DUL: Re: [Declude.Virus] RBL: Norton Antivirus (navdx) NT problemFor Declude

2001-03-14 Thread R. Scott Perry
>However, when I run this under Win NT Server 4.0 (SP 6a), I get an NT GUI >box opening up saying "the application attempted to access the disk >hardware directly which is not supported - Terminate >or Ignore". Choosing "ignore" allows NAVDX to proceed normally. However, >the GUI box can't b

DUL: Re: [Declude.Virus] v1.15 Released

2001-03-15 Thread R. Scott Perry
>What is the difference between %REMOTEHOST% vs %SENDERHOST% and between >%RECIPHOST% vs %LOCALHOST% %LOCALHOST% and %REMOTEHOST% are a local domain on your IMail server, and a remote domain. These come from the To/From addresses, and could be either from the sender or recipient. They deter

DUL: Re: [Declude.Virus] Norton Antivirus (navdx) NT problemForDeclude

2001-03-15 Thread R. Scott Perry
>I checked the NAVDX commandline options (NAVDX /?) and none are helpful. You are right, it doesn't look like any of those options will solve the problem. It may just be that Norton wouldn't allow that to be disabled, so that you could not automate NAVDX on NT Server. The program that the c

DUL: Re: Re: [Declude.Virus] v1.15 Released

2001-03-16 Thread R. Scott Perry
>So, in the case of Imail with a real mail server (MX10 name) and a virtual >server: > >1) the new variables of senderhost and reciphost will reflect the real >mail server; > and, >2) the existing variables of localhost and remotehost will reflect the >virtual server. Actually, all of the do

DUL: Re: [Declude.Virus] 1.16 and 1.16b

2001-03-21 Thread R. Scott Perry
>1.16 - several getting stuck in memory throughout a day (KILL fixes that) >1.16b - appears to not get hung in memory at all (24 Hours+) ... That's not good. We had an alpha (unreleased) version (between 1.16 and 1.16b) that we were running that did that, but identified the problem and fixed

Re: [Declude.Virus] Investigative Reporting???

2001-03-23 Thread R. Scott Perry
>... on a test system I un-mimed about 150 virused >e-mails, scanned them and discovered a pattern. >Given the selected output below, the only reliable >setting you should use in your config file is >"REPORT Found" (without the quotes). Good job! It's too bad that McAfee doesn't keep things the

Re: [Declude.Virus] Declude 1.16c

2001-03-24 Thread R. Scott Perry
> "Will now delete all .SM# files from spool directory, even if E-mail was >not sent." > > Is this only after the queue max tries (~3 days)? In most cases, the >notification is as critical as basic E-mail delivery to our customers. No need to worry about this. The .SM# files are used only

RE: [Declude.Virus] Investigative Reporting???

2001-03-24 Thread R. Scott Perry
>I would like to start using this, but I'm not sure from the docs how to set >it up. I'm using Dr. Solomon. Can someone post a sample of the appropriate >config files with a little documentation. It's still undocumented, but the secret has leaked out a few times. The first step is to get the

RE: [Declude.Virus] Investigative Reporting???

2001-03-24 Thread R. Scott Perry
>Your program decodes attachment sections and gives the scanner temporary >file names ... trade secrets out of the box eh? ... We think of it as a feature rather than a trade secret. I do hope the SMTP-based AV scanners know not to accept any string as a file name... >Perhaps adding another v

Re: [Declude.Virus] False positives?

2001-03-26 Thread R. Scott Perry
>Is it me or does 1.16c seem to be nabbing e-mail that isn't virused? > >I'm reaching for the cheap, easy answer here ... ... and you've got one. Yes, I just confirmed last night that there is an issue with v1.16c where it will catch some E-mail that does not have a virus. I would recommend

Re: [Declude.Virus] False positives?

2001-03-26 Thread R. Scott Perry
>... and you've got one. Yes, I just confirmed last night that there is an >issue with v1.16c where it will catch some E-mail that does not have a >virus. I would recommend going back to v1.16b ( >http://www.declude.com/Release/116b/declude.exe ), which does not have >this issue (but the %V

Re: [Declude.Virus] Missing Open Relays - 1.16b

2001-03-28 Thread R. Scott Perry
>I have been noticing Declude miss some SPAM that is listed on inputs.orbs, >which we are checking. We report SPAM via SPAM COP and it also checks >MAPS RSS and Inputs.orb, ie. > >show] "nslookup 112.40.165.141.inputs.orbs.org." (checking ip) ip = 127.0.0.2 >blocked by ORBS > >Is this an issue

Re: [Declude.Virus] Eml Templates

2001-03-28 Thread R. Scott Perry
>Can some one please check the attached templates for me I am STILL geting >the Unknown Var. in the Email sent to sender and Recip, and I need to get >this done by Monday - as its my last day on this contract. Which variables are showing that? Which version are you running? The "[Unknown Var]"

Re: [Declude.Virus] Alias Names

2001-03-29 Thread R. Scott Perry
>Problem: >When someone sends a message containing a virus to [EMAIL PROTECTED] Declude >will block this message (thats not the problem :) >But now the Alert-message to the recipient will be send to [EMAIL PROTECTED] >and not to [EMAIL PROTECTED] >I've current in use declude 1.14 Earlier versio

Re: [Declude.Virus] 1.16d status ...

2001-03-29 Thread R. Scott Perry
>Well, it has been several days now and >it appears 1.16d is performing VERY well. >I've only had two recent quarantines >which I believe to have been a mistake >because of their involving some strange >uuencoded sections? (False Positives) That is the only known issue with 1.16d. Getting

RE: [Declude.Virus] 1.16d status ...

2001-03-30 Thread R. Scott Perry
>My suggestion: Declude yust knows variables like remotehost, senderhost >etc. Why not add the possibility to include (or exclude) specific domains >in the config-file? That is something that we will definitely be adding. I don't know yet exactly how it will work, but there will be a way to

[Declude.Virus] v1.17 Released

2001-04-04 Thread R. Scott Perry
We have just released Declude v1.17 ( http://www.declude.com/virus/install.htm ). Hopefully, this will be the last of the betas for now and will become the next public release. It fixes the one known problem with v1.16d, where some uuencoded attachments (ones with quoted file names) were mis

Re: [Declude.Virus] 1.17

2001-04-04 Thread R. Scott Perry
>%VERSION% is broken. Thanks for pointing that out. A new copy has just been uploaded that returns 1.17. -Scott [ This E-mail came from the Declude.Virus mailing list. To ] [ unsubscribe, just send an E-mail to [EMAIL PROTECTED], and ] [ t

Re: [Declude.Virus] Config options

2001-04-05 Thread R. Scott Perry
>I'm not happy unless I'm tinkering with something, is there any way I could >get a list of all the config settings for v1.17? You should find them all either at http://www.declude.com/virus/install.htm , or http://www.declude.com/relnotes.htm (which has a few extra options not yet listed in t

Re: [Declude.Virus] I'm confused???

2001-05-09 Thread R. Scott Perry
>My Declude (1.20) handled two messages distributed by the IPSWITCH list >server to me, which were virused, by sending the Imail_Forum two messages >which *I* should have received? The wording of those messages are >what the intended recipient of virused mail, myself, should be getting ..

Re: [Declude.Virus] Question about Postmaster.EML

2001-05-09 Thread R. Scott Perry
>Does the file HAVE to exist? Or can I turn off the "E-Mail the Postmaster" >feature by just removing the file? It's a simple thing to test but I don't >wanna try it out and have declude/imail blow up on me :) That file doesn't need to exist; you can safely remove it. Declude will look for a

Re: [Declude.Virus] Question about Postmaster.EML

2001-05-09 Thread R. Scott Perry
>I've had a few complaints from other systems' postmasters that have people >frequently send viri using their domain (ie sexyfun.net) and these >postmasters ask to not receive the viri notification e-mails because they >get 30 - 40 a day. Perhaps there should be a way to exclude addresses? Just >

Re: [Declude.Virus] Error?

2001-05-10 Thread R. Scott Perry
>What do these log messages mean (in virus logs) and should I do anything >about them: >... couldn't find console; starting (2). >... error starting deccon.exe: 2 This is an issue with v1.19 where the error message "Error starting deccon.exe: 2" may appear in the logs with another similar

Re: [Declude.Virus] Error?

2001-05-10 Thread R. Scott Perry
>is v1.20 released? Yes, it is. It fixes the two reported issues with v1.19 (the two "deccon.exe" error messages appearing in the logs, and an issue with a new Declude JunkMail feature). -Scott This E-mail came from the Declude.Virus mailing list.

Re: [Declude.Virus] Cleaning up email addresses beforenotifications sent

2001-05-10 Thread R. Scott Perry
>These are all addresses that declude tried to send notifications to. Every >one of these was generated by Snow White. > >=?ISO-8859-1?Q?=F6@[216.189.112.13] This is going to be difficult to detect. The problem is that most of the E-mail addresses listed are technically valid addresses. It ma

[Declude.Virus] Beta testers wanted for program to confirm mailing listsubscribes

2001-06-09 Thread R. Scott Perry
Computerized Horizons is getting ready to release a new program, Declude Confirm, which will automatically take care of confirmations for mailing lists. It's very easy to use (if you already have Declude installed, you just need to copy in one or two files, and you're done; that's it!). To s

RE: [Declude.Virus] Beta testers wanted for program to confirmmailing list subscribes

2001-06-09 Thread R. Scott Perry
>How much is it Scott? There hasn't been a final determination, so I can't comment on pricing right now. But, I can say that there will be no charge to participate in the beta test. -Scott This E-mail came from the Declude.Virus mailing

[Declude.Virus] Declude and IMail 7.0

2001-06-19 Thread R. Scott Perry
A lot of people have been asking us whether or not Declude would work with IMail v7.0. Until now, we haven't said anything definite, as we were under an NDA with Ipswitch. I can now, however, say that all Declude products (Declude Virus, Declude JunkMail, Declude Hijack and Declude Confirm) w

Re: [Declude.Virus] multiple scanners?

2001-06-28 Thread R. Scott Perry
>Is there a way to use more than one command-line-scanners in the >config-file? The config file doesn't support multiple scanners, but some of our customers have figured out a way to do it with a batch file. Instead of pointing to the virus scanner with the SCANFILE option, you can have it p

Re: [Declude.Virus] vir folders

2001-06-29 Thread R. Scott Perry
>What are all of these .vir folders for? I've got 3,000 of them in the >Imail\spool folder. Those are the folders that Declude uses temporarily to scan attachments. Have you tested Declude Virus with the eicar.com file to make sure that it is set up properly and detecting viruses? You can se

RE: [Declude.Virus] vir folders

2001-06-29 Thread R. Scott Perry
>You're correct, something is not setup correctly! I'm getting an "Error 2 >starting scanner". Do you know what this message is referring to? That means that your virus scanner isn't where it should be. The \IMail\Declude\virus.cfg file has a SCANFILE line in it that should point to where th

Re: [Declude.Virus] permission not granted

2001-06-29 Thread R. Scott Perry
>When I run the scan.exe from a DOS prompt over the Imail\Spool folder, I get >a "could not be opened - permission denied" message. Do I have to grant >some autority to the spool folder? You shouldn't normally need to grant any special permissions (unless you had previously set permissions on

Re: [Declude.Virus] exclude an account from being scanned forspam ?

2001-07-27 Thread R. Scott Perry
>Is it possible to exclude emails from a specific account from being scanned >as junk mail. To do that, you can add a line "WHITELIST FROM [EMAIL PROTECTED]" to \IMail\Declude\global.cfg (putting in the address you want to always receive mail from). That will force the E-mail to pass all spam

RE: [Declude.Virus] Feature Request in Declude

2001-07-28 Thread R. Scott Perry
>if one of my customers has an email contaning virus and he still want it how >can i find this message in virus directory... so htat i dont have o get all >back in the spool directory again One way is to search the Declude or IMail logs to find the spool file name (Q1234567.SMD and D1234567.SMD

Re: [Declude.Virus] Feature Request in Declude

2001-07-29 Thread R. Scott Perry
>Have been out of town lately. What is the latest version of declude virus? >Also, >where is the download site? The latest version is 1.20 (there's a beta version 1.23, with 1.24 on the way soon). You can always find the latest version at http://www.declude.com/virus/manual.htm .

Re: [Declude.Virus] F-Prot Reporting Virus Name

2001-07-29 Thread R. Scott Perry
>Next Question? I am using F-Prot. How do I get the virus name to show up? I am >using the following switch line. I have it below. > >C:\f_prot\f-prot.exe /NOBO /NOME /AR /DU /P /C /AU /DEL >/AP /REPORT=report.txt Now you just need to add a line "REPORT Infection", that will let Declude know

RE: [Declude.Virus] OSDUL:sir cam

2001-07-30 Thread R. Scott Perry
>I had one today sneak in..fortunately the user didn't recognize the >sender and was smart enough to delete the email. > >The Declude/McAfee setup has been catching this virus left and right. I >don't have a clue why all of a sudden it would let this one in. Did you check the log file to see if

Re: REVDNS:Re[2]: [Declude.Virus] OSDUL:sir cam

2001-07-30 Thread R. Scott Perry
>With the increase in virus activity during the last week maybe we reached >the MAXATONCE 4 and it didn't 'wait' for the 5th? That wouldn't be it. With the MAXATONCE setting, Declude will wait for other scanner processes to finish, and then it will scan the E-mail. You can check to se

RE: [Declude.Virus] OSDUL:sir cam

2001-07-30 Thread R. Scott Perry
>Yes! I checked the log and everything seems to be working fine. The >email came through as "virus free", however, the day before Declude >nabbed it, and has been nabbing it. There's a chance that McAfee may not be recognizing it in certain forms. Virus scanners actually won't scan an entire f

Re: [Declude.Virus] %virusname% and %virusfile%

2001-07-30 Thread R. Scott Perry
>I am running Declude with Netshield v4.5. (everything is working pretty >well too!) > >What I would like to do, is make use of these %virusname% and >%virusfile% options in the alert email that I am having sent to myself >when Declude finds a virus. You need to add "/REPORT report.txt" to the S

Re: [Declude.Virus] REVDNS:Has anyone used F-Prot...

2001-07-30 Thread R. Scott Perry
>Does anyone use F-prot for workstations? >For $2 a system I thought it might be worth looking into. That's a good idea, especially since the minimum license is for 20 computers. So if you already license it to use with Declude Virus, you've got 19 extra licenses you can use. >Also if I go t

Re: [Declude.Virus] Request for Headers

2001-07-30 Thread R. Scott Perry
>I had the postmaster of an ISP request the headers of the virus. I >was able to get them, but thought it might be nice if Declude could do >it automatically. > >Is it possible to have Declude automatically be able to send all the >header info? That isn't possible currently, but I have added th

Re: [Declude.Virus] Invalid final delivery

2001-07-31 Thread R. Scott Perry
>With Declude I keep on getting mails from Postmaster saying > >Invalid final delivery userid: info@localhost > >Any explanation for this? Have you made changes to your \IMail\Declude\*.eml files? It's possible that if a mistake was made in one of them, E-mail could be addressed to "info@loca

RE: [Declude.Virus] %virusname% and %virusfile%

2001-07-31 Thread R. Scott Perry
>But don't I have to do some configuration with Netshield itself You should never need to do any configuration with NetShield itself to get it to work with Declude -- that will change how the "on-access" scanner works (the one that runs in the background), or the Windows-based (pop-up) sc

Re: [Declude.Virus] Report option for Norman Anti-virus

2001-07-31 Thread R. Scott Perry
>Does anyone know how to get the virus name reporting feature to work with >Norman anti-virus? > >I have added the /LF:report.txt along with the 'REPORT infection' in the >virus.cfg. I'm guessing that the "/LF:report.txt" will save the log file correctly (to "report.txt" in the directory that

RE: [Declude.Virus] %virusname% and %virusfile%

2001-07-31 Thread R. Scott Perry
>Please forgive me for being stupid, but in the manual on the Declude >website, it said something about making sure that Netshield is >creating/saving a report file in the same directory as the scanner is >operating from? Does it do that by default? Sorry for the confusion. The "/REPORT report.

Re: [Declude.Virus] X-Note Setting

2001-07-31 Thread R. Scott Perry
>The messages from this mailing list include a header >line that says: > > X-Note: This E-mail was scanned for viruses by Declude (www.declude.com) > >Is this a configurable setting on the virus.cfg file ? >Checked on www.declude.com/virus/manual.htm but found >no references to it. We cheated,

Re: [Declude.Virus] REVDNS:OT what is that REVDNS

2001-08-06 Thread R. Scott Perry
>revdns is added to the subject on some folks (like mine) replies and posts - >I assume that is a result of a test of some sort - does that mean I need to >work on my mail servers dns? Yes, that means that our server wasn't able to find a reverse DNS entry for your mail server. It's rumored th

RE: [Declude.Virus] sir cam

2001-08-06 Thread R. Scott Perry
>I already had /ALL in my SCANFILE line, and I have the latest virus >definitions updated every morning at three o'clock, so I think I was trying >my best. And I am catching the great majority of SirCam-infected offerings, >but I've had at least a half dozen get past. Including two more this >mor

Re: [Declude.Virus] F-Prot, Declude and CPU usage...fprotupdate?

2001-08-06 Thread R. Scott Perry
>Is there any easy way to tell how many messages we send/receive per day ? You can use our "Domain Lister" program at http://www.declude.com/tools . You can also find out the total by typing: FIND "rdeliver" sys.txt /C for outgoing E-mails, and FIND "ldeliver" sys.

RE: [Declude.Virus] Invalid %LOCALHOST%

2001-08-07 Thread R. Scott Perry
> > This should be fixed in the next release. > >Would that be 1.23 ? Actually, it will be 1.24 (1.23 had been released previously). 1.24 should hopefully be released by tomorrow. -Scott This E-mail came from the Declude.Virus mailing list. To unsub

Re: ORBL:Re: [Declude.Virus] Internal email sending virus'

2001-08-07 Thread R. Scott Perry
At 11:38 AM 8/7/01 -0500, you wrote: >ow .. :( >This is something you really should have listed on your pre-sales >information pages ... I would have been very interested in knowing this >before purchasing the product. We are planning to update our web site to make this clearer. However, you

Re: [Declude.Virus] Internal email sending virus'

2001-08-07 Thread R. Scott Perry
>I asked you this in a private message earlier, but there's no way to >restrict F-Prot's on-access scanner to certain directories, is there? I >haven't been able to find much information concerning those configs from >them -- and they still haven't even sent me the registered version yet. I d

Re: REVDNS:Re: [Declude.Virus] subscribe message

2001-08-07 Thread R. Scott Perry
>One simple question. >I have just installed declude virus. If the sender is a user from my >organization I only want to notify the sender, and not the recipient (I do >not want that somebody out of my company knows that we have a virus), but >when the virus is send by somebody out of my office I

Re: REVDNS:Re: [Declude.Virus] subscribe message

2001-08-08 Thread R. Scott Perry
>Do you think it will be possible in near future ? I think it's an important >feature to protect the prestige of the company and not only notify to a >customer (out going messages) that our virus protection system has detected >the virus and not send the e-mail, but to hide that the company have

Re: [Declude.Virus] Sircam still going through...

2001-08-08 Thread R. Scott Perry
>I added the /DUMB switch to the scanfile settings and the virus is still >going through. Any other ideas? I think it is just happening when it is a >.doc.lnk extension. We're able to catch Sircam with the .doc.lnk extension using F-Prot here. Could you E-mail me your \IMail\Declude\virus.cfg

[Declude.Virus] Declude Virus v1.24 (beta)

2001-08-09 Thread R. Scott Perry
We have just released Declude Virus v1.24 (beta). It includes the following changes: o Previous versions could send out E-mails from Declude JunkMail or Declude Confirm; fixed. o %LOCALHOST% will return the master host name in remote-to-remote E-mails o You can now ban certain file extensions

Re: [Declude.Virus] Declude Virus v1.24 (beta)

2001-08-09 Thread R. Scott Perry
>Does anything happen to these BANNED files? And are any alerts to anyone >made? With v1.24, no notifications are made; the files are just quarantined. We are considering whether or not to add support for E-mail notifications for the banned files.

Re: REVDNS:RE: [Declude.Virus] Declude Virus v1.24 (beta)

2001-08-09 Thread R. Scott Perry
>oh, man - what is the cost going to be for the pro version...by domain - I >was really waiting for that one??? I should have more information later tonight or tomorrow, but I'm guessing nobody will be too disappointed. -Scott This E-mail came fr

[Declude.Virus] Virus Issue resolved

2001-08-14 Thread R. Scott Perry
>Hopefully it is a corrupted non voltile strain??? Don't want my 20 bucks for >20 users to go to waste :) I just had it tested in our virus lab, and when we try to run it (on NT) a pop-up windows appears that says that it is not a valid Windows NT application. Nor did it change the registry e

Re: [Declude.Virus] Anti Virus Policy

2001-08-15 Thread R. Scott Perry
>We have installed and are using Declude with F-Prot and we are very happy >with the results. However, it raises an interesting policy issue. Because >by definition, a virus scanner's ability to detect a new virus will lag >behind the introduction of a virus, there will still be a chance that a

Re: PIP:RE: [Declude.Virus] Anti Virus Policy

2001-08-15 Thread R. Scott Perry
>Is this at new version of SirCam > >came with this subject: homepage > >and this text Hi! > >You've got to see this page! It's really cool ;O) > >and an attachnebt called homepage.htm.zlv with an icon showing a letter and >a lock on top of it ??? That sounds like the "HomePage" virus. If you g

Re: [Declude.Virus] Pro upgrade pricing for existing users

2001-08-15 Thread R. Scott Perry
>Has this been announced yet? Didn't see it on the site. We made the decision to make it a free upgrade for existing users, as a way of saying "Thanks" to our customers. >Are the per domian/user settings the only addition, or are more planned? Right now, it's just the per-domain and per-user

Re: [Declude.Virus] Multiple Scanners

2001-08-19 Thread R. Scott Perry
>We just had another issue, where a different magistr virus got through >F-Prot, and hit a machine with NAV. In this case, NAV picked it up >(different virus). It's a little disappointing the F-Prot isn't catching >them, and that they hadn't gotten back to me on the original one I sent them.

RE: [Declude.Virus] Pro upgrade pricing for existing users

2001-08-21 Thread R. Scott Perry
>Free upgrade to the Pro version of Declude Virus? >Where do I find the Pro version online? >Do I continue using my original eight-character code, >or do I need a new code for the Pro version? We made this one pretty easy for you; you don't need to download anything or change activation codes.

RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2001-08-21 Thread R. Scott Perry
>How did you get all that info in the email from Declude? Mine only states >the following: > >Declude Virus caught a virus with the subject "Snowhite and the Seven >Dwarfs - The REAL story!" >from <> to: [EMAIL PROTECTED] > >The spool file name is Daf9d0f8.SMD. The E-mail template files are fu

RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2001-08-21 Thread R. Scott Perry
>I get that. But why did Imail drop the email into [EMAIL PROTECTED] account >which is the only domain on the server? Why did it not send it off to the >correct place? The %LOCALHOST% variable will return the domain of the local user (the one on your domain). If the person is relaying their ma

RE: [Declude.Virus] FW: WARNING: YOU MAY HAVE A VIRUS

2001-08-21 Thread R. Scott Perry
>I understand this Scott. It worked correctly and addressed the email to >[EMAIL PROTECTED] So why did it drop it into the [EMAIL PROTECTED] mailbox >instead of sending it out to THEIR server? That sounds like a problem with the IMail "imail1.exe" program. It's pretty strange, and requires tha

Re: [Declude.Virus] Problems with new ONLYSENDIFREMOTESENDERdirectives?

2001-08-22 Thread R. Scott Perry
>Can someone post a working recip.eml that uses the ONLYSENDIFREMOTESENDER >option? > >I can't seem to get it working as expected. The recip.eml always goes out. You just add "ONLYSENDIFREMOTESENDER" on a line by itself to the recip.eml file (preferably the first line). >Also, what is determi

Re: [Declude.Virus] using rules vs Declude

2001-08-22 Thread R. Scott Perry
>Just wondering, is there a way to have imail rules inacted before Declude >does? > >The reason I ask is it would be nice to have the H a h a h a S e x y Fun >virus not have e-mails sent to the sender or recipient, and just be >trashed. I can't think of any way of doing that. IMail's rules run

Re: [Declude.Virus] using rules vs Declude

2001-08-22 Thread R. Scott Perry
>so what about a change to declude so that certain viruses (or subjects, >whatever) would get passed through to rules? The problem is that in order to do that, Declude would need to have the rules itself (in order to know what to pass to IMail's rules, it would have to have the full functiona

Re: [Declude.Virus] Problems with new ONLYSENDIFREMOTESENDERdirectives?

2001-08-22 Thread R. Scott Perry
>Can you take a look at the attached files? The zip contains the queue files >of the test message, my recip.eml, debug log output for the message, and the >generated recipient notification. The problem is that you are running an older version of Declude (1.14 through 1.16). If you upgrade to

Re: [Declude.Virus] Variables for email templates

2001-08-22 Thread R. Scott Perry
>I have been unsuccessful at locating a list of the variables for customizing >the email template for Delude's warning email. Can anyone point me in the >right direction? Thanks in advance. http://www.declude.com/virus/manual.htm , look at the "E-mail notifications" section.

Re: [Declude.Virus] Problems with new ONLYSENDIFREMOTESENDERdirectives?

2001-08-22 Thread R. Scott Perry
>08/22/2001 15:50:18 ERROR: SCANFILE option must not have any spaces in the >pathname > >My SCANFILE line is: >SCANFILEd:\imail\declude\FullScan.Bat > >Everything works. It is still calling the scanner successfully. We added that test to help people who are initially installing Declude Virus.

Re: [Declude.Virus] Console window pops up using 1.25

2001-08-22 Thread R. Scott Perry
>I get a console screen of the virus scanning popping up whenever I am logged >into the server. Are you using "LOGLEVEL DEBUG" in the virus.cfg file? That would cause this. >I added CONSOLE OFF to the virus .cfg and get "08/22/2001 16:37:39 Console >turned OFF" in the log file. That's differ

Re: [Declude.Virus] need help selecting av product

2001-08-24 Thread R. Scott Perry
> I saved an email message infected with Sircam virus as a .eml file, and tried to scan it with different AV programs. > of all what I used (Fprot, Mcafee, Sophos, Norton), only norton detected the virus. That's because the .eml file you saved isn't a virus, it's an E-mail. An E-mail can co

RE: [Declude.Virus] Satistics

2001-08-30 Thread R. Scott Perry
>It's funny you should mention that, I was just looking at my /SPOOL/ >directory and my vir.log files are huge. I have LOG_OK NONE in my >virus.cfg, and have had for ages, but I have acres of virus free lines in >the logs nonetheless. Are you sure it's just "LOG_OK NONE" (exactly that, with

RE: [Declude.Virus] Statistics

2001-08-30 Thread R. Scott Perry
>LOGLEVELhigh >LOG_OK NONE Are you getting the "Virus Free" messages in the log, or are you getting other ones? It may be that some of the LOGLEVEL HIGH messages will get recorded whether or not the E-mail has a virus in it.

Re: [Declude.Virus] F-Prot Stuff

2001-08-30 Thread R. Scott Perry
>A half month turn-around on any virus issue, even if it's not a threat, >seems a bit .. umm .. unreasonable? I'm quite surprised that it would take them that long to deal with the issue. >It's been letting more Sircom viruses through as well. I'm getting a >little bit on the frustrated side

Re: [Declude.Virus] F-Prot Stuff

2001-08-31 Thread R. Scott Perry
>I do not have /TYPE, as either /DUMB _OR_ /TYPE can be used, but supposedly >not both together. I use /DUMB. Don't know if it really hurts to have both >though. Here's my understanding of these two options: /TYPE tells F-Prot to scan all files, regardless of extension, to see if they are po

Re: [Declude.Virus] F-Prot Stuff

2001-08-31 Thread R. Scott Perry
>You're probably right, /PACKED is a wise idea. I didnt notice it wasn't >scanning compressed files already -- thought it did by default. Thanks, /ARCHIVE is the one needed to scan standard compressed files (such as .ZIP). /PACKED is a very different beast. It will attempt to scan compressed

Re: [Declude.Virus] F-Prot Stuff

2001-08-31 Thread R. Scott Perry
> > /PACKED is a very different beast. It will attempt to scan compressed > > .EXE's (such as PKLite or Neolite) by actually emulating the decompression > > code. I personally wouldn't use this on a server, just in case someone > > figures out a way to bypass F-Prot's safety mechanisms when run

Re: [Declude.Virus] ERRORs

2001-08-31 Thread R. Scott Perry
>08/30/2001 09:36:30 Q3ef614a ERROR: IMail1.exe didn't finish after 10 >minutes; terminating. > >I am getting a lot of that. I got 9 instances yesterday. Is this normal That isn't normal. Declude uses the IMail1.exe to send E-mail, usually for the E-mail notifications. If there is somethi

Re: [Declude.Virus] ORDB:server load

2001-09-01 Thread R. Scott Perry
>What kind of load can I expect to put on my server when using declude. I >have a PII with 256ram running 650 email accounts and a web server. The most important factor is the number of E-mails scanned per day. With 650 E-mail accounts, unless you do a much higher than average volume, I don

Re: [Declude.Virus] ORDB:server load

2001-09-01 Thread R. Scott Perry
>that is what I thought:) the pro version of the virus says it can done set >for just certain emails. How is that accomplished. If someone does not >want the service how do I turn it off for them or just turn it on for >others. The "Declude Virus Pro" section of the manual covers this. There

Re: [Declude.Virus] Headers?

2001-09-06 Thread R. Scott Perry
>I just upgraded to Imail 7.03, and all of a sudden all e-mails I receive >begin with a part of the headers: There is a problem with Declude JunkMail v1.25 that could cause this in some situations; if you upgrade to 1.25a it will take care of the problem.

Re: [Declude.Virus] 1.25a issues

2001-09-06 Thread R. Scott Perry
>I arrived at the office this morning to an array of nastygrams from my users >that the mailserver was sluggish or nonresponsive, and discovered a single >declude process that had been running just shy of 16 hours and was eating up >90+% of CPU utilization and the system was locked in at 100% tot

[Declude.Virus] Declude JunkMail questions

2001-09-06 Thread R. Scott Perry
There has started to be an increase of questions on the Declude Virus list regarding Declude JunkMail. Just so everyone knows, I respond to those on the Declude JunkMail mailing list (with a cc: to the original sender, in case they aren't on the Declude JunkMail list), just so that people don'

Re: [Declude.Virus] Bug in 1.25a?

2001-09-06 Thread R. Scott Perry
>I got your reply on this but should it be checking outgoing mail from my >network? No, but it's fixed in v1.25.a. :) -Scott This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsu

Re: [Declude.Virus] 1.25a issues

2001-09-07 Thread R. Scott Perry
>Someone posted on Imail list that he uses fprot as first line defense and >Netshield as second line defense. >can declude use 2 scanners at the same time ? >Can you have 2 scanfile commands in the config file ? You can do this, by having Declude start a batch file instead of a scanner (for exa

Re: [Declude.Virus] Adult

2001-09-07 Thread R. Scott Perry
>What is the test definition for "ADULT"? That test isn't in beta testing yet, we only have it running on our server. -Scott This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type

Re: [Declude.Virus] mcafee vs fprot... re speed, cpu?

2001-09-08 Thread R. Scott Perry
>Is your comment below about Mcafee Netshield or Virusscan ? >Or both product use the same scanner & options ? Although the testing was done with VirusScan, we are under the impression that all versions of VirusScan and NetShield use the same scan.exe engine.

Re: [Declude.Virus] MISSING_REVERSE_DNS:Parse Error

2001-09-08 Thread R. Scott Perry
>09/07/2001 21:32:30 Q8332268 Could not find parse string Found in report.txt >09/07/2001 21:32:30 Q8332268 WARNING: Virus scanner reported an error #-1. >09/07/2001 21:32:30 Q8332268 Scanned: Error in virus scanner. [MIME: 2 53679] >Scott, wondering what the above errors represent? I use >McAfe

Re[2]: [Declude.Virus] MISSING_REVERSE_DNS:Parse Error

2001-09-08 Thread R. Scott Perry
>I would say we handle about 5-10,000 emails a day >and this occurs roughly at a rate of about 10-20 times >per hour. That level of E-mail shouldn't cause the known McAfee problem, where it will report an error if two copies are started too closely to one another (if this happens, Declude will

Re[3]: [Declude.Virus] MISSING_REVERSE_DNS:Parse Error

2001-09-08 Thread R. Scott Perry
At 12:47 PM 9/8/2001, you wrote: >I think I will use the scanning limit of 1 and see >if they go away... that will kinda confirm if too close >scanning might be occurring...?? That's a good idea. If the problem continues, then that would prove that it isn't the problem with the scanner processe

Re: [Declude.Virus] Closed/Open Relay

2001-09-10 Thread R. Scott Perry
>I have a fairy stupid sounding question to ask. While diagnosing a remote >location's e-mail troubles I had a tech from an ISP ask me if our mail >server was "Open or Closed Relay". I didn't understand the question and >felt quite dumb for not knowing. Do you know if I-Mail is open or closed

Re: [Declude.Virus] ORBL:email notice

2001-09-10 Thread R. Scott Perry
>I purchased Declude last night. (EAsy to steup) I coped the email >notifications into the \imail\declude folder but do not understand what I >need to do in order to make those work. I went ot the declude homepage >and sent the test message to myself on a protected account and one not >prot

Re: [Declude.Virus] Could not find parse string

2001-09-12 Thread R. Scott Perry
>In my virus log I see this error: >Waring: Virus Scanner reported an error #8. F-Prot will return a #8 code if it finds a "suspicious" file. You may want to try adding " /NOHEUR" to the SCANFILE line in \IMail\Declude\virus.cfg to prevent F-Prot from running its heuristics test, which could

Re: [Declude.Virus] Declude & Kill.lst

2001-09-12 Thread R. Scott Perry
>Which runs first on the Imail machine >when an email comes in: Declude or >the kill.lst and rules.ima? First (when the E-mail is being received), the kill.lst and access control (IP list) are run. Next, Declude is called. Finally, during the delivery, the rules.ima is used.

Re: [Declude.Virus] keys

2001-09-13 Thread R. Scott Perry
>I sent a message to [EMAIL PROTECTED] about needing to know what would be >needed to re-install in the event of a reconstruction of a server Normally, all you need to do for a re-install is follow the same procedure as during the original installation ( at http://www.declude.com/virus/manual.

<    1   2   3   4   5   6   7   8   9   10   >