>However, when I run this under Win NT Server 4.0 (SP 6a), I get an NT GUI
>box opening up saying "the application attempted to access the disk
>hardware directly which is not supported - Terminate
>or Ignore". Choosing "ignore" allows NAVDX to proceed normally. However,
>the GUI box can't b
>What is the difference between %REMOTEHOST% vs %SENDERHOST% and between
>%RECIPHOST% vs %LOCALHOST%
%LOCALHOST% and %REMOTEHOST% are a local domain on your IMail server, and a
remote domain. These come from the To/From addresses, and could be either
from the sender or recipient. They deter
>I checked the NAVDX commandline options (NAVDX /?) and none are helpful.
You are right, it doesn't look like any of those options will solve the
problem. It may just be that Norton wouldn't allow that to be disabled, so
that you could not automate NAVDX on NT Server. The program that the
c
>So, in the case of Imail with a real mail server (MX10 name) and a virtual
>server:
>
>1) the new variables of senderhost and reciphost will reflect the real
>mail server;
> and,
>2) the existing variables of localhost and remotehost will reflect the
>virtual server.
Actually, all of the do
>1.16 - several getting stuck in memory throughout a day (KILL fixes that)
>1.16b - appears to not get hung in memory at all (24 Hours+) ...
That's not good. We had an alpha (unreleased) version (between 1.16 and
1.16b) that we were running that did that, but identified the problem and
fixed
>... on a test system I un-mimed about 150 virused
>e-mails, scanned them and discovered a pattern.
>Given the selected output below, the only reliable
>setting you should use in your config file is
>"REPORT Found" (without the quotes).
Good job! It's too bad that McAfee doesn't keep things the
> "Will now delete all .SM# files from spool directory, even if E-mail was
>not sent."
>
> Is this only after the queue max tries (~3 days)? In most cases, the
>notification is as critical as basic E-mail delivery to our customers.
No need to worry about this. The .SM# files are used only
>I would like to start using this, but I'm not sure from the docs how to set
>it up. I'm using Dr. Solomon. Can someone post a sample of the appropriate
>config files with a little documentation.
It's still undocumented, but the secret has leaked out a few times.
The first step is to get the
>Your program decodes attachment sections and gives the scanner temporary
>file names ... trade secrets out of the box eh? ...
We think of it as a feature rather than a trade secret. I do hope the
SMTP-based AV scanners know not to accept any string as a file name...
>Perhaps adding another v
>Is it me or does 1.16c seem to be nabbing e-mail that isn't virused?
>
>I'm reaching for the cheap, easy answer here ...
... and you've got one. Yes, I just confirmed last night that there is an
issue with v1.16c where it will catch some E-mail that does not have a
virus. I would recommend
>... and you've got one. Yes, I just confirmed last night that there is an
>issue with v1.16c where it will catch some E-mail that does not have a
>virus. I would recommend going back to v1.16b (
>http://www.declude.com/Release/116b/declude.exe ), which does not have
>this issue (but the %V
>I have been noticing Declude miss some SPAM that is listed on inputs.orbs,
>which we are checking. We report SPAM via SPAM COP and it also checks
>MAPS RSS and Inputs.orb, ie.
>
>show] "nslookup 112.40.165.141.inputs.orbs.org." (checking ip) ip = 127.0.0.2
>blocked by ORBS
>
>Is this an issue
>Can some one please check the attached templates for me I am STILL geting
>the Unknown Var. in the Email sent to sender and Recip, and I need to get
>this done by Monday - as its my last day on this contract.
Which variables are showing that? Which version are you running?
The "[Unknown Var]"
>Problem:
>When someone sends a message containing a virus to [EMAIL PROTECTED] Declude
>will block this message (thats not the problem :)
>But now the Alert-message to the recipient will be send to [EMAIL PROTECTED]
>and not to [EMAIL PROTECTED]
>I've current in use declude 1.14
Earlier versio
>Well, it has been several days now and
>it appears 1.16d is performing VERY well.
>I've only had two recent quarantines
>which I believe to have been a mistake
>because of their involving some strange
>uuencoded sections? (False Positives)
That is the only known issue with 1.16d. Getting
>My suggestion: Declude yust knows variables like remotehost, senderhost
>etc. Why not add the possibility to include (or exclude) specific domains
>in the config-file?
That is something that we will definitely be adding. I don't know yet
exactly how it will work, but there will be a way to
We have just released Declude v1.17 (
http://www.declude.com/virus/install.htm ). Hopefully, this will be the
last of the betas for now and will become the next public release. It
fixes the one known problem with v1.16d, where some uuencoded attachments
(ones with quoted file names) were mis
>%VERSION% is broken.
Thanks for pointing that out. A new copy has just been uploaded that
returns 1.17.
-Scott
[ This E-mail came from the Declude.Virus mailing list. To ]
[ unsubscribe, just send an E-mail to [EMAIL PROTECTED], and ]
[ t
>I'm not happy unless I'm tinkering with something, is there any way I could
>get a list of all the config settings for v1.17?
You should find them all either at http://www.declude.com/virus/install.htm
, or http://www.declude.com/relnotes.htm (which has a few extra options not
yet listed in t
>My Declude (1.20) handled two messages distributed by the IPSWITCH list
>server to me, which were virused, by sending the Imail_Forum two messages
>which *I* should have received? The wording of those messages are
>what the intended recipient of virused mail, myself, should be getting ..
>Does the file HAVE to exist? Or can I turn off the "E-Mail the Postmaster"
>feature by just removing the file? It's a simple thing to test but I don't
>wanna try it out and have declude/imail blow up on me :)
That file doesn't need to exist; you can safely remove it. Declude will
look for a
>I've had a few complaints from other systems' postmasters that have people
>frequently send viri using their domain (ie sexyfun.net) and these
>postmasters ask to not receive the viri notification e-mails because they
>get 30 - 40 a day. Perhaps there should be a way to exclude addresses? Just
>
>What do these log messages mean (in virus logs) and should I do anything
>about them:
>... couldn't find console; starting (2).
>... error starting deccon.exe: 2
This is an issue with v1.19 where the error message "Error starting
deccon.exe: 2" may appear in the logs with another similar
>is v1.20 released?
Yes, it is. It fixes the two reported issues with v1.19 (the two
"deccon.exe" error messages appearing in the logs, and an issue with a new
Declude JunkMail feature).
-Scott
This E-mail came from the Declude.Virus mailing list.
>These are all addresses that declude tried to send notifications to. Every
>one of these was generated by Snow White.
>
>=?ISO-8859-1?Q?=F6@[216.189.112.13]
This is going to be difficult to detect. The problem is that most of the
E-mail addresses listed are technically valid addresses. It ma
Computerized Horizons is getting ready to release a new program, Declude
Confirm, which will automatically take care of confirmations for mailing
lists. It's very easy to use (if you already have Declude installed, you
just need to copy in one or two files, and you're done; that's it!). To
s
>How much is it Scott?
There hasn't been a final determination, so I can't comment on pricing
right now. But, I can say that there will be no charge to participate in
the beta test.
-Scott
This E-mail came from the Declude.Virus mailing
A lot of people have been asking us whether or not Declude would work with
IMail v7.0. Until now, we haven't said anything definite, as we were under
an NDA with Ipswitch.
I can now, however, say that all Declude products (Declude Virus, Declude
JunkMail, Declude Hijack and Declude Confirm) w
>Is there a way to use more than one command-line-scanners in the
>config-file?
The config file doesn't support multiple scanners, but some of our
customers have figured out a way to do it with a batch file. Instead of
pointing to the virus scanner with the SCANFILE option, you can have it
p
>What are all of these .vir folders for? I've got 3,000 of them in the
>Imail\spool folder.
Those are the folders that Declude uses temporarily to scan attachments.
Have you tested Declude Virus with the eicar.com file to make sure that it
is set up properly and detecting viruses? You can se
>You're correct, something is not setup correctly! I'm getting an "Error 2
>starting scanner". Do you know what this message is referring to?
That means that your virus scanner isn't where it should be.
The \IMail\Declude\virus.cfg file has a SCANFILE line in it that should
point to where th
>When I run the scan.exe from a DOS prompt over the Imail\Spool folder, I get
>a "could not be opened - permission denied" message. Do I have to grant
>some autority to the spool folder?
You shouldn't normally need to grant any special permissions (unless you
had previously set permissions on
>Is it possible to exclude emails from a specific account from being scanned
>as junk mail.
To do that, you can add a line "WHITELIST FROM [EMAIL PROTECTED]" to
\IMail\Declude\global.cfg (putting in the address you want to always
receive mail from). That will force the E-mail to pass all spam
>if one of my customers has an email contaning virus and he still want it how
>can i find this message in virus directory... so htat i dont have o get all
>back in the spool directory again
One way is to search the Declude or IMail logs to find the spool file name
(Q1234567.SMD and D1234567.SMD
>Have been out of town lately. What is the latest version of declude virus?
>Also,
>where is the download site?
The latest version is 1.20 (there's a beta version 1.23, with 1.24 on the
way soon). You can always find the latest version at
http://www.declude.com/virus/manual.htm .
>Next Question? I am using F-Prot. How do I get the virus name to show up? I am
>using the following switch line. I have it below.
>
>C:\f_prot\f-prot.exe /NOBO /NOME /AR /DU /P /C /AU /DEL
>/AP /REPORT=report.txt
Now you just need to add a line "REPORT Infection", that will let Declude
know
>I had one today sneak in..fortunately the user didn't recognize the
>sender and was smart enough to delete the email.
>
>The Declude/McAfee setup has been catching this virus left and right. I
>don't have a clue why all of a sudden it would let this one in.
Did you check the log file to see if
>With the increase in virus activity during the last week maybe we reached
>the MAXATONCE 4 and it didn't 'wait' for the 5th?
That wouldn't be it. With the MAXATONCE setting, Declude will wait for
other scanner processes to finish, and then it will scan the E-mail. You
can check to se
>Yes! I checked the log and everything seems to be working fine. The
>email came through as "virus free", however, the day before Declude
>nabbed it, and has been nabbing it.
There's a chance that McAfee may not be recognizing it in certain
forms. Virus scanners actually won't scan an entire f
>I am running Declude with Netshield v4.5. (everything is working pretty
>well too!)
>
>What I would like to do, is make use of these %virusname% and
>%virusfile% options in the alert email that I am having sent to myself
>when Declude finds a virus.
You need to add "/REPORT report.txt" to the S
>Does anyone use F-prot for workstations?
>For $2 a system I thought it might be worth looking into.
That's a good idea, especially since the minimum license is for 20
computers. So if you already license it to use with Declude Virus, you've
got 19 extra licenses you can use.
>Also if I go t
>I had the postmaster of an ISP request the headers of the virus. I
>was able to get them, but thought it might be nice if Declude could do
>it automatically.
>
>Is it possible to have Declude automatically be able to send all the
>header info?
That isn't possible currently, but I have added th
>With Declude I keep on getting mails from Postmaster saying
>
>Invalid final delivery userid: info@localhost
>
>Any explanation for this?
Have you made changes to your \IMail\Declude\*.eml files? It's possible
that if a mistake was made in one of them, E-mail could be addressed to
"info@loca
>But don't I have to do some configuration with Netshield itself
You should never need to do any configuration with NetShield itself to get
it to work with Declude -- that will change how the "on-access" scanner
works (the one that runs in the background), or the Windows-based (pop-up)
sc
>Does anyone know how to get the virus name reporting feature to work with
>Norman anti-virus?
>
>I have added the /LF:report.txt along with the 'REPORT infection' in the
>virus.cfg.
I'm guessing that the "/LF:report.txt" will save the log file correctly (to
"report.txt" in the directory that
>Please forgive me for being stupid, but in the manual on the Declude
>website, it said something about making sure that Netshield is
>creating/saving a report file in the same directory as the scanner is
>operating from? Does it do that by default?
Sorry for the confusion. The "/REPORT report.
>The messages from this mailing list include a header
>line that says:
>
> X-Note: This E-mail was scanned for viruses by Declude (www.declude.com)
>
>Is this a configurable setting on the virus.cfg file ?
>Checked on www.declude.com/virus/manual.htm but found
>no references to it.
We cheated,
>revdns is added to the subject on some folks (like mine) replies and posts -
>I assume that is a result of a test of some sort - does that mean I need to
>work on my mail servers dns?
Yes, that means that our server wasn't able to find a reverse DNS entry for
your mail server. It's rumored th
>I already had /ALL in my SCANFILE line, and I have the latest virus
>definitions updated every morning at three o'clock, so I think I was trying
>my best. And I am catching the great majority of SirCam-infected offerings,
>but I've had at least a half dozen get past. Including two more this
>mor
>Is there any easy way to tell how many messages we send/receive per day ?
You can use our "Domain Lister" program at http://www.declude.com/tools
. You can also find out the total by typing:
FIND "rdeliver" sys.txt /C
for outgoing E-mails, and
FIND "ldeliver" sys.
> > This should be fixed in the next release.
>
>Would that be 1.23 ?
Actually, it will be 1.24 (1.23 had been released previously). 1.24 should
hopefully be released by tomorrow.
-Scott
This E-mail came from the Declude.Virus mailing list. To
unsub
At 11:38 AM 8/7/01 -0500, you wrote:
>ow .. :(
>This is something you really should have listed on your pre-sales
>information pages ... I would have been very interested in knowing this
>before purchasing the product.
We are planning to update our web site to make this clearer. However, you
>I asked you this in a private message earlier, but there's no way to
>restrict F-Prot's on-access scanner to certain directories, is there? I
>haven't been able to find much information concerning those configs from
>them -- and they still haven't even sent me the registered version yet.
I d
>One simple question.
>I have just installed declude virus. If the sender is a user from my
>organization I only want to notify the sender, and not the recipient (I do
>not want that somebody out of my company knows that we have a virus), but
>when the virus is send by somebody out of my office I
>Do you think it will be possible in near future ? I think it's an important
>feature to protect the prestige of the company and not only notify to a
>customer (out going messages) that our virus protection system has detected
>the virus and not send the e-mail, but to hide that the company have
>I added the /DUMB switch to the scanfile settings and the virus is still
>going through. Any other ideas? I think it is just happening when it is a
>.doc.lnk extension.
We're able to catch Sircam with the .doc.lnk extension using F-Prot
here. Could you E-mail me your \IMail\Declude\virus.cfg
We have just released Declude Virus v1.24 (beta). It includes the
following changes:
o Previous versions could send out E-mails from Declude JunkMail or Declude
Confirm; fixed.
o %LOCALHOST% will return the master host name in remote-to-remote E-mails
o You can now ban certain file extensions
>Does anything happen to these BANNED files? And are any alerts to anyone
>made?
With v1.24, no notifications are made; the files are just quarantined. We
are considering whether or not to add support for E-mail notifications for
the banned files.
>oh, man - what is the cost going to be for the pro version...by domain - I
>was really waiting for that one???
I should have more information later tonight or tomorrow, but I'm guessing
nobody will be too disappointed.
-Scott
This E-mail came fr
>Hopefully it is a corrupted non voltile strain??? Don't want my 20 bucks for
>20 users to go to waste :)
I just had it tested in our virus lab, and when we try to run it (on NT) a
pop-up windows appears that says that it is not a valid Windows NT
application. Nor did it change the registry e
>We have installed and are using Declude with F-Prot and we are very happy
>with the results. However, it raises an interesting policy issue. Because
>by definition, a virus scanner's ability to detect a new virus will lag
>behind the introduction of a virus, there will still be a chance that a
>Is this at new version of SirCam
>
>came with this subject: homepage
>
>and this text Hi!
>
>You've got to see this page! It's really cool ;O)
>
>and an attachnebt called homepage.htm.zlv with an icon showing a letter and
>a lock on top of it ???
That sounds like the "HomePage" virus. If you g
>Has this been announced yet? Didn't see it on the site.
We made the decision to make it a free upgrade for existing users, as a way
of saying "Thanks" to our customers.
>Are the per domian/user settings the only addition, or are more planned?
Right now, it's just the per-domain and per-user
>We just had another issue, where a different magistr virus got through
>F-Prot, and hit a machine with NAV. In this case, NAV picked it up
>(different virus). It's a little disappointing the F-Prot isn't catching
>them, and that they hadn't gotten back to me on the original one I sent them.
>Free upgrade to the Pro version of Declude Virus?
>Where do I find the Pro version online?
>Do I continue using my original eight-character code,
>or do I need a new code for the Pro version?
We made this one pretty easy for you; you don't need to download anything
or change activation codes.
>How did you get all that info in the email from Declude? Mine only states
>the following:
>
>Declude Virus caught a virus with the subject "Snowhite and the Seven
>Dwarfs - The REAL story!"
>from <> to: [EMAIL PROTECTED]
>
>The spool file name is Daf9d0f8.SMD.
The E-mail template files are fu
>I get that. But why did Imail drop the email into [EMAIL PROTECTED] account
>which is the only domain on the server? Why did it not send it off to the
>correct place?
The %LOCALHOST% variable will return the domain of the local user (the one
on your domain). If the person is relaying their ma
>I understand this Scott. It worked correctly and addressed the email to
>[EMAIL PROTECTED] So why did it drop it into the [EMAIL PROTECTED] mailbox
>instead of sending it out to THEIR server?
That sounds like a problem with the IMail "imail1.exe" program. It's
pretty strange, and requires tha
>Can someone post a working recip.eml that uses the ONLYSENDIFREMOTESENDER
>option?
>
>I can't seem to get it working as expected. The recip.eml always goes out.
You just add "ONLYSENDIFREMOTESENDER" on a line by itself to the recip.eml
file (preferably the first line).
>Also, what is determi
>Just wondering, is there a way to have imail rules inacted before Declude
>does?
>
>The reason I ask is it would be nice to have the H a h a h a S e x y Fun
>virus not have e-mails sent to the sender or recipient, and just be
>trashed.
I can't think of any way of doing that. IMail's rules run
>so what about a change to declude so that certain viruses (or subjects,
>whatever) would get passed through to rules?
The problem is that in order to do that, Declude would need to have the
rules itself (in order to know what to pass to IMail's rules, it would have
to have the full functiona
>Can you take a look at the attached files? The zip contains the queue files
>of the test message, my recip.eml, debug log output for the message, and the
>generated recipient notification.
The problem is that you are running an older version of Declude (1.14
through 1.16). If you upgrade to
>I have been unsuccessful at locating a list of the variables for customizing
>the email template for Delude's warning email. Can anyone point me in the
>right direction? Thanks in advance.
http://www.declude.com/virus/manual.htm , look at the "E-mail
notifications" section.
>08/22/2001 15:50:18 ERROR: SCANFILE option must not have any spaces in the
>pathname
>
>My SCANFILE line is:
>SCANFILEd:\imail\declude\FullScan.Bat
>
>Everything works. It is still calling the scanner successfully.
We added that test to help people who are initially installing Declude
Virus.
>I get a console screen of the virus scanning popping up whenever I am logged
>into the server.
Are you using "LOGLEVEL DEBUG" in the virus.cfg file? That would cause this.
>I added CONSOLE OFF to the virus .cfg and get "08/22/2001 16:37:39 Console
>turned OFF" in the log file.
That's differ
> I saved an email message infected with Sircam virus as a .eml file, and
tried to scan it with different AV programs.
> of all what I used (Fprot, Mcafee, Sophos, Norton), only norton detected
the virus.
That's because the .eml file you saved isn't a virus, it's an E-mail. An
E-mail can co
>It's funny you should mention that, I was just looking at my /SPOOL/
>directory and my vir.log files are huge. I have LOG_OK NONE in my
>virus.cfg, and have had for ages, but I have acres of virus free lines in
>the logs nonetheless.
Are you sure it's just "LOG_OK NONE" (exactly that, with
>LOGLEVELhigh
>LOG_OK NONE
Are you getting the "Virus Free" messages in the log, or are you getting
other ones? It may be that some of the LOGLEVEL HIGH messages will get
recorded whether or not the E-mail has a virus in it.
>A half month turn-around on any virus issue, even if it's not a threat,
>seems a bit .. umm .. unreasonable?
I'm quite surprised that it would take them that long to deal with the issue.
>It's been letting more Sircom viruses through as well. I'm getting a
>little bit on the frustrated side
>I do not have /TYPE, as either /DUMB _OR_ /TYPE can be used, but supposedly
>not both together. I use /DUMB. Don't know if it really hurts to have both
>though.
Here's my understanding of these two options:
/TYPE tells F-Prot to scan all files, regardless of extension, to see if
they are po
>You're probably right, /PACKED is a wise idea. I didnt notice it wasn't
>scanning compressed files already -- thought it did by default. Thanks,
/ARCHIVE is the one needed to scan standard compressed files (such as .ZIP).
/PACKED is a very different beast. It will attempt to scan compressed
> > /PACKED is a very different beast. It will attempt to scan compressed
> > .EXE's (such as PKLite or Neolite) by actually emulating the decompression
> > code. I personally wouldn't use this on a server, just in case someone
> > figures out a way to bypass F-Prot's safety mechanisms when run
>08/30/2001 09:36:30 Q3ef614a ERROR: IMail1.exe didn't finish after 10
>minutes; terminating.
>
>I am getting a lot of that. I got 9 instances yesterday. Is this normal
That isn't normal.
Declude uses the IMail1.exe to send E-mail, usually for the E-mail
notifications. If there is somethi
>What kind of load can I expect to put on my server when using declude. I
>have a PII with 256ram running 650 email accounts and a web server.
The most important factor is the number of E-mails scanned per day. With
650 E-mail accounts, unless you do a much higher than average volume, I
don
>that is what I thought:) the pro version of the virus says it can done set
>for just certain emails. How is that accomplished. If someone does not
>want the service how do I turn it off for them or just turn it on for
>others.
The "Declude Virus Pro" section of the manual covers this. There
>I just upgraded to Imail 7.03, and all of a sudden all e-mails I receive
>begin with a part of the headers:
There is a problem with Declude JunkMail v1.25 that could cause this in
some situations; if you upgrade to 1.25a it will take care of the problem.
>I arrived at the office this morning to an array of nastygrams from my users
>that the mailserver was sluggish or nonresponsive, and discovered a single
>declude process that had been running just shy of 16 hours and was eating up
>90+% of CPU utilization and the system was locked in at 100% tot
There has started to be an increase of questions on the Declude Virus list
regarding Declude JunkMail. Just so everyone knows, I respond to those on
the Declude JunkMail mailing list (with a cc: to the original sender, in
case they aren't on the Declude JunkMail list), just so that people don'
>I got your reply on this but should it be checking outgoing mail from my
>network?
No, but it's fixed in v1.25.a. :)
-Scott
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsu
>Someone posted on Imail list that he uses fprot as first line defense and
>Netshield as second line defense.
>can declude use 2 scanners at the same time ?
>Can you have 2 scanfile commands in the config file ?
You can do this, by having Declude start a batch file instead of a scanner
(for exa
>What is the test definition for "ADULT"?
That test isn't in beta testing yet, we only have it running on our server.
-Scott
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type
>Is your comment below about Mcafee Netshield or Virusscan ?
>Or both product use the same scanner & options ?
Although the testing was done with VirusScan, we are under the impression
that all versions of VirusScan and NetShield use the same scan.exe engine.
>09/07/2001 21:32:30 Q8332268 Could not find parse string Found in report.txt
>09/07/2001 21:32:30 Q8332268 WARNING: Virus scanner reported an error #-1.
>09/07/2001 21:32:30 Q8332268 Scanned: Error in virus scanner. [MIME: 2 53679]
>Scott, wondering what the above errors represent? I use
>McAfe
>I would say we handle about 5-10,000 emails a day
>and this occurs roughly at a rate of about 10-20 times
>per hour.
That level of E-mail shouldn't cause the known McAfee problem, where it
will report an error if two copies are started too closely to one another
(if this happens, Declude will
At 12:47 PM 9/8/2001, you wrote:
>I think I will use the scanning limit of 1 and see
>if they go away... that will kinda confirm if too close
>scanning might be occurring...??
That's a good idea. If the problem continues, then that would prove that
it isn't the problem with the scanner processe
>I have a fairy stupid sounding question to ask. While diagnosing a remote
>location's e-mail troubles I had a tech from an ISP ask me if our mail
>server was "Open or Closed Relay". I didn't understand the question and
>felt quite dumb for not knowing. Do you know if I-Mail is open or closed
>I purchased Declude last night. (EAsy to steup) I coped the email
>notifications into the \imail\declude folder but do not understand what I
>need to do in order to make those work. I went ot the declude homepage
>and sent the test message to myself on a protected account and one not
>prot
>In my virus log I see this error:
>Waring: Virus Scanner reported an error #8.
F-Prot will return a #8 code if it finds a "suspicious" file. You may want
to try adding " /NOHEUR" to the SCANFILE line in \IMail\Declude\virus.cfg
to prevent F-Prot from running its heuristics test, which could
>Which runs first on the Imail machine
>when an email comes in: Declude or
>the kill.lst and rules.ima?
First (when the E-mail is being received), the kill.lst and access control
(IP list) are run.
Next, Declude is called.
Finally, during the delivery, the rules.ima is used.
>I sent a message to [EMAIL PROTECTED] about needing to know what would be
>needed to re-install in the event of a reconstruction of a server
Normally, all you need to do for a re-install is follow the same procedure
as during the original installation ( at
http://www.declude.com/virus/manual.
501 - 600 of 1618 matches
Mail list logo