[Declude.Virus] Something strange out...

2004-11-19 Thread Markus Gufler
From this morning on (09:00 am GMT+1) on we can see a lot of unknown viruses As this messages contains from one to many recipients there are comming back a lot of NDR's from our warning messages. (Scott: you know we can not SKIPIF unknown virus) So at the momen I've disabled all warning messages

RE: [Declude.Virus] Something strange out...

2004-11-19 Thread Markus Gufler
Additional notes: Seems like F-Prot with Viruscode 8 is catching this for over an hour now. Mcafee does not. As there are always (?) pif,scr,... attachments it will be catched also by banned extensions. (Do you send out bannotifies?) But I've seen also .xls.zip attachments hold as unknwon

RE: [Declude.Virus] Something strange out...

2004-11-19 Thread Markus Gufler
Here's another body sample: === Your password was changed successfully! ++ User-Service: http://www.news.vva.de ++ MailTo: [EMAIL PROTECTED] *-*-* Attachment: No Virus found *-*-* THALER- Anti_Virus Service *-*-* http://www.thaler.it

RE: [Declude.Virus] Something strange out...

2004-11-19 Thread Hirthe, Alexander
Hello, this is a new Sober. Alex -Original Message- From: Markus Gufler [mailto:[EMAIL PROTECTED] Sent: Friday, November 19, 2004 10:09 AM To: [EMAIL PROTECTED] Subject: [Declude.Virus] Something strange out... From this morning on (09:00 am GMT+1) on we can see a lot of

RE: [Declude.Virus] Something strange out...

2004-11-19 Thread Markus Gufler
Ok, both F-Prot and McAfee are catching it now as Sober.j Markus -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Hirthe, Alexander Sent: Friday, November 19, 2004 10:28 AM To: [EMAIL PROTECTED] Subject: RE: [Declude.Virus] Something strange

[Declude.Virus] vulnerabilities and spam

2004-11-19 Thread Bonno Bloksma
Hi, I'm almost at the point where I simply won't send out any e-mail to the sender or recipient when a "virus" is detected. Just about all of them are forged anyway. However, what anoys me most is the fact most "vulnerabilities" are spam. And I would like to report a vulnerability to the

Re: [Declude.Virus] vulnerabilities and spam

2004-11-19 Thread Russ Uhte
Bonno Bloksma wrote: Hi, I'm almost at the point where I simply won't send out any e-mail to the sender or recipient when a virus is detected. Just about all of them are forged anyway. However, what anoys me most is the fact most vulnerabilities are spam. And I would like to report a

[Declude.Virus] F-Prot 3.16 available.

2004-11-19 Thread Hirthe, Alexander
Hello, fyi: -- FRISK Software has released version 3.16 of F Prot Antivirus for Windows as well as versions 4.4.8 of F-Prot Antivirus for all UNIX based platforms. More information on these releases can be found on our website:

Re: [Declude.Virus] F-Prot 3.16 available.

2004-11-19 Thread Info Wind
Hello, it seems that f-prot has a problem at the moment with high traffic: This is a messages from F-Prot Support: We have been experiencing extensive traffic on our servers and therefore downloading from them has been very slow. Our network administrator is working on this issue and it should be

RE: [Declude.Virus] F-Prot 3.16 available.

2004-11-19 Thread Panda Consulting S.A. Luis Alberto Arango
Try this link. Is there download server. http://subscription.f-prot.com/cgi-bin/cust_master Luis -Original Message- From: [EMAIL PROTECTED] [mailto:Declude.Virus- [EMAIL PROTECTED] On Behalf Of Info Wind Sent: Friday, November 19, 2004 12:06 PM To: [EMAIL PROTECTED] Subject: Re:

RE: [Declude.Virus] F-Prot 3.16 question.

2004-11-19 Thread Panda Consulting S.A. Luis Alberto Arango
Their release notes say Among improvements introduced in version 3.16 of F-Prot Antivirus for Windows is a new method of ensuring that F-Prot Antivirus is up-to-date as soon as it has been installed with virus signature file updates now being triggered during the installation procedure of the

Re: [Declude.Virus] F-Prot 3.16 question.

2004-11-19 Thread Matt
There are all sorts of these, also known as decompression bombs. Many AV scanners have code to stop at least some of the exploits, but I don't know if this presents an issue with Declude (I don't think so because I don't think that Declude performs any form of decompression on it's own, but I

Re: [Declude.Virus] MRTG

2004-11-19 Thread Nick
Is anyone aware of a port of declude virus logs to mrtg? Thanks! -Nick Hayer --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type

[Declude.Virus] ClamAv

2004-11-19 Thread Jeff Kratka
I just started to try out Clam AV and so far it's been catching more than F-Prot did. Is there a switch to have Declude add the virus name to the Declude logs.My config in the virus .cfg is SCANFILE C:\imail\declude\runclamscan.exe log=1 C:\clamav-devel\bin\clamdscan.exe --quiet --mbox -l

RE: [Declude.Virus] ClamAv

2004-11-19 Thread Jeff Kratka
Sorry, I figured it out... Thanks Jeff Kratka TymeWyse Internet P.O.Box 84 - 110 Ecklund St., Canyonville, OR 97417 tel/fax: (541) 839-6027 - [EMAIL PROTECTED] -Original Message- From:

RE: [Declude.Virus] ClamAv

2004-11-19 Thread Jonathan
Running ClamAV under cygwin? Wow, that seems like a horrible performance hit on any type of high volume mail server. Jonathan At 06:22 PM 11/19/2004, you wrote: Sorry, I figured it out... Thanks Jeff Kratka TymeWyse Internet P.O.Box 84 - 110

RE: [Declude.Virus] ClamAv

2004-11-19 Thread Jeff Kratka
That's why I trying it out. I'm still trying to figure a few things out. I can say that Clam updated and caught things quick today. Their virus updates came out before F-Prot did. I still like F-Prot so that's why I'm just watching for now. Jeff Kratka -- Original Message