Re: [Declude.Virus] MS05-16 Exploit

2005-05-31 Thread NIck Hayer
Title: Message Hi Andy, Colbeck, Andrew wrote: Declude Virus will *not* detect abuse of MS05-16 with the Declude CLSID vulnerability detector. They are entirely different animals, which happen to have CLSID at their heart. You are sure up to date with this stuff!

Re: [Declude.Virus] Second Scanner

2005-06-06 Thread NIck Hayer
I am not real clear on this thread - but if it has to do with clamd - it w/Declude no question has a problem in Windows. I have stopped using it - it may take a week or even a month but it will crash... -Nick Terry Fritts wrote: I can't find anything in the event or application logs

Re: [Declude.Virus] what does this mean in the virus log file?

2005-06-06 Thread NIck Hayer
Vulnerability flags = 76 Thanks! -Nick --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at http://www.mail-archive.com.

Re: [Declude.Virus] what does this mean in the virus log file?

2005-06-07 Thread NIck Hayer
- Original Message - From: NIck Hayer [EMAIL PROTECTED] To: Declude.Virus@declude.com Sent: Monday, June 06, 2005 5:51 PM Subject: Re: [Declude.Virus] what does this mean in the virus log file? Vulnerability flags = 76 Thanks! -Nick --- This E-mail came from the Declude.Virus mailing list

Re: [Declude.Virus] Patch Tuesday and graphic images

2005-07-12 Thread Nick Hayer
Thanks Andrew! -Nick Colbeck, Andrew wrote: Today is Microsoft Patch Tuesday for July 2005. One of the bulletins is: http://www.microsoft.com/technet/security/Bulletin/MS05-036.mspx Which fails to indicate which graphics formats are affected by this vulnerability. It does mention that

Re: [Declude.Virus] Seemingly bad virus this morning

2005-09-12 Thread Nick Hayer
Hi Matt - Matt wrote: I was wrong about what was detecting it first...it was F-Prot. I just figured out that my McAfee update script is no longer working. Does anyone have a newer link to the daily DAT's than http://download.nai.com/products/mcafee-avert/daily_dats/DailyDAT.zip.

Re: [Declude.Virus] Declude Beta 3.0.4.4 Posted

2005-09-23 Thread Nick Hayer
Hi Andy, Andy Schmidt wrote: Thanks Bill. I had gotten the impression as if everyone with dual-processor system was reporting this and that people were still seeing it with the latest version. If you will would you let me know more about this issue. I haven't been following exactly so I

Re: [Declude.Virus] Declude Beta 3.0.4.4 Posted

2005-09-23 Thread Nick Hayer
Andy Schmidt wrote: Hi Nick: I'm only repeating what I'm told - I don't have factual information on my own. chuckle chuckle chuckle. you are very funny at times! Declude is supposed to check the /proc folder and ONLY go to sleep (for 30 seconds), if the folder contains no messages. On

[Declude.Virus] error line in log file

2005-09-26 Thread Nick Hayer
Hi - would anyone know what Couldn't create map1 would mean in the Declude virus log file? Thanks! -Nick --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.Virus.The archives can be found at

Re: [Declude.Virus] 3.0.5.10

2005-10-24 Thread Nick Hayer
Thanks David! -Nick David Barker wrote: 3.0.5.10 - Change was made to reset the winsock when the \proc directory reached 0 messages 3.0.5.11 - Change was made to reset the winsock when the \proc directory reached 0 messages and threads in the \work had completed processing I will update

Re: [Declude.Virus] Second scanner

2005-11-04 Thread Nick Hayer
Hi David, Mcafee is one - the command line scanner is only $11 - if you can find a vendor to sell it to you. ClamAV is another choice and its free. I use it w/clamd. http://www.sosdg.org/clamav-win32/index.php I use all three.. -Nick David Dodell wrote: After many years of using Virus

Re: [Declude.Virus] Second scanner

2005-11-04 Thread Nick Hayer
Matt has done this - it is in the Archives - -Nick John Carter wrote: This raises a question(s): Has anyone done any real testing of which AVs (in relation to Declude) perform the best, use the least resources, what is the best scanning order, and how many to use (how many is too many

Re: [Declude.Virus] Declude 3.0.5.18 Posted

2005-11-05 Thread Nick Hayer
Thanks for the info David! -Nick David Barker wrote: Declude 3.0.5.18 ALL - Fixed un-defined variables causing intermittent stop/start with the decludeproc service. JM - Fixed SmarterMail incoming email recipient domain aliases. AV - Fixed un-defined variables, causing incorrect Virus

Re: [Declude.Virus] Hardware Issue

2005-12-26 Thread Nick Hayer
Hi David, Would you kindly elaborate on the ramifications of such a failure? I am interested in when its fixed but more importantly its ramifications. Are you saying that a hardware/network/software issue on your end can in anyway disarm/defuse/alter/change the way Declude functions on its

Re: [Declude.Virus] [Declude.JunkMail] Declude Hardware Issue

2005-12-27 Thread Nick Hayer
David, David Franco-Rocha wrote: B) Your software is NEVER downgraded for any reason, either automatically or otherwise hmm - would you kindly shut down your key server for awhile and monitor the list in the meantime? -Nick We have had a few reports from customers who

Re: [Declude.Virus] Feature request: DELETEVIRUSNAME

2006-01-27 Thread Nick Hayer
Don Brown wrote: #1 "The main benefit is that it cuts down on the amount of messages virus scanned thus saving resources." correct. #2 "It still gets virus scanned." only those emails that get past the junkmail scanning. If you do not delete any junkmail then there is no

Re: [Declude.Virus] Encoded viruses...worried topic change - to Bill Landry

2006-02-01 Thread Nick Hayer
With these, you don't need to run CygWin ports or the Microsoft Windows Services for Unix. Bill Landry put the Declude and Message Sniffer mailing list users on to these a long time ago, and I'm still grateful to him. Well I am grateful and frustrated at times- because it can do so

Re: [Declude.Virus] Encoded viruses...worried topic change - to Bill Landry

2006-02-01 Thread Nick Hayer
the tools can be used and maybe will inspire others to create some cool scripts that they would be willing to share with others on the list. Bill - Original Message - From: Nick Hayer Well I am grateful and frustrated at times- because it can do so much and I

Re: [Declude.Virus] Updates from Declude

2006-03-08 Thread Nick Hayer
David Barker wrote: The next release of Declude which is currently being tested and soon to be released ahh David - wanna share? What will the new ver have to offer? :) -Nick David B www.declude.com From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] On Behalf Of

Re: [Declude.Virus] F-Prot Switches

2006-03-28 Thread Nick Hayer
Hi Mark, Mark Reimer wrote: After seeing Matt's response I'm curious what other users are using for their F-prot switches. here are mine: SCANFILE1e:\Progra~1\FSI\F-Prot\fpcmd.exe /ARCHIVE=5 /DUMB /NOBOOT /NOMEM /PACKED /SERVER /SILENT /TYPE /REPORT=report.txt VIRUSCODE13

[Declude.Virus] url file extensions

2006-04-11 Thread Nick Hayer
I been asked to remove the block I have on these - and since I have forgotten why I am blocking them Is there a valid reason to block these? Thanks in advance -Nick --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and

Re: [Declude.Virus] url file extensions

2006-04-11 Thread Nick Hayer
eServices For You "Seek, and ye shall find!" -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] On Behalf Of Nick Hayer Sent: Tuesday, April 11, 2006 12:10 PM To: Declude.Virus@declude.com Subject: [Declude.Virus] url file extensio

Re: [Declude.Virus] url file extensions

2006-04-11 Thread Nick Hayer
PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Nick Hayer Sent: Tuesday, April 11, 2006 12:10 PM To: Declude.Virus@declude.com Subject: [Declude.Virus] url file extensions I been asked to remove the block I have on these - and since I have forgotten why I am blocking them Is there a valid

Re: [Declude.Virus] url file extensions

2006-04-11 Thread Nick Hayer
--Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] On Behalf Of Nick Hayer Sent: Tuesday, April 11, 2006 1:09 PM To: Declude.Virus@declude.com Subject: Re: [Declude.Virus] url file extensions Hi John, I was referring to file attachments that had a .url extensio

Re: [Declude.Virus] url file extensions

2006-04-11 Thread Nick Hayer
gateways for about a year now and thus far have had no problems with it. Bill - Original Message - From: Nick Hayer [EMAIL PROTECTED] To: Declude.Virus@declude.com Sent: Tuesday, April 11, 2006 1:30 PM Subject: Re: [Declude.Virus] url file extensions Bill, Will you kindly elaborate

Re: [Declude.Virus] 4.2.3 Built-in scanner slight off topic reply

2006-07-12 Thread Nick Hayer
I just switched to 4x and noticed in the logs that scan times are recorded - here are some sample scan times against the same email - 2062ms Clamscan 468ms Mcafee scan.exe 171ms fprot These relative scan time proportional differences appear to remain the same against other emails.

[Declude.Virus] ClamAV

2006-07-17 Thread Nick Hayer
I have noticed now with 4x that if ClamAv is the first scanner it fails - it cannot find the file to scan. However it it is moved to the 2 'hole' or 3 'hole' - identical config otherwise - it works like a charm. Does any one else see this anomolie? -Nick --- This E-mail came from the

Re: [Declude.Virus] AVG Updates

2006-09-12 Thread Nick Hayer
Mine is 9/8. -Nick Mark Reimer wrote: What are the latest AVG updates that everyone has? Im worried that my AVG stopped updating for some reason. Or is it from Declude moving all their stuff around? Mark Reimer IT Project Manager American CareSource 214-596-2464

Re: [Declude.Virus] Fw: A secret e-card has been sent fot you!!

2006-09-29 Thread Nick Hayer
Darrell ([EMAIL PROTECTED]) wrote: Pretty nice peice of social engineering below - how many of your users will click on this tomorrow :) Who can resist the temptation of a "secret" greeting card. I get quite a few of these - here is my postcard-phish.txt SKIPIFWEIGHT 26 REVDNS

Re: [Declude.Virus] ClamAV Exit codes

2006-09-29 Thread Nick Hayer
Failure I do believe, probably ClamD is not running? -Nick Markus Gufler wrote: Does anyone know what exit codes ClamAV has and what they mean? From 2006-09-27 06:50PM on I can see a huge number of Virus scanner 2 reports exit code of 2 ...in the virus-logfile. Markus --- This E-mail

Re: [Declude.Virus] RE: Differences in reporting of ClamAV And ClamWin.

2006-10-26 Thread Nick Hayer
Darrell ([EMAIL PROTECTED]) wrote: Also, for me to get the virus name I had to use the wrapper. fyi - The names are otherwise recorded in the clamd.log -Nick --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type

Re: [Declude.Virus] Release Update

2007-02-01 Thread Nick Hayer
Hi David, What will this release contain? -Nick David Barker wrote: We had scheduled a release for 31 January 2007, which we are delaying for some changes next date is Monday 5 February 2007 Thanks David Barker Director of Product Management Your Email security is our business 978.499.2933

Re: [Declude.Virus] Declude 4.3.40 Released

2007-03-12 Thread Nick Hayer
Thanks David -Nick David Barker wrote: FIX ZEROHOUR passing weight to SM when email WHITELISTED FIX Ignore Case checking in Imail Address book 2006 FIX Improved performance when OUTBOUNDSPAMSCANNING OFF FIX Updated CommTouch ZEROHOUR Dll FIX EXITSCANONVIRUSDETECT ON works

Re: [Declude.Virus] ClamAV 0.90.1-2 problems

2007-03-13 Thread Nick Hayer
Exit code of 2 means ClamAV had an error - Is clamd running? will clamdscan.exe file to be scanned work? eg no parameters? -Nick Gary Steiner wrote: Ever since I upgraded to ClamAV 0.90.1-2 (the SOSDG windows port), I've been unable to get it to work. The Declude log files show an error

[Declude.Virus] [Fwd: [clamav-announce] Problems with ClamAV/SOSDG For WIndows 0.90.1-1 and -2]

2007-03-13 Thread Nick Hayer
fyi - Original Message Subject: [clamav-announce] Problems with ClamAV/SOSDG For WIndows 0.90.1-1 and -2 Date: Tue, 13 Mar 2007 14:20:20 -0400 From: Bri Bruns [EMAIL PROTECTED] To: [EMAIL PROTECTED] Okay, been getting reports of people having problems with the

[Declude.Virus] [Fwd: [clamav-announce] ClamAV/SOSDG For Windows 0.90.1-3 Is Now Available]

2007-03-15 Thread Nick Hayer
fyi - Original Message Subject: [clamav-announce] ClamAV/SOSDG For Windows 0.90.1-3 Is Now Available Date: Wed, 14 Mar 2007 16:02:48 -0400 From: Bri Bruns [EMAIL PROTECTED] To: [EMAIL PROTECTED] Hello all, With help from various people, I've got a new build of

[Declude.Virus] [Fwd: [clamav-announce] ClamAV/SOSDG 0.90.2-1 has been released! (Security Fix)]

2007-04-13 Thread Nick Hayer
fyi - Original Message Subject: [clamav-announce] ClamAV/SOSDG 0.90.2-1 has been released! (Security Fix) Date: Fri, 13 Apr 2007 17:05:54 -0400 From: Brie Bruns [EMAIL PROTECTED] Organization: The Summit Open Source Development Group To: [EMAIL PROTECTED] Hello

RE: [Declude.Virus] Declude Virus inoperable for 13% of th year?

2009-06-03 Thread Nick Hayer
David - At times like this its OK to sigh these emails: David your pinata Barker :) -Nick From: David Barker dbar...@declude.com Sent: Wednesday, June 03, 2009 4:14 PM To: declude.virus@declude.com Subject: RE: [Declude.Virus] Declude Virus

RE: [Declude.Virus] ClamAV

2010-04-29 Thread Nick Hayer
Thanks Michael for the effort to 'splain! I appreciated it. Make sure you are using the sanesecurity sigs as well as the MSRBL's -Nick MadRiverAccess.com|Skywaves.com Tech Support US/Canada 877-873-6482 or International +1-802-229-6574 Emergency Support 24/7: supp...@skywaves.net General