Will my old version of Declude work with the new version of Imail?
TIA,
Sharyn
---
This E-mail came from the Declude.JunkMail mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.JunkMail. The archives can be found
at
Title: Declude and Imail 2006
Hi,
We are getting ready to upgrade to Imail 2006.
I am wondering if my older version of declude virus and junkmail (2.0.6) will work with Imail 2006?
Thanks,
Sharyn
---This E-mail came from the Declude.JunkMail mailing list. Tounsubscribe, just send
Title: Possible virus?
Anyone seen or heard of a virus that is sending out random power point attachments?
One of the attachments is called House_of_Golf.pps
Thanks,
Sharyn
Title: Correct path in virus config?
Hi,
I'm going to be using a different version of McAfee Virus Scan software. This version is VS80i.
It looks like the command line scanner installs in a different location then the old version (4.0) that I was using.
Can someone verify for me that
Title: U can check out but you can never leave
Sorry to interrupt with a non technical post but
I have tried 3 times already to unsubscribe from this list.
I get the confirmation request, I send it off, but I never receive notification that I've been unsubscribed.
Then, I get more
Title: Message
Ill see that you are
taken off the lists as soon as our email administer comes in. Thanks for
the report. Well fix the problem with unsubscribe as
well.
Have a great
vacation!
Thanks
Bill!
See you all
when I return!
Sharyn
Title: Virus notifications from local host
Hi,
I have Declude set to send me an email notification when it has quarrantined an email containing a virus, using this variable:
From: [EMAIL PROTECTED]
I have since changed my OHN in IMAIL.
The notification still has the old OHN
It's
After 4 years of hard work and little sleep Scott Perry has decided to move
away from customer facing activities with Declude and will be spending more
of his time working with the Red Cross.
Scott continues his commitment to Declude in an advisory role.
LOL! Now, folks, is this a BIG SHOCKER
Zafi.d sends messages in different european languages having christmas
content (for example in Italian with the subject line Buon natale)
We are getting HAMMERED by these but Declude/McAfee is catching them and
identifying them correctly, DAT 4414..
Declude Virus caught a virus with the
Title: Virus infection warnings
Scott?
At one time you were following up with mailservers that had Declude software installed, that were sending out these messages for forging viruses.
Anything you can do about this?
Thanks,
Sharyn
The Declude Virus software on fmmalaysia.com.my
Title: V1.81?
I never installed 1.80 after reading some of the jpeg issues on this list.
Now, I see 1.81 is out.
Have the false positive issues been resolved?
I'm assuming there is no need to upgrade to 1.80 first before installing 1.81. Correct?
Thanks,
Sharyn
Title: Lines in the virus.cfg file
I was looking through my virus.cfg and I noticed the following:
# The SKIPEXT option will let you skip scanning of certain file extensions. For
# example, a GIF file can't contain a virus, so there is no need to scan it.
#
SKIPEXT GIF
SKIPEXT TXT
Title: New release
Hi,
Due to a minor inconvenience called Hurricane Jeanne, we have been offline for about 5 days now.
Can someone please tell me when the newest release was available for download?
Thanks,
Sharyn
And no, it was not my wife. I am genetically prone to bloody noses in dry
weather. This week, the average humidity in Southern California has been
around 15%.
Gee, come to Florida where we are about to be hit with our FOURTH hurricane
in about 6 weeks, lots of rain and humidity here!
Sharyn
users check mail direct from the
backup as far as I know you would need a second license for
declude.
Jim Matuska Jr.Computer Tech
IICCNANez Perce TribeInformation Systems[EMAIL PROTECTED]
- Original Message -
From:
Sharyn
Schmidt
To: [EMAIL PROTECTED
Title: Second mail server
Scott,
Am I to assume that if I configure a backup mailserver I will need to purchase another full license for the Declude products?
Thanks,
Sharyn
Title: OT: Hello?
I haven't rec'd anything from either of these lists today?
Sharyn
Title: OT- Anyone know about this latest attack reported by CNN?
Here is what CNN says:
http://www.cnn.com/2004/TECH/internet/06/24/internet.attack.ap/index.html
Sharyn
Thanks!
We are patched.
Sharyn
We are the worldwide producer and marketer of the award winning Cruzan
Single Barrel Rum, judged Best in the World at the annual
San Francisco Wine and Spirits Championships. For
more information, please click (go to) htmla
Title: Exploit-ObjectData trojan
Forgive me , I've been out of the loop, working on other things.
What is this Exploit-ObjectData trojan?
I can't seem to find mention of it on McAfee's website and Declude is nabbing them like crazy.
Thanks in advance,
Sharyn
Title: Message
http://us.mcafee.com/virusInfo/default.asp?id=descriptionvirus_k=100715
Got it, thanks.
I'm apparantly a bit brain dead this morning.
:)
Sharyn
W32/[EMAIL PROTECTED] virus
Aww, c'mon NewWorm has a nice ring to it.
Sharyn
We are the worldwide producer and marketer of the award winning Cruzan
Single Barrel Rum, judged Best in the World at the annual
San Francisco Wine and Spirits Championships. For
more information, please click (go
Title: Message
Are you talking about
the creators or the users who open them anyways?
LOL! I was talking about the creators, however, if the
shoe fits.
Sharyn
Title: Message
I can also recommend
snort. There is a full windows version put out by
Engagesecurity.com The product is called EagleX and is a single
install of all needed components for Snort to operate on a Windows
platform.
For those of you running Snort, please give me what
Title: Deleting quarrantined viruses
Due to the overwhelming amount of MyDoom quarrantines, my virus folder is huge.
I know this has been addressed, sorry, but can I just delete what is in there?
Sharyn
Sharyn, I am trying to help you find out what is wrong.
I know you are ..I am not being obtuse (or dishonest) on purpose,
honest.
I thought you stated before you are not using a gateway, that e-mail is
received directly by the Imail server where the mail boxes are.
And the lightbulb goes off.
This is expected in a gateway configuration.
And yes, I feel like an @ss for not thinking of the smtp proxy on the
firewall as the culprit sooner...so please, be gentle..no flames
Sharyn
We are the worldwide producer and marketer of the award winning Cruzan
Single Barrel Rum, judged Best
What is the flavor? I hope you do not have the IP of that firewall in
the Imail SMTP relay for addresses.
It's a Watchguard Firebox 3 and the IMAIL server sits on what the
Watchguard people call the Optional Interface but what I would call the
DMZ.
If all mail passes through the Firebox smtp
Sharyn, what exactly does the Qbacc08dd025a52a7.SMD file say?
QD:\IMAIL\spool\Dbacc08dd025a52a7.SMD
Htodhunter.com
WD:\IMAIL
E0,
R[EMAIL PROTECTED]
S[EMAIL PROTECTED]
NRCPT TO:[EMAIL PROTECTED]
R[EMAIL PROTECTED]
The masterbackup address is the email address used for the copy all mail
Title: Non bouncingto non users..FIXED
Answer/Solution: If IMail says 'OK, accepted for peer' and you are not currently using any additional IMail servers with the Peering feature, here is the fix: run regedit. Go to:
HKEY_LOCAL_MACHINE\SOFTWARE\Ipswitch\IMail\Domains\your-domain
Delete the
Title: MyDoom going to non existant users
Over 1/2 the MyDoom emails we are receiving are being sent to users that don't even exist, as in, [EMAIL PROTECTED]
Is anyone else seeing this and is there any way to stop these emails before all the scanning is done on them?
Sharyn
Title: Message
If they
don't exist how are you receiving them? Do you have nobody alias?
I've always wondered
that myself.
Perhaps you want to deactivate it for the duration
of this virus frenzy..
I will deactivate it permanently if I can find the freaking
thing.
Thanks!
Title: Message
If they
don't exist how are you receiving them? Do you have nobody alias?
OkFolks, color me stupid but wouldn't the nobody
alias be located in the "Alias"
folder?
If this is the case, thenthe mysterious nobody is
non existant and I still don't have a clue why these emails
To all that are having this problem. Please check the Q file to see if
there is at least one valid user listed.
We are required by federal law, due to the nature of our business, to
keep copies of all email received so we use the copy all function in
IMAIL, sending every email received to a
Todhunter Firewall. Have sender deliver to [EMAIL PROTECTED] and CC: you. Contact Network Administrator (Sharyn Schmidt) for message retrieval.]
Title: Virtual domains
I have just added a virtual domain (my first, so please bear with me!).
I want to make sure both JM and Virus are scanning mail on the virtual domain.
Is there any special configuration I need or will it do it automatically, as it's using the same mail server?
It will be done automatically. :)
grin
Why isn't all software this easy to use??!!!
Thanks,
Sharyn
We are the worldwide producer and marketer of the award winning Cruzan
Single Barrel Rum, judged Best in the World at the annual
San
Title: Message
Not a single person in the domains hosted on our server has received a
single incident.
Kami,
If it makes you
feel any better, I am getting approximately 40 to 50 of these a day, while the
rest of my users, combined, have received no more than 20.
Sharyn
Title: This in from my local newspaper
Looks like someone is busy writing a trojan that takes advantage of the security flaw that MS announced last week..
http://ap.polkonline.com/pstories/technology/20030916/1468801.shtml
Sharyn
vir0819.log 437 437
vir0820.log 2,939 2,939
vir0821.log 3,937 3,937
vir0822.log 2,755 2,755
vir0823.log 275 275
vir0824.log 91 91
vir0825.log 8,525
You can download it here http://www.csonline.net/imailstuff/viruslog.htm
It *is* my day for dumb questions, or perhaps it's a tribute to Declude
virus that I haven't had to touch the config file since the day I
installed it. After changing the loglevel to MID to use this tool, does
anything need
I'm running McAfee NetShield on the servers, where I can exclude certain
folders, e.g., the Imail Spool folder tree.
I am too, with the IMAIL directory excluded, and knock on wood haven't
had any problems with either Declude or infections on the mail server
itself.
And, FYI, McAfee was catching
Feel free to send it to [EMAIL PROTECTED] (just be sure to let me
know
after you send it, as that mailbox isn't monitored).
-Scott
Guess we are all curious now as to what it is.
Sharyn
We are the worldwide producer and marketer of the
Title: Message
This
is what I'm getting..
The IP address of the offending server is
12.154.100.6
The name of the virus is [Unknown: Err].
The attachment is the Exploit-CodeBase trojan !!!
Sharyn
Afternoon,
I am curious, does Declude send out the sender.eml message when it
catches a vulnerability as opposed to a virus?
Thanks,
Sharyn
We are the worldwide producer and marketer of the award winning Cruzan
Single Barrel Rum, judged Best in the World at the annual
San Francisco Wine and
Yes, unless you add the SKIPIF line.
Is there any way to skip sending the notification to a particular
address, as opposed to a virus name?
Sharyn
We are the worldwide producer and marketer of the award winning Cruzan
Single Barrel Rum, judged Best in the World at the annual
San Francisco
Thanks, Scott, last question for the day...
Can I use the SKIPIFVIRUSNAMEHAS on a vulnerability?
As in, add a line that says.
SKIPIFVIRUSNAMEHAS Vulnerability (provided I spell it correctly which
I'm not sure I did here)
I set up the .eml options a really LONG time ago
You can go to http://www.declude.com/virus/manual.htm and look at the
latest .eml files, which include the settings that we recommend (such as
not sending the notifications to the senders of the Klez virus).
-Scott
:)
That's where I was looking when I realized there
? (reader's digest version is
fine)
TIA,
Sharyn Schmidt
Network Administrator
Florida Distillers Company
(863) 956-1116 x221
We are the worldwide producer and marketer of the award winning Cruzan
Single Barrel Rum, judged Best in the World at the annual
San Francisco Wine and Spirits
global.cfg
---
frndgrt filter d:\imail\declude\frndgrt.txt x 0 0
$default$.junkmail
-
frndgrt BOUNCE
frndgrt.txt
-
BODY0 CONTAINSF r i e n d - G r e e t i n g s . c o m
(without the spaces)
Thanks! This is
Unless someone knows of a better way.
At the risk of getting flamed for mentioning something that is somewhat
off topic in regard to this, I am blocking friendcard.com with the http
proxy on my firewall.
No, that doesn't prevent the email with the link from coming in, but it
sure as heck
Only problem is, that only protects the 19 people behind the firewalls
I control.
Exactly. That sort of set up is only good for a small business like mine
where everyone is forced to authenticate through my firewall before
going out to the web, and doesn't help anyone who doesn't have a
I havent received mail from the IMAIL list in about 2 days. Is the list
down?
Sharyn
We are the worldwide producer and marketer of the award winning Cruzan
Single Barrel Rum, judged Best in the World at the annual
San Francisco Wine and Spirits Championships, and the
artisan tequilas of
In my IMAIL spool folder, I have a bunch of .vir subfolders, such as
Dc29c2b4.vir. I am assuming these were viruses that were nabbed by
Declude and sent to a quarrantine folder.
Can these just be deleted?
Thanks,
Sharyn Schmidt
Network Specialist
Florida Distillers Company
(863) 956-1116
I have excluded the imail directory from any on access scan.
I am looking at the old setup, on the server that was running mail and
declude and netshield and it's set up the exact same way.
I'll be happy to email you my virus.cfg and logs. You want me to send
them to this address or email you
.
The Official Host name is the same, I copied over the whole Imail
directory, including the Declude folder and declude.exe. I launched the
declude.exe file.
Is there something else I need to do?
Sharyn Schmidt
Network Specialist
Florida Distillers Company
(863) 956-1116 x139
We
Looking at the virus log, it looks like Declude is running, but
everything is being passed off as virus free.
Sharyn
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of R. Scott Perry
Sent: Thursday, February 14, 2002 5:41 PM
To: [EMAIL PROTECTED]
Subject:
gotten past the mail server once it hit my network but
somehow it did. I am running Netshield (and Declude) on my mail server
with the latest scan engine and DAT file, and up until now, the latest
Badtrans was being caught.
Thanks!
Sharyn Schmidt
Network Specialist
Florida Distillers Company
I have my entire IMAIL directory excluded, with the option to include
subfolders checked.
It's working fine for me.
Sharyn
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of R. Scott Perry
Sent: Friday, October 12, 2001 1:01 PM
To: [EMAIL PROTECTED]
Ok, so..we delete them manually?
I agree..I don't see any reason to save them if they really contain a
virus. Is there a certain time period that it's safe to get rid of
these?
Sharyn
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of R. Scott Perry
The Declude installed on my mail server nabbed this :)
Sharyn
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of Dan Spangenberg
Sent: Monday, October 08, 2001 11:37 AM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.Virus] Magstr.39921
I received this
Hmmm
I'm using the Declude/McAfee Netshield setup and mine caught it,
complete with email notification that I had received a virus,
etc...wonder if I just got lucky :)
Sharyn
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of Rick Rountree
Sent:
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus] Magstr.39921
Hi Sharyn,
What av are you using with Declude ?
- Original Message -
From: Sharyn Schmidt [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Monday, October 08, 2001 3:41 PM
Subject: RE: [Declude.Virus] Magstr.39921
The Declude
No, I have the on access protection turned OFF for the whole Imail
directory as this seemed to be causing a problem when I had it turned
on.
I have the default Declude time out set..I didn't mess with this setting
at all.
Sharyn
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL
But don't I have to do some configuration with Netshield itself
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of R. Scott Perry
Sent: Monday, July 30, 2001 2:47 PM
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus] %virusname% and %virusfile%
I am
I had one today sneak in..fortunately the user didn't recognize the
sender and was smart enough to delete the email.
The Declude/McAfee setup has been catching this virus left and right. I
don't have a clue why all of a sudden it would let this one in.
Sharyn Schmidt
Network Specialist
Florida
OK..
I think you hit it Scott.
The one that was missed, is the only one so far, that has come through
with the .doc.com extension. Everything else has come with the .pif. My
guess would be that Mcaffee saw the .doc extension and just quit
scanning.
Just goes to show that even with all the
67 matches
Mail list logo