I've caught about 30 with f-prot since noon-ish(EST) when the patterns
were
> updated.
>
> Jerry
>
> Subject: Hi
> Incoming/Outgoing: incoming
> Number Recepients: 1
> Message ID: <001401c17cf8$2ce20c70$6664a8c0@XXXXXX>
> Date: 12/04/2001
> Time: 14:17:52
> QueueFile Name: D215d228.SMD
> Infected File: gone.scr
> Virus Name:  W32/Goner.A@mm
>
> ----- Original Message -----
> From: "Paul Ingram" <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Sent: Tuesday, December 04, 2001 2:48 PM
> Subject: RE: [Declude.Virus] New W32/Goner-A virus
>
>
> > No F-Prot is not chaching it ..I have caught 68 since 2:15pm when a user
> > called me to ask could the install this screen saver. I am caching by
> > filtering the subject line and body text. I also tried Macfee and I
didn't
> > see an update for them yet either.
> >
> > Paul
> >
> > -----Original Message-----
> > From: [EMAIL PROTECTED]
> > [mailto:[EMAIL PROTECTED]]On Behalf Of Grant Griffith
> > Sent: Tuesday, December 04, 2001 2:40 PM
> > To: [EMAIL PROTECTED]
> > Subject: RE: [Declude.Virus] New W32/Goner-A virus
> >
> > I just downloaded the files from F-Prot and they are what we already
had.
> > F-Prot must either already catch it or has not updated the info yet.
> >
> > Sincerely,
> > Grant Griffith, Vice President
> > EI8HT LEGS Web Management Co., Inc.
> > http://www.getafreewebsite.com
> > 877-483-3393
> >
> > ||-----Original Message-----
> > ||From: [EMAIL PROTECTED]
> > ||[mailto:[EMAIL PROTECTED]]On Behalf Of Andy Schmidt
> > ||Sent: Tuesday, December 04, 2001 2:39 PM
> > ||To: [EMAIL PROTECTED]
> > ||Subject: RE: [Declude.Virus] New W32/Goner-A virus
> > ||
> > ||
> > ||Yep - at least TWO client firms were infected this morning, spreading
> > ||hundreds of new infections.
> > ||
> > ||Best Regards
> > ||Andy
> > ||
> > ||
> > ||
> > ||-----Original Message-----
> > ||From: [EMAIL PROTECTED]
> > ||[mailto:[EMAIL PROTECTED]]On Behalf Of R. Scott Perry
> > ||Sent: Tuesday, December 04, 2001 02:31 PM
> > ||To: [EMAIL PROTECTED]
> > ||Subject: [Declude.Virus] New W32/Goner-A virus
> > ||
> > ||
> > ||FYI, there is a new fast-spreading virus "W32/Goner-A" with an
> > ||attachment
> > ||"Gone.SCR".  I would strongly recommend that everyone update their
virus
> > ||
> > ||definitions immediately (even if you update daily, you might not want
to
> > ||
> > ||wait for the next update).  F-Prot, McAfee, Sophos and likely others
> > ||have
> > ||new definitions out that catch this one.
> > ||                                           -Scott
> > ||
> > ||This E-mail came from the Declude.Virus mailing list.  To
> > ||unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
> > ||type "unsubscribe Declude.Virus".  You can E-mail
> > ||[EMAIL PROTECTED] for assistance.  You can visit our web
> > ||site at http://www.declude.com .
> > ||
> >
> > This E-mail came from the Declude.Virus mailing list.  To
> > unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
> > type "unsubscribe Declude.Virus".  You can E-mail
> > [EMAIL PROTECTED] for assistance.  You can visit our web
> > site at http://www.declude.com .
> >
> > This E-mail came from the Declude.Virus mailing list.  To
> > unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
> > type "unsubscribe Declude.Virus".  You can E-mail
> > [EMAIL PROTECTED] for assistance.  You can visit our web
> > site at http://www.declude.com .
>
>
> This E-mail came from the Declude.Virus mailing list.  To
> unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
> type "unsubscribe Declude.Virus".  You can E-mail
> [EMAIL PROTECTED] for assistance.  You can visit our web
> site at http://www.declude.com .
>

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .

Reply via email to