We have just released Declude v1.35. It is a released version, and
includes the following changes:
Declude Virus: Extra check to make sure that only HTML files get pre-scanned,
Declude JunkMail: Makes sure that "<>" can't fail the MAILFROM test,
Declude JunkMail: Now lets you use variables w
- Original Message -
From: "R. Scott Perry" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Tuesday, January 29, 2002 4:57 PM
Subject: Re: [Declude.Virus] Prescaning the party
> >BTW, someone just sent me a copy, and fprot did not identify the virus
> >correctly, notification said unkn
I'm not sure what your asking. Update instructions are clearly described in
the virus listing on McAfee's site.
Jerry
- Original Message -
From: "Steve Spear" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Tuesday, January 29, 2002 4:32 PM
Subject: Re: [Declude.Virus] McAfee Daily DA
Well, I feel safe again. Not only did I ticker with McAfee, but have
added F-Prot and am scanning with both. I'm catching the littl' buggers
just about when they go dominant. Ha!
Thanks for the help, guys.
John
P.S. I wonder if we can convince George W. that virus writers are
terrorists too?
Thank you all
the new defs did the job correctly
- Original Message -
From: <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Tuesday, January 29, 2002 10:08 PM
Subject: DSN:Re: [Declude.Virus] Prescaning the party
> F-prot did not correctly identify the virus for us till we updated t
F-prot did not correctly identify the virus for us till we updated the def's at
aprox 1:30pm est time today. These appear to be diffent def's than were
available in the am though the file names and sizes are the same.
Stu
At 09:53 PM 01/29/2002 -, you wrote:
>And if I don't have a prescan l
F-Prot has new Def data today 1/29/02 that fix the identity issue.
Chris
At 09:53 PM 01/29/2002 +, you wrote:
>And if I don't have a prescan line, the default is on or off ?
>
>BTW, someone just sent me a copy, and fprot did not identify the virus
>correctly, notification said unknown virus.
>And if I don't have a prescan line, the default is on or off ?
The default is off. The problem can only occur if the line "PRESCAN ON" is
present.
>BTW, someone just sent me a copy, and fprot did not identify the virus
>correctly, notification said unknown virus.
That's right. You can sear
And if I don't have a prescan line, the default is on or off ?
BTW, someone just sent me a copy, and fprot did not identify the virus
correctly, notification said unknown virus.
others said here they were correctly identifying the virus, what do you
think the problem is over here ?
Prescan defaul
Then on the mcafee site there isn't a link for an update for the command
line scanner for the myparty virus. If there is a link, please forward
it.
Thanks,
STeve
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
This E-mail came from the Declude.Virus mailing
- Original Message -
From: "Jerry Murdock" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Monday, January 28, 2002 6:53 PM
Subject: [Declude.Virus] McAfee Daily DAT Command
Line Scanner Update Script
> As requested a few times, attached is a script to update the engine
and dat> fi
- Original Message -
From: "Jerry Murdock" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Wednesday, January 16, 2002 3:49
AM
Subject: [Declude.Virus] New lower-bandwidth f-prot
update script.
> Attached is a new updfprot script using wget
instead of ftp. It does not> download
Do you have a URL for dailyDAT files from McAfee?
Mike
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Michael E. Trendel
Sent: Tuesday, January 29, 2002 11:12 AM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] MISSING_REVERSE_DNS:McAfee not catching
>I don't think I ever used the prescan, but just to make sure, how do you
>turn it off ?
You would just change the PRESCAN ON line to PRESCAN OFF (in the virus.cfg
file).
>manual.html does not mention prescan
Thanks for pointing that out -- we're putting a list of additions to make
to the ma
Hi,
I don't think I ever used the prescan, but just to make sure, how do you
turn it off ?
manual.html does not mention prescan
also, I am asking for the second time, someone please send me a copy of "my
party"
thanks
- Original Message -
From: "R. Scott Perry" <[EMAIL PROTECTED]>
To:
> I tried turning off PRESCAN and suddenly there were
>a flood of full catches (not even error code 8).
FYI, we have discovered an issue where the prescanning can attempt to scan
non-HTML files, which could cause this.
Until we have a fix for this, it is recommended to turn prescanning off
maybe but its both on sending and receiving and thats what i dont understand
> -Opprinnelig melding-
> Fra: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]]Pa vegne av R. Scott Perry
> Sendt: 29. januar 2002 18:13
> Til: [EMAIL PROTECTED]
> Emne: Re: [Declude.Virus] OFFTOPIC but an imail pr
>No, I just wondered. There was a question last week about the LOG_OK option.
>I have not seen this option documented anywhere, and I was curious what
>other undocumented options there were.
That hasn't been documented yet, but should be within the next day or two.
-Scott
-
I had problems yesterday in catching "my party" even with def's updated as
late as 5pm est. Files were being scanned but reported as virus free.
VIRUSCODE 8 was in the config file. Only thing I could do was ban the com
extension.
Just recently (1:20pm est) we ran the updater for F-Prot and it pic
>I'm currently running Declude virus ver 1.2. and all the configs that were
>current with 1.20. Our f-prot win version is 309a. Since I got your email
>regarding a new year of service/upgrade contract. I been wanting to upgrade
>to the latest version (1.34 I think). Are there any config or .eml c
Lifesaver. Thanks alot. Worked wonders. Need English lessons. Sentence
Fragments. :) It did work and thanks a bundle.
Craig.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Michael Abbott
Sent: Tuesday, January 29, 2002 10:55 AM
To: [EMAIL PROTECTED]
Sub
Scott,
We have owned declude in conjuction with f-prot win for almost a year now.
And have had virtually no problems. I'm quite happy with the product.
I'm currently running Declude virus ver 1.2. and all the configs that were
current with 1.20. Our f-prot win version is 309a. Since I got your e
>We are using McAfee and have had good luck using the DailyDAT files. We
>manually download the zip file then extract them directly into the command
>line scanner directly, never having to stop/restart the SMTP service. I find
>if you then use the built-in auto up-date you will over write the dai
Seem thing happen to me yesterday after I installed extra.dat still didn't
catch a thing so I tried the install again then stopped and started all
McAfee services and it worked fine.
Good day,
Paul
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Michael
>I have one client her which get a lot of mail twice and also when they
>send it will deliver twice
>
>below are 2 headers showing 2 incoming mail, the only difference i can see
>is the status U and R
>
>I am banging my head in the wall to find a solution without any luck.
>
>any good idas wher
We are using McAfee and have had good luck using the DailyDAT files. We
manually download the zip file then extract them directly into the command
line scanner directly, never having to stop/restart the SMTP service. I find
if you then use the built-in auto up-date you will over write the dailyDAT
I have one client her which get a lot of mail twice and also when they send it will
deliver twice
below are 2 headers showing 2 incoming mail, the only difference i can see is the
status U and R
I am banging my head in the wall to find a solution without any luck.
any good idas where how to s
I had updated to F-prot January 28 definitions and did
even not get any virus errorcode 8 warnings yesterday.
It's possible that I got a Jan 28 update that someone
else got that won't even detect the Party at all.
However after updating to Jan 29 F-prot definitions,
there were still no bl
>I know I have seen this previously posted but I cannot remember the command
>line command to determine the version of Declude AV. Could someone please
>post it once again?
You can type "Declude -diag" from a command prompt. The top line shows the
version.
-Scot
>I'm running McAfee with Declude and still not catching the MyParty
>virus. Have Def 4183 with the Extra.dat file as the web site says to
>do. When I remove a rule on the MyParty and stop/restart SMTP, the
>virus free comes through undetected.
It may just be that McAfee isn't properly update
John,
I believe you need to stop and start McAfee services. I installed them
yesterday morning and it is working find.
Mike
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of John Carter
Sent: Tuesday, January 29, 2002 10:23 AM
To: Declude.Virus
Subject: [
I know I have seen this previously posted but I cannot remember the command
line command to determine the version of Declude AV. Could someone please
post it once again?
Thanks in advance.
Mike
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
This E-mail ca
Our McAffe is catching them like a champ.
_M
| -Original Message-
| From: [EMAIL PROTECTED]
| [mailto:[EMAIL PROTECTED]]On Behalf Of Craig Gittens
| Sent: Tuesday, January 29, 2002 8:59 AM
| To: [EMAIL PROTECTED]
| Subject: RE: [Declude.Virus] "My party" virus
|
|
| My McAfee is not catch
I'm running McAfee with Declude and still not catching the MyParty
virus. Have Def 4183 with the Extra.dat file as the web site says to
do. When I remove a rule on the MyParty and stop/restart SMTP, the
virus free comes through undetected.
Any ideas / have I missed something in earlier postin
Hello All,
I signed up for this group yesterday because of the MyParty virus. My
system was delivering it. I got it 4 times yesterday... Thankful my Norton
on my system caught it. From reading this I noticed why it must have been
sent. I have DELIVERERRORS ON. I have added the VIRUSCODE 8 w
I see a quite a few of F-prot error code 8.
1.) "Joke file" - files that corporations might want to ban because they
are not productive and could be a risk - the screen flippers, rollercoaster
ride, cartoons, etc.
2.) People who have had the KAK virus but not completely eliminated - it
puts
You must retrieve and install the Extra.dat file manually. The file is
available at http://vil.mcafee.com/dispVirus.asp?virus_k=99332&;
It will check MyParty after the extra.dat file is installed and you restart
the service.
Mike
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAI
>I've had Declude Virus catch viruses and send messages to the recipient
>WARNING: YOU WERE SENT A VIRUS
>
>However, I'm just getting that and the headers. Is there a way
>to have it send along the body of the original message so they can still
>get the message, without the attachment (similar t
>What other kinds of files will I catch by change the error level to 8? Will
>I be catching false positives and then needing to weed through them? or
>should I just stay with banning the .com ext until f-prot's defs are fixed?
Banning the .com extension will likely catch more false positives t
39 matches
Mail list logo