[Declude.Virus] Email being released today - Advance Notice
This is a preview of an email being shortly released by Declude and being sent to all customers. _ We recently promised you information about our plans as and when it became available. Here are two pieces of news: A Beta release of Declude 2.0 will be available on or around December 16th that will include new functionality and also support for an additional windows based mail server as an affordable alternative to IMail. This opens up the options for a reasonably priced, fully functional gateway. In order to provide more equitable pricing on Service Agreements we will introduce a new mechanism which will be available immediately. There will be server/product based support agreements rather than a blanket cost which penalizes the smaller user. Please visit our Service Agreements page to see more details. On a less positive note we have been monitoring downloads and activations of Declude software and have discovered that there are a significant number of non licensed copies being used. These include customers downloading the latest release without a valid Service Agreement and others who have installed multiple copies of unlicensed software. We encourage all customers who are participating in these activities to regularize their legal position by December 31st, 2004. If you have any questions as to the validity of your installation please email us at [EMAIL PROTECTED] or call us at (866) 332-5833 between 8.00 am and 5 pm Eastern Time, Monday thru Friday.
[Declude.Virus] Advice on Antivirus for System Protection
We've been using Declude/F-Prot to protect our email users, and Symantec Corp. Ed. to protect the server it'self. Our Symantec is up for renewal and I was wondering what others are using that might be less expensive. Bill Green dfn Systems --- [This E-mail scanned for viruses by Declude Virus] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
Re: [Declude.Virus] Advice on Antivirus for System Protection
I find Symantec Corporate Edition to be my server AV scanner of choice because it is easily configurable (primarily for exclusions), and has a nice feature that shows you exactly what is being scanned in real-time. It hardly costs anything, and they now also offer multi-year licenses. Make sure that you purchase over the Internet to save substantially. http://shopper-search.cnet.com/search?part=q=Symantec+Corporate+Edition+Server+9.0 Matt Bill Green dfn Systems wrote: We've been using Declude/F-Prot to protect our email users, and Symantec Corp. Ed. to protect the server it'self. Our Symantec is up for renewal and I was wondering what others are using that might be less expensive. Bill Green dfn Systems --- [This E-mail scanned for viruses by Declude Virus] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com. -- = MailPure custom filters for Declude JunkMail Pro. http://www.mailpure.com/software/ = --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
Re: [Declude.Virus] about Imail1.exe security issue
IPSwitch tech-support reply me that they are still investigating this issue. I am very sure it's caused by a mass mail worm outside my server, just don't know how can it cause a pop up windows in my server desktop. - Original Message - From: Mike Wiegers [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Tuesday, November 30, 2004 1:21 AM Subject: RE: [Declude.Virus] about Imail1.exe security issue Has anyone found out anymore about this issue? Is it related to Imail and Declude users only? Thanks, Mike --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
RE: [Declude.Virus] log file grepping
Bill?.. or anyone :) Is there a way in a single line to use grep or a similar tool on a virus log file and have it return 2 values: total_scanned and viruses found? I have been able to do this in multiple lines with temp files but am stuck trying to do it on a single command line. The purpose here is to use mrtg to graph virus traffic - I can do it with one value but when I try to combine both I am lost. Thanks in advance - -Nick --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
Re: [Declude.Virus] log file grepping
Nick, What is your time table on this? If you can wait a couple days I will add virus graphing to the mrtg stuff I already make available. I would have it sooner, but I am just trying to wrap up the final touches on DLAnalyzer 4.0 which I hope to have out sometime over the next day or two. Let me know, Darrell Check out http://www.invariantsystems.com for utilities for Declude And Imail. IMail/Declude Overflow Queue Monitoring, MRTG Integration, and Log Parsers. Nick writes: Bill?.. or anyone :) Is there a way in a single line to use grep or a similar tool on a virus log file and have it return 2 values: total_scanned and viruses found? I have been able to do this in multiple lines with temp files but am stuck trying to do it on a single command line. The purpose here is to use mrtg to graph virus traffic - I can do it with one value but when I try to combine both I am lost. Thanks in advance - -Nick --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
RE: [Declude.Virus] log file grepping
grep INFECTED virMMDD.log | gawk {print $8} | sort | uniq -ic | sort /reverse Gives a nice listing of catches: 50 HTML/[EMAIL PROTECTED]: 33 W32/[EMAIL PROTECTED]: 19 'CR' 18 W32/[EMAIL PROTECTED]: 3 W32/[EMAIL PROTECTED]: 2 Encoding 1 W32/Wurmark.A: 1 W32/[EMAIL PROTECTED]: 1 W32/[EMAIL PROTECTED]: 1 W32/[EMAIL PROTECTED]: 1 W32/[EMAIL PROTECTED]: 1 W32/[EMAIL PROTECTED]: 1 'Space 1 'MIME 1 'Blank John Dobbin -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Nick Sent: Wednesday, December 01, 2004 4:31 PM To: [EMAIL PROTECTED] Subject: RE: [Declude.Virus] log file grepping Bill?.. or anyone :) Is there a way in a single line to use grep or a similar tool on a virus log file and have it return 2 values: total_scanned and viruses found? I have been able to do this in multiple lines with temp files but am stuck trying to do it on a single command line. The purpose here is to use mrtg to graph virus traffic - I can do it with one value but when I try to combine both I am lost. Thanks in advance - -Nick --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
Re: [Declude.Virus] log file grepping
On 1 Dec 2004 at 17:58, DLAnalyzer Support wrote: What is your time table on this? If you can wait a couple days I will add virus graphing to the mrtg stuff I already make available. No rush. And thanks for doing this. I've wanted this for awhile - today I just caved in in a weak moment and had to ask for help! -Nick --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
Re: [Declude.Virus] log file grepping
Just a thought. I produce this list nightly with a batch file with unxtools. I really like the add I have to tell me if it's an inside machine or outside. Inside ones show the IP of the sending computer. See the EXE banned at the bottom. I'd be happy to share my bat file for this, it does require unxtools and certain values in the eml files and I send all items to a catchall user for parsing. bob 27 Virus Name: : W32/[EMAIL PROTECTED] outside 19 Virus Name: : HTML/[EMAIL PROTECTED] outside 16 Virus Name: : W32/[EMAIL PROTECTED] outside 9 Virus Name: : W32/[EMAIL PROTECTED] outside 8 Virus Name: : W32/[EMAIL PROTECTED] outside 4 Virus Name: : W32/[EMAIL PROTECTED] outside 2 Virus Name: : W32/[EMAIL PROTECTED] outside 1 Virus Name: [Outlook 'MIME segment in MIME Preamble' Vulnerability] outside 1 Virus Name: [Outlook 'Blank Folding' Vulnerability] outside 1 Virus Name: : W32/[EMAIL PROTECTED] outside 1 Virus Name: : W32/[EMAIL PROTECTED] outside 1 Virus Name: : W32/[EMAIL PROTECTED] outside 1 Virus Name: : W32/[EMAIL PROTECTED] outside 1 Virus Name: : W32/[EMAIL PROTECTED] outside 1 Virus Name: : W32/[EMAIL PROTECTED] outside 1 Banned Attachment: URL outside 1 Banned Attachment: JS outside 1 Banned Attachment: EXE In-District Attempt 10.13.1.77 On Wednesday, December 1, 2004 3:59 PM, John Dobbin [EMAIL PROTECTED] wrote: grep INFECTED virMMDD.log | gawk {print $8} | sort | uniq -ic | sort /reverse Gives a nice listing of catches: 50 HTML/[EMAIL PROTECTED]: 33 W32/[EMAIL PROTECTED]: 19 'CR' 18 W32/[EMAIL PROTECTED]: 3 W32/[EMAIL PROTECTED]: 2 Encoding 1 W32/Wurmark.A: 1 W32/[EMAIL PROTECTED]: 1 W32/[EMAIL PROTECTED]: 1 W32/[EMAIL PROTECTED]: 1 W32/[EMAIL PROTECTED]: 1 W32/[EMAIL PROTECTED]: 1 'Space 1 'MIME 1 'Blank John Dobbin -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Nick Sent: Wednesday, December 01, 2004 4:31 PM To: [EMAIL PROTECTED] Subject: RE: [Declude.Virus] log file grepping Bill?.. or anyone :) Is there a way in a single line to use grep or a similar tool on a virus log file and have it return 2 values: total_scanned and viruses found? I have been able to do this in multiple lines with temp files but am stuck trying to do it on a single command line. The purpose here is to use mrtg to graph virus traffic - I can do it with one value but when I try to combine both I am lost. Thanks in advance - -Nick --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
Re: [Declude.Virus] log file grepping
- Original Message - From: Nick [EMAIL PROTECTED] Bill?.. or anyone :) Is there a way in a single line to use grep or a similar tool on a virus log file and have it return 2 values: total_scanned and viruses found? Total messages scanned for the day and the total number of viruses found for that day (not count of individual virus)? Bill --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
Re: [Declude.Virus] Advice on Antivirus for System Protection
Matt, Looking at the costs on cnet, I don't see any mention of if you get the media with this cost or if you are just buying the licenses. On the Symantec site, they talk about getting the media with their license packs, but you have to buy at least 10 licenses. I only want to run this on my mail server with no clients, so do you know if one of these other sites sell just a single license with the disk media? Thanks, Dean __ Dean Lawrence, CIO/Partner Internet Data Technology 888.GET.IDT1 ext. 701 * fax: 888.438.4381 http://www.idatatech.com/ Corporate Internet Development and Marketing Specialists --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
Re: [Declude.Virus] Advice on Antivirus for System Protection
I'm not an expert on Symantec licensing, but you can definitely buy the media online as well. http://shopper-search.cnet.com/search?part=q=Symantec+Corporate+Edition+media+9.0 Matt Dean Lawrence wrote: Matt, Looking at the costs on cnet, I don't see any mention of if you get the media with this cost or if you are just buying the licenses. On the Symantec site, they talk about getting the media with their license packs, but you have to buy at least 10 licenses. I only want to run this on my mail server with no clients, so do you know if one of these other sites sell just a single license with the disk media? Thanks, Dean __ Dean Lawrence, CIO/Partner Internet Data Technology 888.GET.IDT1 ext. 701 * fax: 888.438.4381 http://www.idatatech.com/ Corporate Internet Development and Marketing Specialists --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com. -- = MailPure custom filters for Declude JunkMail Pro. http://www.mailpure.com/software/ = --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
Re: [Declude.Virus] Advice on Antivirus for System Protection
A plus to Symantec for me is that since I can't use Symantec for my Declude e-mail protection, and I do use it on workstations and servers, any e-mail virus needs to make it through an additional and different A/V program on the desktop. The higher the hurdle, the less that can make the leap. - Original Message - From: Matt [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Wednesday, December 01, 2004 12:25 PM Subject: Re: [Declude.Virus] Advice on Antivirus for System Protection I find Symantec Corporate Edition to be my server AV scanner of choice because it is easily configurable (primarily for exclusions), and has a nice feature that shows you exactly what is being scanned in real-time. It hardly costs anything, and they now also offer multi-year licenses. Make sure that you purchase over the Internet to save substantially. http://shopper-search.cnet.com/search?part=q=Symantec+Corporate+Edition+Ser ver+9.0 Matt Bill Green dfn Systems wrote: We've been using Declude/F-Prot to protect our email users, and Symantec Corp. Ed. to protect the server it'self. Our Symantec is up for renewal and I was wondering what others are using that might be less expensive. Bill Green dfn Systems --- [This E-mail scanned for viruses by Declude Virus] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com. -- = MailPure custom filters for Declude JunkMail Pro. http://www.mailpure.com/software/ = --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
[Declude.Virus] Declude Virus Log Analyzer
Title: Message I got his announcement and have been running some reports. Looks encouraging! -Original Message-Subject:DLAnalyzer 4.0 Customer Pre-Release Is Now Available. We are making available to our customers a pre-release version of DLAnalyzer 4.0. With version 4.0 we have integrated Declude Virus log processing into DLAnalyzer giving you the ability to generate one report that encompasses both spam and virus statistics. In addition, to the virus processing we have added many other features to the core application. The Declude Virus Log processing requires you to be running log level HIGH for most of the reports to function correctly. New Features in Version 4.0 1.) Ability to process multiple servers 2.) Overall Server Virus Report 3.) Virus Scanner Report 4.) File Extension Report 5.) File Extension Virus Report 6.) IP Virus Summary Report 7.) Recipient Virus Report 8.) Sender Virus Report 9.) Banned File Extension Report 10.) Per Domain Virus Report 11.) Per Domain Recipient Virus Report 12.) Per Domain IP Virus Summary Report 13.) Advanced Virus Reporting Plus Many Other Features and Bug Fixes Release Notes: http://www.invariantsystems.com/download/current/readme.txt Download: http://www.invariantsystems.com/download/dlanalyzer400.zip ***NOTE: Before installation of DLAnalyzer 4.0 please make a backup copy of your dlanalyzer.xml license file. You will need to drop your license file in the folder you install DLAnalyzer 4.0 into. NOTE: This is a pre-release because we have not finished the documentation and websiteupdates forversion 4.0. We expectto have all of the documentation in place by the end of next week for general release. ---Check out http://www.invariantsystems.com for utilities for Declude And Imail. IMail/Declude Overflow Queue Monitoring, MRTG Integration, and Log Parsers.