Re: [Declude.Virus] Update on Upgrade
What specific 3.x version did you upgrade to? The latest is 3.0.5.18. Bill - Original Message - From: David Dodell [EMAIL PROTECTED] To: declude.virus@declude.com Sent: Saturday, November 05, 2005 11:04 AM Subject: [Declude.Virus] Update on Upgrade It appears it is generating out the messages, but the messages are being held as GSE and GSC files, and then taking a long time to process, where it used to be instant before ??? David - Internet Dental Forum www.internetdentalforum.org Dentalcast Podcast www.dentalcast.net --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com. --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
Re: [Declude.Virus] Update
Does this contain a fix for declude aborting with the error message that has the 0xc142 and then a click ok to terminate the application ? If not is there a work around ? Avolve Support Get High Speed Internet - Go Wireless ! http://www.avolvewireless.net -- Original Message -- From: [EMAIL PROTECTED] [EMAIL PROTECTED] Reply-To: Declude.Virus@declude.com Date: Wed, 25 May 2005 16:42:59 -0400 Incremental Release A new incremental release (2.0.6.16) is now available for customers with a current service agreement. This release includes: . Virus scanner rules change option (EXITSCANONVIRUS) . Bitmasked External Test Results - JunkMail enhancement . Remove Process Counter Popup To receive information on releases in the future please send an E-mail to [EMAIL PROTECTED] with a body of subscribe Declude.Releases Firstname Lastname. Customer Information We have migrated a large portion of our customer accounts from the older system. The majority of customers can now view their Host information at the foot of the 'My Account' page on www.declude.com. Please review it and let us know of any discrepancies, missing hosts, wrong names, etc. Barry --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com. --- [This E-mail scanned for viruses by Declude Virus By Avolve.net] Sent via the WebMail system at avolve.net --- [This E-mail scanned for viruses by Declude Virus By Avolve.net] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
Re: [Declude.Virus] Update
Barry, I just checked 'My Account' - the host name should be mail.orcsweb.com, not mail.orcswe.com. And we are not running JunkMail Pro, we are running AntiVirus Pro if that matters. SmarterMail is correct though. ;)) Thanks, David Weber Windows 2000 MCP http://www.orcsweb.com/ Powerful Web Hosting Solutions #1 in Service and Support - Original Message - From: [EMAIL PROTECTED] [EMAIL PROTECTED] To: Declude.Virus@declude.com Sent: Wednesday, May 25, 2005 4:42 PM Subject: [Declude.Virus] Update Incremental Release A new incremental release (2.0.6.16) is now available for customers with a current service agreement. This release includes: . Virus scanner rules change option (EXITSCANONVIRUS) . Bitmasked External Test Results - JunkMail enhancement . Remove Process Counter Popup To receive information on releases in the future please send an E-mail to [EMAIL PROTECTED] with a body of subscribe Declude.Releases Firstname Lastname. Customer Information We have migrated a large portion of our customer accounts from the older system. The majority of customers can now view their Host information at the foot of the 'My Account' page on www.declude.com. Please review it and let us know of any discrepancies, missing hosts, wrong names, etc. Barry --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com. --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
Re: [Declude.Virus] Update
Wednesday, May 25, 2005, 3:42:59 PM, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: [SNIP] BD Customer Information BD We have migrated a large portion of our customer accounts from the older BD system. The majority of customers can now view their Host information at the BD foot of the 'My Account' page on www.declude.com. Please review it and let BD us know of any discrepancies, missing hosts, wrong names, etc. BD Barry Merchant Card Service is listed on our account, but they should have their own account. We sold the initial product to them, but we will not be involved in maintenance. Don Brown - Dallas, Texas USA Internet Concepts, Inc. [EMAIL PROTECTED] http://www.inetconcepts.net (972) 788-2364Fax: (972) 788-5049 --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
RE: [Declude.Virus] Update
Don, I will create there own account for them. Thanks Barry -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Don Brown Sent: Thursday, May 26, 2005 6:51 AM To: [EMAIL PROTECTED] Subject: Re: [Declude.Virus] Update Wednesday, May 25, 2005, 3:42:59 PM, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: [SNIP] BD Customer Information BD We have migrated a large portion of our customer accounts from the older BD system. The majority of customers can now view their Host information at the BD foot of the 'My Account' page on www.declude.com. Please review it and let BD us know of any discrepancies, missing hosts, wrong names, etc. BD Barry Merchant Card Service is listed on our account, but they should have their own account. We sold the initial product to them, but we will not be involved in maintenance. Don Brown - Dallas, Texas USA Internet Concepts, Inc. [EMAIL PROTECTED] http://www.inetconcepts.net (972) 788-2364Fax: (972) 788-5049 --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com. --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
Re: [Declude.Virus] update virus manual page
Could you add the link to the page explaining about the vulnerabilities ( http://www.declude.com/virus/vulnerability.htmhttp://www.declude.com/virus/vulnerability.htm ) to the virus manual page at the relevant place? I needed that link and was unable to find it on the site via any other link. Searching for vulnerability did not produce *any* hit. Maybe that should be adressed as well, as it is a big feature of Declude virus. Thanks -- I'll pass this on to the person who is maintaining the website. It sounds like the search function is broken. -Scott --- Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000. Declude Virus: Ultra reliable virus detection and the leader in mailserver vulnerability detection. Find out what you've been missing: Ask for a free 30-day evaluation. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
Re: [Declude.Virus] Update- New virus
None are catching this. I just updated all the AV definitions and emialed me the same virus that arrived this morning.. This new one -- (Dear user of your_domain.com e-mail server gateway...) likely is not going to get caught by any virus scanners. The only information that an AV program has about an encrypted .ZIP file is the filename, the size, and the CRC (a fingerprint of the file). This virus (Bagle.J) make the filename, size, and CRC random, so it will be nearly impossible for an AV program to detect it. We are now recommending that people block encrypted .ZIP files. You can do this by addding a line BANEXT EZIP in the \IMail\Declude\virus.cfg file if you are using the latest interim release at http://www.declude.com/interim . -Scott --- Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000. Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection. Find out what you've been missing: Ask for a free 30-day evaluation. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
RE: [Declude.Virus] Update- New virus
1.78i8 === X-Note: This E-mail was scanned filtered by Declude [1.78i8] for SPAM virus. === Kami _ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Keith Johnson Sent: Wednesday, March 03, 2004 8:46 AM To: [EMAIL PROTECTED] Subject: RE: [Declude.Virus] Update- New virus Kami, What verison of Declude are you running (1.78i7 or 1.78i8)? Thanks, Keith -Original Message- From: [EMAIL PROTECTED] on behalf of Kami Razvan Sent: Wed 3/3/2004 8:32 AM To: [EMAIL PROTECTED] Cc: Subject: [Declude.Virus] Update- New virus Hi; Just to update my last email. The new virus is still not being caught by scanners: Norton AV McAfee F-Prot AVG None are catching this. I just updated all the AV definitions and emialed me the same virus that arrived this morning.. As of 8:31 EST We are now blocking it with the new features. Regards, Kami In case it is of interest this is what we have in our .cfg file so far virus.cfg entries: BANEXT asp BANEXT bas BANEXT bat BANEXT CEO BANEXT chm BANEXT cmd BANEXT com BANEXT exe BANEXT hlp BANEXT hta BANEXT inf BANEXT isp BANEXT js BANEXT jse BANEXT lnk BANEXT msi BANEXT mst BANEXT pcd BANEXT pif BANEXT reg BANEXT scr BANEXT url BANEXT vbe BANEXT vbs BANEXT ws BANEXT wsh BANEXT ad BANEXT adp BANEXT crt BANEXT ins BANEXT mdb BANEXT mde BANEXT msc BANEXT msp BANEXT sct BANEXT shb BANEXT vb BANEXT wsc BANEXT wsf BANEXT cpl BANEXT shs BANEXT vsd BANEXT vst BANEXT vss BANEXT vsw BANEZIPEXTS ON attachment: winmail.dat
Re: [Declude.Virus] Update- New virus
R. Scott Perry wrote: None are catching this. I just updated all the AV definitions and emialed me the same virus that arrived this morning.. This new one -- (Dear user of your_domain.com e-mail server gateway...) likely is not going to get caught by any virus scanners. The only information that an AV program has about an encrypted .ZIP file is the filename, the size, and the CRC (a fingerprint of the file). This virus (Bagle.J) make the filename, size, and CRC random, so it will be nearly impossible for an AV program to detect it. Running McAfee WebShield 4.5 MR1a on a mailrelay before my mailserver (with Declude) with with Scan engine version 4.3.20 DAT version 4.3.4332 and it's detecting W32/[EMAIL PROTECTED] Erminio --- [This E-mail has been scanned for viruses by Declude Virus] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
RE: [Declude.Virus] Update- New virus
I didn't see your last e-mail? What virus? -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Kami Razvan Sent: Wednesday, March 03, 2004 8:32 AM To: [EMAIL PROTECTED] Subject: [Declude.Virus] Update- New virus Hi; Just to update my last email. The new virus is still not being caught by scanners: Norton AV McAfee F-Prot AVG None are catching this. I just updated all the AV definitions and emialed me the same virus that arrived this morning.. As of 8:31 EST We are now blocking it with the new features. Regards, Kami In case it is of interest this is what we have in our .cfg file so far virus.cfg entries: BANEXT asp BANEXT bas BANEXT bat BANEXT CEO BANEXT chm BANEXT cmd BANEXT com BANEXT exe BANEXT hlp BANEXT hta BANEXT inf BANEXT isp BANEXT js BANEXT jse BANEXT lnk BANEXT msi BANEXT mst BANEXT pcd BANEXT pif BANEXT reg BANEXT scr BANEXT url BANEXT vbe BANEXT vbs BANEXT ws BANEXT wsh BANEXT ad BANEXT adp BANEXT crt BANEXT ins BANEXT mdb BANEXT mde BANEXT msc BANEXT msp BANEXT sct BANEXT shb BANEXT vb BANEXT wsc BANEXT wsf BANEXT cpl BANEXT shs BANEXT vsd BANEXT vst BANEXT vss BANEXT vsw BANEZIPEXTS ON attachment: winmail.dat
RE: [Declude.Virus] Update- New virus
Erminio: I have a copy of this virus.. I don't think it is J. We have virus that is caught as J but this one that I have is not being caught. I can gladly send it to you off list to test.. Kami -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of E. Ballerini Sent: Wednesday, March 03, 2004 9:16 AM To: [EMAIL PROTECTED] Subject: Re: [Declude.Virus] Update- New virus R. Scott Perry wrote: None are catching this. I just updated all the AV definitions and emialed me the same virus that arrived this morning.. This new one -- (Dear user of your_domain.com e-mail server gateway...) likely is not going to get caught by any virus scanners. The only information that an AV program has about an encrypted .ZIP file is the filename, the size, and the CRC (a fingerprint of the file). This virus (Bagle.J) make the filename, size, and CRC random, so it will be nearly impossible for an AV program to detect it. Running McAfee WebShield 4.5 MR1a on a mailrelay before my mailserver (with Declude) with with Scan engine version 4.3.20 DAT version 4.3.4332 and it's detecting W32/[EMAIL PROTECTED] Erminio --- [This E-mail has been scanned for viruses by Declude Virus] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
Re: [Declude.Virus] Update- New virus
Running McAfee WebShield 4.5 MR1a on a mailrelay before my mailserver (with Declude) with with Scan engine version 4.3.20 DAT version 4.3.4332 and it's detecting W32/[EMAIL PROTECTED] Is it detecting the one with Dear user of your_domain.com e-mail server gateway... (or similar text)? Is it detecting them in an encrypted file? It may be that the virus is spreading in non-encrypted .ZIP files as well. -Scott --- Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000. Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection. Find out what you've been missing: Ask for a free 30-day evaluation. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
RE: [Declude.Virus] Update- New virus
Scott: I guess considering the concept is forging does not apply to blocking the zip files we should STOP sending banned extension notifications. True? Regards, Kami -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of R. Scott Perry Sent: Wednesday, March 03, 2004 9:05 AM To: [EMAIL PROTECTED] Subject: Re: [Declude.Virus] Update- New virus None are catching this. I just updated all the AV definitions and emialed me the same virus that arrived this morning.. This new one -- (Dear user of your_domain.com e-mail server gateway...) likely is not going to get caught by any virus scanners. The only information that an AV program has about an encrypted .ZIP file is the filename, the size, and the CRC (a fingerprint of the file). This virus (Bagle.J) make the filename, size, and CRC random, so it will be nearly impossible for an AV program to detect it. We are now recommending that people block encrypted .ZIP files. You can do this by addding a line BANEXT EZIP in the \IMail\Declude\virus.cfg file if you are using the latest interim release at http://www.declude.com/interim . -Scott --- Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000. Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection. Find out what you've been missing: Ask for a free 30-day evaluation. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
RE: [Declude.Virus] Update- New virus
At one point, only Declude Virus Pro included this new functionality of detecting virii in encoded zip files. Is that still the case? Actually, Declude Virus never had the ability to detect viruses in encoded .ZIP files (unless the AV program used with it could). The new feature (BANEXT EZIP) to block all encrypted .ZIP files works with all versions of Declude Virus (and always has). The new BANZIPEXTS and BANEZIPEXTS features (which block file extensions within .ZIP or encoded .ZIP files) currently only works with the Pro version, and the new bogus .BAT/.COM/.PIF/.SCR detection only works with the Pro version. In general, any feature that is required to catch viruses (such as BANEXT EZIP) is available in all versions; any features designed to detect new viruses that are not yet detectable with virus definitions are in the Pro version. -Scott --- Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000. Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection. Find out what you've been missing: Ask for a free 30-day evaluation. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
RE: [Declude.Virus] Update- New virus
This brings back my question (I know you are extremely busy) about adding the option of using something like BanZIPNotify.eml for zips. John Tolmachoff Engineer/Consultant/Owner eServices For You -Original Message- From: [EMAIL PROTECTED] [mailto:Declude.Virus- [EMAIL PROTECTED] On Behalf Of R. Scott Perry Sent: Wednesday, March 03, 2004 7:29 AM To: [EMAIL PROTECTED] Subject: RE: [Declude.Virus] Update- New virus I guess considering the concept is forging does not apply to blocking the zip files we should STOP sending banned extension notifications. That is probably a good idea. -Scott --- Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000. Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection. Find out what you've been missing: Ask for a free 30-day evaluation. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
Re: [Declude.Virus] Update- New virus
Is it detecting them in an encrypted file? It may be that the virus is spreading in non-encrypted .ZIP files as well. An email from [EMAIL PROTECTED], addressed to [EMAIL PROTECTED] , with subject E-mail account disabling warning. was infected with the virus W32/[EMAIL PROTECTED] in attachment unknown. The infected attachment has been cleaned and quarantined.(from MAILRELAY IP 192.87.68.214 user SYSTEM running WebShield 4.5 MR1a '_') Unfortunately, they aren't giving you enough information. There isn't any indication that this is one from an encrypted .ZIP file. So I would assume this is a standard Bagle.J in a non-encrypted file (such as a .PIF file). -Scott --- Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000. Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection. Find out what you've been missing: Ask for a free 30-day evaluation. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.
RE: [Declude.Virus] Update the Updater? (CC to Declude.Junkmail)
Hi Doug, Thanks for your information about this. We've found a simply solution for this, so that nobody must update his DecludeUpdater. Scott now has changed the order in the version.txt file from beta-release to release-beta so if you start again the update-process it should put the right version of declude.exe in the imail-directory. (be sure to delete first the folder 164 in the subfolder beta so that the updater knows that he has not allready updated to Beta 1.64) For all who don't know what's the Declude updater try it out! You can download this free tool from http://www.zcom.it/decludeupdater/decludeupdater.zip It can run both in gui (manual and for configuration) as in command line mode (scheduled). You can choose if you want to use the latest release or beta version of declude. The updater keep each version in a separate subdir so you can switch back whenever you want. After an successfull update you will be notified be an email. Scott keeps the version-file updodate on his website. Markus -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] On Behalf Of Doug McKee Sent: Friday, December 06, 2002 10:08 PM To: [EMAIL PROTECTED] Subject: [Declude.Virus] Update the Updater? Declude Beta updated to Version 160 That's the email I just got from my declude updater. It was set to beta. Is there an update for the updater? Thanks, Doug --- [This E-mail scanned for viruses by Declude Virus] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.