Yes. We have caught quite a few since upgrading the virus defs.
_M
| -Original Message-
| From: [EMAIL PROTECTED]
| [mailto:[EMAIL PROTECTED]]On Behalf Of Michael Abbott
| Sent: Tuesday, December 04, 2001 3:40 PM
| To: [EMAIL PROTECTED]
| Subject: [Declude.Virus] Is McAfee catching w32/Go
>So if you use the banext, the mail is not delivered if the attachment
>matches the extension but there is no notification at all?
That is correct. The E-mail will be quarantined, but no virus
notifications will go out.
>example
>banext scr
>
>I get a message that has an scr attachment but n
So if you use the banext, the mail is not delivered if the attachment matches the
extension but there is no notification at all?
example
banext scr
I get a message that has an scr attachment but not a virus. The message is not
delivered and there is no notification as to the non-delivery?
If
Yes, caught one within 10 minutes of my update. You need the EXTRA.DAT
or the SUPER EXTRA.DAT (this includes an engine update). Had to hunt
for it. Go the virus alert page for Goner. It has links.
John
Michael Abbott wrote:
>
> Does anyone know if McAfee is catching the w32/Goner-A virus?
>
>Does anyone know if McAfee is catching the w32/Goner-A virus?
Yes. McAfee, F-Prot, Sophos, and others have new virus definitions that
are catching it.
-Scott
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
This E-mail c
>and will it scan first and if no virus isfound will it then ban it? thereby
>sending the notification if it is known to be infected?
That is correct -- the E-mail will still be scanned, and the notifications
will be sent out if it contains a virus.
-Sco
I've seen numerous auto-update batch files for most of the AV products,
but don't remember seeing one for McAfee. Could someone help me out
there? I know simple batch files, AT scheduler, but after looking at
the ftp.nai.com site, I'm not sure which directory and update file to
grab.
Thanks,
Does anyone know if McAfee is catching the w32/Goner-A virus?
Mike Abbott
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe D
>what version do i have to be running to use this feature?
It is in v1.24 and higher (you can type "Declude -diag" from a command
prompt to see the version number).
-Scott
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
Th
and will it scan first and if no virus isfound will it then ban it? thereby
sending the notification if it is known to be infected?
thanks again... and keep up the great work! I'd like to see
ipswitc/sysmantec respond this quickly!
Jim
- Original Message -
From: "R. Scott Perry" <[EMAI
what version do i have to be running to use this feature?
thanks,
jim
- Original Message -
From: "R. Scott Perry" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Tuesday, December 04, 2001 2:24 PM
Subject: Re: [Declude.Virus] New W32/Goner-A virus
>
> >Is there a way to kill all i
>Is there a way to kill all incoming .scr attachments? using declude or
>something else?
You can add a line "BANEXT scr" to your \IMail\Deculde\virus.cfg file,
which will ban files with .scr attachments. Note, however, that no
notifications will go out if you do this.
In your virus.cfg file in your declude folder
Works perfectly
BANEXT lnk
BANEXT vbs
BANEXT scr
BANEXT shs
BANEXT wsh
BANEXT vbx
BANEXT bat
BANEXT cab
BANEXT nws
BANEXT asp
BANEXT dll
BANEXT cmd
BANEXT xml
BANEXT sys
BANEXT asd
BANEXT chm
BANEXT ocx
BANEXT vbe
BANEXT wsf
BANEXT js
Your vir*.log f
The latest update for Fprot is catching Goner-A. I put the update in place
about an hour ago and so far have caught about 30 copies of the virus.
Jim Matuska Jr.
Nez Perce Tribe
Computer Services
[EMAIL PROTECTED]
- Original Message -
From: "Dean Zingle, Ipswitch.ca" <[EMAIL PROTECTED]>
Is there a way to kill all incoming .scr attachments? using declude or
something else? i would prefer that it happen after the virus scan... just
in case a new .scr virus comes out...
thanks,
jim
- Original Message -
From: "Jerry Murdock" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Se
I've caught about 30 with f-prot since noon-ish(EST) when the patterns were
updated.
Jerry
Subject: Hi
Incoming/Outgoing: incoming
Number Recepients: 1
Message ID: <001401c17cf8$2ce20c70$6664a8c0@XX>
Date: 12/04/2001
Time: 14:17:52
QueueFile Name: D215d228.SMD
Infected File: gone.scr
Virus N
The report should list these dates:
SIGN.DEF created 4. December 2001
SIGN2.DEF created 4. December 2001
MACRO.DEF created 30. November 2001
- Original Message -
From: "Grant Griffith" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Tuesday, December 04, 2001 2:40 PM
Subject: RE: [Dec
I removed the EXTRA.DAT for copyright reasons - and it's available online
for download. But you may find the document helpful.
-Original Message-
From: Virus Research [mailto:[EMAIL PROTECTED]]
Network Associates
McAfee AVERT, UK
A Division of Network Associates
UK, Aylesbury
Customer re
http://www.mcafee.com/anti-virus/viruses/goner/default.asp?cid=2636
scroll down and follow the link to download the EXTRA.DAT.
That's how McAfee handled last-minute updates.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Paul Ingram
Sent: Tuesday, Dece
OK, got the updates there. Have to start checking ftp2.complex.is instead.
Sincerely,
Grant Griffith, Vice President
EI8HT LEGS Web Management Co., Inc.
http://www.getafreewebsite.com
877-483-3393
||-Original Message-
||From: [EMAIL PROTECTED]
||[mailto:[EMAIL PROTECTED]]On Behalf Of Bi
Cool thanks
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Andy Schmidt
Sent: Tuesday, December 04, 2001 3:02 PM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] New W32/Goner-A virus
Nope - has nothing to do with boot disks. EXTRA.DATs contain prote
You are right about F-Prot!!:) I just download and tried it again it it is
now catching it. But as of 45min ago the defs on frisk.is where not
cathching at least it didn't work here but all is rosey now:)
Thanks, Paul
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]O
Nope - has nothing to do with boot disks. EXTRA.DATs contain protection
against a particular new virus strain before the regular scheduled .DAT file
update becomes available.
It's been this way for the longest time and works with all current VirusScan
family products.
Best Regards
Andy Schmidt
Would it not just be easier to BANEXT scr in your virus.cfg file?
Chris
At 02:48 PM 12/4/01 -0500, you wrote:
>No F-Prot is not chaching it ..I have caught 68 since 2:15pm when a user
>called me to ask could the install this screen saver. I am caching by
>filtering the subject line and body text
Just updated McAfee on our mail server (with declude).
It caught 2 inbound within 30 seconds.
_M
| -Original Message-
| From: [EMAIL PROTECTED]
| [mailto:[EMAIL PROTECTED]]On Behalf Of R. Scott Perry
| Sent: Tuesday, December 04, 2001 2:55 PM
| To: [EMAIL PROTECTED]
| Subject: RE: [Declud
My copy of f-prot is catching the gomer-a. However, I logged into the login page at
frisk.is and got them manually...
On Tuesday, December 4, 2001 12:48 PM, Paul Ingram <[EMAIL PROTECTED]> wrote:
>No F-Prot is not chaching it ..I have caught 68 since 2:15pm when a user
>called me to ask could t
I got it from F-Prot site
http://www.f-prot.com/f-prot/virusinfo/goner.html
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Bill Beach
Sent: martedì 4 dicembre 2001 20.51
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] New W32/Goner-A virus
I just go
Within the last hour there has been an update from F-Prot for sign.def and
sign2.def. I do not know what has been added but the update is available.
Dean Zingle
Optrics Inc.
- Original Message -
From: "Grant Griffith" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Tuesday, December 0
Trend Micro had an update out at 11:30am cst. Been catching them since.
Had a few come through in the open window before they released dat earlier.
Ken
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Paul Ingram
Sent: Tuesday, December 04, 2001 1:49 PM
>I just downloaded the files from F-Prot and they are what we already had.
>F-Prot must either already catch it or has not updated the info yet.
You can verify it by going to a command prompt, going to the directory
F-Prot is in, and typing:
F-Prot /virlist | find "goner" /i
This sho
30 matches
Mail list logo