[Declude.Virus] Declude v1.35 released

2002-01-29 Thread R. Scott Perry
We have just released Declude v1.35. It is a released version, and includes the following changes: Declude Virus: Extra check to make sure that only HTML files get pre-scanned, Declude JunkMail: Makes sure that "<>" can't fail the MAILFROM test, Declude JunkMail: Now lets you use variables w

Re: [Declude.Virus] Prescaning the party

2002-01-29 Thread Bennie
- Original Message - From: "R. Scott Perry" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Tuesday, January 29, 2002 4:57 PM Subject: Re: [Declude.Virus] Prescaning the party > >BTW, someone just sent me a copy, and fprot did not identify the virus > >correctly, notification said unkn

Re: [Declude.Virus] McAfee Daily DAT Command Line Scanner Update Script

2002-01-29 Thread Jerry Murdock
I'm not sure what your asking. Update instructions are clearly described in the virus listing on McAfee's site. Jerry - Original Message - From: "Steve Spear" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Tuesday, January 29, 2002 4:32 PM Subject: Re: [Declude.Virus] McAfee Daily DA

Re: [Declude.Virus] MISSING_REVERSE_DNS:McAfee not catching My*Party

2002-01-29 Thread John Carter
Well, I feel safe again. Not only did I ticker with McAfee, but have added F-Prot and am scanning with both. I'm catching the littl' buggers just about when they go dominant. Ha! Thanks for the help, guys. John P.S. I wonder if we can convince George W. that virus writers are terrorists too?

Re: DSN:Re: [Declude.Virus] Prescaning the party

2002-01-29 Thread Serge Dergham
Thank you all the new defs did the job correctly - Original Message - From: <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Tuesday, January 29, 2002 10:08 PM Subject: DSN:Re: [Declude.Virus] Prescaning the party > F-prot did not correctly identify the virus for us till we updated t

DSN:Re: [Declude.Virus] Prescaning the party

2002-01-29 Thread smb
F-prot did not correctly identify the virus for us till we updated the def's at aprox 1:30pm est time today. These appear to be diffent def's than were available in the am though the file names and sizes are the same. Stu At 09:53 PM 01/29/2002 -, you wrote: >And if I don't have a prescan l

Re: [Declude.Virus] Prescaning the party

2002-01-29 Thread Chris Hunt
F-Prot has new Def data today 1/29/02 that fix the identity issue. Chris At 09:53 PM 01/29/2002 +, you wrote: >And if I don't have a prescan line, the default is on or off ? > >BTW, someone just sent me a copy, and fprot did not identify the virus >correctly, notification said unknown virus.

Re: [Declude.Virus] Prescaning the party

2002-01-29 Thread R. Scott Perry
>And if I don't have a prescan line, the default is on or off ? The default is off. The problem can only occur if the line "PRESCAN ON" is present. >BTW, someone just sent me a copy, and fprot did not identify the virus >correctly, notification said unknown virus. That's right. You can sear

Re: [Declude.Virus] Prescaning the party

2002-01-29 Thread Serge Dergham
And if I don't have a prescan line, the default is on or off ? BTW, someone just sent me a copy, and fprot did not identify the virus correctly, notification said unknown virus. others said here they were correctly identifying the virus, what do you think the problem is over here ? Prescan defaul

Re: [Declude.Virus] McAfee Daily DAT Command Line Scanner Update Script

2002-01-29 Thread Steve Spear
Then on the mcafee site there isn't a link for an update for the command line scanner for the myparty virus. If there is a link, please forward it. Thanks, STeve --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] This E-mail came from the Declude.Virus mailing

Re: [Declude.Virus] McAfee Daily DAT Command Line Scanner Update Script

2002-01-29 Thread Jerry Murdock
- Original Message - From: "Jerry Murdock" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Monday, January 28, 2002 6:53 PM Subject: [Declude.Virus] McAfee Daily DAT Command Line Scanner Update Script > As requested a few times, attached is a script to update the engine and dat> fi

Re: [Declude.Virus] New lower-bandwidth f-prot update script.

2002-01-29 Thread Jerry Murdock
- Original Message - From: "Jerry Murdock" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Wednesday, January 16, 2002 3:49 AM Subject: [Declude.Virus] New lower-bandwidth f-prot update script. > Attached is a new updfprot script using wget instead of ftp.  It does not> download

RE: [Declude.Virus] MISSING_REVERSE_DNS:McAfee not catching My*Party

2002-01-29 Thread Michael Abbott
Do you have a URL for dailyDAT files from McAfee? Mike -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Michael E. Trendel Sent: Tuesday, January 29, 2002 11:12 AM To: [EMAIL PROTECTED] Subject: RE: [Declude.Virus] MISSING_REVERSE_DNS:McAfee not catching

Re: [Declude.Virus] Prescaning the party

2002-01-29 Thread R. Scott Perry
>I don't think I ever used the prescan, but just to make sure, how do you >turn it off ? You would just change the PRESCAN ON line to PRESCAN OFF (in the virus.cfg file). >manual.html does not mention prescan Thanks for pointing that out -- we're putting a list of additions to make to the ma

Re: [Declude.Virus] Prescaning the party

2002-01-29 Thread Serge Dergham
Hi, I don't think I ever used the prescan, but just to make sure, how do you turn it off ? manual.html does not mention prescan also, I am asking for the second time, someone please send me a copy of "my party" thanks - Original Message - From: "R. Scott Perry" <[EMAIL PROTECTED]> To:

Re: [Declude.Virus] Prescaning the party

2002-01-29 Thread R. Scott Perry
> I tried turning off PRESCAN and suddenly there were >a flood of full catches (not even error code 8). FYI, we have discovered an issue where the prescanning can attempt to scan non-HTML files, which could cause this. Until we have a fix for this, it is recommended to turn prescanning off

SV: [Declude.Virus] OFFTOPIC but an imail problem

2002-01-29 Thread ISPhuset Visual Web Norge
maybe but its both on sending and receiving and thats what i dont understand > -Opprinnelig melding- > Fra: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED]]Pa vegne av R. Scott Perry > Sendt: 29. januar 2002 18:13 > Til: [EMAIL PROTECTED] > Emne: Re: [Declude.Virus] OFFTOPIC but an imail pr

RE: [Declude.Virus] Complete list of options

2002-01-29 Thread R. Scott Perry
>No, I just wondered. There was a question last week about the LOG_OK option. >I have not seen this option documented anywhere, and I was curious what >other undocumented options there were. That hasn't been documented yet, but should be within the next day or two. -Scott -

[Declude.Virus] DSN:Now catching the party!!

2002-01-29 Thread smb
I had problems yesterday in catching "my party" even with def's updated as late as 5pm est. Files were being scanned but reported as virus free. VIRUSCODE 8 was in the config file. Only thing I could do was ban the com extension. Just recently (1:20pm est) we ran the updater for F-Prot and it pic

Re: [Declude.Virus] MISSING_REVERSE_DNS:update

2002-01-29 Thread R. Scott Perry
>I'm currently running Declude virus ver 1.2. and all the configs that were >current with 1.20. Our f-prot win version is 309a. Since I got your email >regarding a new year of service/upgrade contract. I been wanting to upgrade >to the latest version (1.34 I think). Are there any config or .eml c

RE: [Declude.Virus] "My party" virus

2002-01-29 Thread Craig Gittens
Lifesaver. Thanks alot. Worked wonders. Need English lessons. Sentence Fragments. :) It did work and thanks a bundle. Craig. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Michael Abbott Sent: Tuesday, January 29, 2002 10:55 AM To: [EMAIL PROTECTED] Sub

[Declude.Virus] MISSING_REVERSE_DNS:update

2002-01-29 Thread lco
Scott, We have owned declude in conjuction with f-prot win for almost a year now. And have had virtually no problems. I'm quite happy with the product. I'm currently running Declude virus ver 1.2. and all the configs that were current with 1.20. Our f-prot win version is 309a. Since I got your e

RE: [Declude.Virus] MISSING_REVERSE_DNS:McAfee not catchingMy*Party

2002-01-29 Thread R. Scott Perry
>We are using McAfee and have had good luck using the DailyDAT files. We >manually download the zip file then extract them directly into the command >line scanner directly, never having to stop/restart the SMTP service. I find >if you then use the built-in auto up-date you will over write the dai

RE: [Declude.Virus] MISSING_REVERSE_DNS:McAfee not catching My*Party

2002-01-29 Thread Paul Ingram
Seem thing happen to me yesterday after I installed extra.dat still didn't catch a thing so I tried the install again then stopped and started all McAfee services and it worked fine. Good day, Paul -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Michael

Re: [Declude.Virus] OFFTOPIC but an imail problem

2002-01-29 Thread R. Scott Perry
>I have one client her which get a lot of mail twice and also when they >send it will deliver twice > >below are 2 headers showing 2 incoming mail, the only difference i can see >is the status U and R > >I am banging my head in the wall to find a solution without any luck. > >any good idas wher

RE: [Declude.Virus] MISSING_REVERSE_DNS:McAfee not catching My*Party

2002-01-29 Thread Michael E. Trendel
We are using McAfee and have had good luck using the DailyDAT files. We manually download the zip file then extract them directly into the command line scanner directly, never having to stop/restart the SMTP service. I find if you then use the built-in auto up-date you will over write the dailyDAT

[Declude.Virus] OFFTOPIC but an imail problem

2002-01-29 Thread Visual Web Norge
I have one client her which get a lot of mail twice and also when they send it will deliver twice below are 2 headers showing 2 incoming mail, the only difference i can see is the status U and R I am banging my head in the wall to find a solution without any luck. any good idas where how to s

[Declude.Virus] Prescaning the party

2002-01-29 Thread niceman
I had updated to F-prot January 28 definitions and did even not get any virus errorcode 8 warnings yesterday. It's possible that I got a Jan 28 update that someone else got that won't even detect the Party at all. However after updating to Jan 29 F-prot definitions, there were still no bl

RE: DSN:Re: [Declude.Virus] MY Party not caught

2002-01-29 Thread R. Scott Perry
>I know I have seen this previously posted but I cannot remember the command >line command to determine the version of Declude AV. Could someone please >post it once again? You can type "Declude -diag" from a command prompt. The top line shows the version. -Scot

Re: [Declude.Virus] MISSING_REVERSE_DNS:McAfee not catchingMy*Party

2002-01-29 Thread R. Scott Perry
>I'm running McAfee with Declude and still not catching the MyParty >virus. Have Def 4183 with the Extra.dat file as the web site says to >do. When I remove a rule on the MyParty and stop/restart SMTP, the >virus free comes through undetected. It may just be that McAfee isn't properly update

RE: [Declude.Virus] MISSING_REVERSE_DNS:McAfee not catching My*Party

2002-01-29 Thread Michael Abbott
John, I believe you need to stop and start McAfee services. I installed them yesterday morning and it is working find. Mike -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of John Carter Sent: Tuesday, January 29, 2002 10:23 AM To: Declude.Virus Subject: [

RE: DSN:Re: [Declude.Virus] MY Party not caught

2002-01-29 Thread Michael Abbott
I know I have seen this previously posted but I cannot remember the command line command to determine the version of Declude AV. Could someone please post it once again? Thanks in advance. Mike --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] This E-mail ca

RE: [Declude.Virus] "My party" virus

2002-01-29 Thread Madscientist
Our McAffe is catching them like a champ. _M | -Original Message- | From: [EMAIL PROTECTED] | [mailto:[EMAIL PROTECTED]]On Behalf Of Craig Gittens | Sent: Tuesday, January 29, 2002 8:59 AM | To: [EMAIL PROTECTED] | Subject: RE: [Declude.Virus] "My party" virus | | | My McAfee is not catch

[Declude.Virus] MISSING_REVERSE_DNS:McAfee not catching My*Party

2002-01-29 Thread John Carter
I'm running McAfee with Declude and still not catching the MyParty virus. Have Def 4183 with the Extra.dat file as the web site says to do. When I remove a rule on the MyParty and stop/restart SMTP, the virus free comes through undetected. Any ideas / have I missed something in earlier postin

Re: DSN:Re: [Declude.Virus] MY Party not caught

2002-01-29 Thread Bennie
Hello All, I signed up for this group yesterday because of the MyParty virus. My system was delivering it. I got it 4 times yesterday... Thankful my Norton on my system caught it. From reading this I noticed why it must have been sent. I have DELIVERERRORS ON. I have added the VIRUSCODE 8 w

Re: DSN:Re: [Declude.Virus] MY Party not caught

2002-01-29 Thread Mike Nice
I see a quite a few of F-prot error code 8. 1.) "Joke file" - files that corporations might want to ban because they are not productive and could be a risk - the screen flippers, rollercoaster ride, cartoons, etc. 2.) People who have had the KAK virus but not completely eliminated - it puts

RE: [Declude.Virus] "My party" virus

2002-01-29 Thread Michael Abbott
You must retrieve and install the Extra.dat file manually. The file is available at http://vil.mcafee.com/dispVirus.asp?virus_k=99332&; It will check MyParty after the extra.dat file is installed and you restart the service. Mike -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAI

Re: [Declude.Virus] MISSING_REVERSE_DNS:WARNING: YOU WERE SENTA VIRUS... rest of message?

2002-01-29 Thread R. Scott Perry
>I've had Declude Virus catch viruses and send messages to the recipient >WARNING: YOU WERE SENT A VIRUS > >However, I'm just getting that and the headers. Is there a way >to have it send along the body of the original message so they can still >get the message, without the attachment (similar t

Re: [Declude.Virus] Missing the party!!

2002-01-29 Thread R. Scott Perry
>What other kinds of files will I catch by change the error level to 8? Will >I be catching false positives and then needing to weed through them? or >should I just stay with banning the .com ext until f-prot's defs are fixed? Banning the .com extension will likely catch more false positives t