[Declude.Virus] OT - Alert lists.

2003-09-12 Thread Pete - Madscientist
We're thinking of augmenting our service by aggressively pursuing email born malware. What lists everyone thinks are best for up-to-date alerts on new outbreaks their details. Thanks, _M Pete McNeil (Madscientist) President, MicroNeil Research Corporation Chief SortMonster, www.SortMonster.com

RE: [Declude.Virus] OT - Alert lists.

2003-09-12 Thread Todd Holt
Will this be incorporated into our rulebase files? If so, shouldn't the virus scanner have found the virus before the sniffer gets to scan it? Todd Holt Xidix Technologies, Inc Las Vegas, NV USA www.xidix.com -Original Message- From: [EMAIL PROTECTED] [mailto:Declude.Virus- [EMAIL

RE: [Declude.Virus] OT - Alert lists.

2003-09-12 Thread Pete - Madscientist
Yes, these rules will go into the rulebase files under the malware group. There are a number of reasons we're thinking about being more aggressive: * Some systems do not have server based virus scanning. * We *may* be able to respond more quickly than some anti-virus companies. * We service many

[Declude.Virus] Sophos - Not detecting?

2003-09-12 Thread Jack Taugher
Does Sophos's CLI work well with Declude? The reason I ask is it only seems like Declude/Sophos' interaction is only picking up these types of viruses: --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list.

[Declude.Virus] Sophos - Declude? Work well?

2003-09-12 Thread Jack Taugher
Does Sophos' CLI work well with Declude/Imail? I ask because I don't see anything but the following come through my personal mail server: 09/11/2003 21:52:15 Q34df003e009edb62 Outlook 'CR' vulnerability [MIME-Versi] in line 8 09/11/2003 21:52:17 Q34df003e009edb62 File(s) are INFECTED [[Outlook

Re: [Declude.Virus] Sophos - Declude? Work well?

2003-09-12 Thread R. Scott Perry
Does Sophos' CLI work well with Declude/Imail? The Sophos sav32cli.exe file will work fine with Declude Virus. If it is not detecting the eicar.com file (when sent from our Test Virus Sender at http://www.declude.com/tools ), the next step would be the debug mode. To do this, change the

RE: [Declude.Virus] Sophos - Declude? Work well?

2003-09-12 Thread John Tolmachoff \(Lists\)
That is not Sophos, that is Declude finding them. What does the virus log say? You might need to put it in Debug mode. John Tolmachoff MCSE CSSA Engineer/Consultant eServices For You www.eservicesforyou.com -Original Message- From: [EMAIL PROTECTED] [mailto:Declude.Virus- [EMAIL