[Declude.Virus] Are you satisfied with this product?

2002-05-02 Thread Ron Covington
We as a company are looking at purchasing this product. Would like some feedback as to how solid this product is or is not. What problems you are having or not having. We are trying to determine which product is suited to our needs.   285 Users - Sm-Sized Company Windows NT Server Imail Ver

Re: [Declude.Virus] DSN:New Version of Virus Log File Analyzer

2002-05-02 Thread smb
It is in the works but I don't have a time frame. Stu At 09:28 PM 05/02/2002 -, you wrote: >an plan of adding a command line option so we can program a daily execution? >thanks for sharing > >- Original Message - >From: <[EMAIL PROTECTED]> >To: <[EMAIL PROTECTED]> >Sent: Thursday, M

Re: [Declude.Virus] DSN:New Version of Virus Log File Analyzer

2002-05-02 Thread Serge
an plan of adding a command line option so we can program a daily execution? thanks for sharing - Original Message - From: <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Thursday, May 02, 2002 9:11 PM Subject: [Declude.Virus] DSN:New Version of Virus Log File Analyzer > For those usi

[Declude.Virus] DSN:New Version of Virus Log File Analyzer

2002-05-02 Thread smb
For those using the virus log file analyzer (or those that wish to try it) a new version of the Virus Log Analyzer is a available at http://www.csonline.net/imailstuff/viruslog.htm This version has changes to the report that now indicates the number of Inbound and Outbound viruses. Virus lines t

Re: [Declude.Virus] another option needed

2002-05-02 Thread R. Scott Perry
>onlysendifvirusnamehas > >also not as important as the skip option, it can be used for >debugging/tracing. >so if it does not take much work, please put it on the wish list. It's in the suggestion database now. I can't say if/when it will get added, but it will be considered for upcoming rele

RE: [Declude.Virus] Footer

2002-05-02 Thread R. Scott Perry
>Is there a way to add the footer to only outgoing messages? >I though this might be an easy way to put a company disclaimer in every >out going email. Unless someone else has a better way. No, there isn't a way to restrict the footer only to outgoing E-mail. -Scott

RE: [Declude.Virus] Footer

2002-05-02 Thread Paul Ingram
Is there a way to add the footer to only outgoing messages? I though this might be an easy way to put a company disclaimer in every out going email. Unless someone else has a better way. ~Paul~ --- [This E-mail scanned for viruses by Declude Virus/McAfee] --- [This E-mail was scanned for vir

Re: [Declude.Virus] Klez.h

2002-05-02 Thread R. Scott Perry
>is there a variable for the following IP adress (sender) > > Yes, the %REMOTEIP% variable will display the IP address of the remote mailserver. -Scott --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] This E-mail came from the

Re: [Declude.Virus] Klez.h

2002-05-02 Thread R. Scott Perry
>So from the information below which IP address is first received header? >Received: from mailhost1.attcanada.net [206.191.82.42] by mail.scm.ca with >ESMTP > (SMTPD32-6.06) id A87C25A70096; Thu, 02 May 2002 10:25:32 -0600 >Received: from Eoqjmed ([142.154.13.134]) by mailhost1.attcanada.net

Re: [Declude.Virus] W32.Klez.gen@mm

2002-05-02 Thread R. Scott Perry
>I'm using F-Prot with declude and works fine. >Today one customer said me tha the virus Klez.gen was received on his >mailbox. >It seems that F-prot (or declude) let go this virus > >Do you think that's true ? One possibility is that the virus was received from another source (such as anot

Re: NJABL:Re: [Declude.Virus] Klez.h

2002-05-02 Thread Serge
hi, is there a variable for the following IP adress (sender) - Original Message - From: "Mike Watchman" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Thursday, May 02, 2002 4:20 PM Subject: NJABL:Re: [Declude.Virus] Klez.h > So from the information below which IP address is firs

[Declude.Virus] another option needed

2002-05-02 Thread Serge
onlysendifvirusnamehas also not as important as the skip option, it can be used for debugging/tracing. so if it does not take much work, please put it on the wish list. thanks --- [This E-mail scanned for viruses by Declude Virus] --- [This E-mail was scanned for viruses by Declude Virus (ht

Re[2]: [Declude.Virus] Klez.h

2002-05-02 Thread Eje Gustafsson
Dear Andy, That is not true. Far from it. It spoofs both. The from in the envelop is right that it uses the right MX server for the domain in question. For a LONG time we had one client that got daily notifications claiming he sent viruses. However the senders was from aol, comcast, roadrunner a

NJABL:Re: [Declude.Virus] Klez.h

2002-05-02 Thread Mike Watchman
So from the information below which IP address is first received header? And what is the Envelope from variable that Andy mentioned. Thanks Scott/Everyone, Declude and this list are a great help to me. Mike Declude Virus v1.51 caught the : W32/Klez.H@mm virus in Lottery.pif from [EMAIL PROTECTED

[Declude.Virus] W32.Klez.gen@mm

2002-05-02 Thread PesaroService
Hi, I'm using F-Prot with declude and works fine. Today one customer said me tha the virus Klez.gen was received on his mailbox. It seems that F-prot (or declude) let go this virus Do you think that's true ? Any tips ? Thanks Giampiero Pagnoni --- [This E-mail was scanned for viruses by D

RE: [Declude.Virus] Klez.h

2002-05-02 Thread Andy Schmidt
Actually Scott - DECLUDE is much smarter than you give it credit for. In ALL of my many daily KLEZ encounters I have found the following to be true: a) the Message Header "FROM:" is false b) the Envelope "FROM:" always uses an email addresses that matches the host in the first RECEIVED line. He

Re: [Declude.Virus] Klez.h

2002-05-02 Thread R. Scott Perry
>Hi, how do I tell where the Klez.h is really coming from? Thanks. The only way to know for sure is to check the first Received: header to see the IP address that it was sent from. To find the user it came from, you would need to find someone responsible for the IP address it came from, and

[Declude.Virus] NJABL:Klez.h

2002-05-02 Thread Mike Watchman
Hi, how do I tell where the Klez.h is really coming from? Thanks. Mike --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Dec

[Declude.Virus] Declude and iMail Rules

2002-05-02 Thread Paul
We want to treat email with different weights differently. For example, 1. email failing the weight10 test would be sent through with the attach action, and 2. email failing the weight15 test would be diverted on the server with iMail rules. But, if a message fails weight15, then it also failed