Page 2 of 2 FirstFirst 12
Results 11 to 18 of 18

Thread: hit hard with virus's and googles down.

  1. #11
    Junior Member
    Join Date
    Jan 2003
    Posts
    28
    I'm getting the same exact error. I thought maybe I was typing in bad strings, but even when I search for things I knew would work I still get the same error page. I guess I'll just have to temporarily use another search engine unfortunately.

  2. #12
    Senior Member RoadClosed's Avatar
    Join Date
    Jun 2003
    Posts
    3,834
    I don't know your system deftones12 but netshield is a file level scanner and it only works on the servers. Clients would need a local file level access scanner on each workstation. Netshield will ONLY catch a virus if it's local file system is accessed. So a client getting email off the internet or an Exchange file share will NOT access the local Netshield system and NOT be detected. If you use exchange the Netshield scanner will not be able to scan or access the information store EVEN if located on the same machine. Groupshield is necessary or a client scanner like VirusScan plugged into Outlook.
    West of House
    You are standing in an open field west of a white house, with a boarded front door.
    There is a small mailbox here.

  3. #13
    Senior Member deftones12's Avatar
    Join Date
    Jan 2003
    Location
    cali forn i a
    Posts
    333
    For all incoming email, gee-whiz, our email scanner at the gateway, grabs the emails and scans them, using netshield that our servers use to scan the servers and shares. So on the server pretty much our email scanner uses the netshield engine and dat's. Im just wondering why netshield isnt catching them. I have looked through the forums and on the internet the best i can without google and cant find anyone else to be having this problem. Currently so far the virus's that are getting throught are the latest doom variant (the spoofing email of the mail delievery subsystem, to many employees fall for that one :-/) and the bagle-ai, which has been getting through since like tuesday or wenesday i think and its really startin to frustrate me, netshield should be catching those. The client version of mcafee scanner catches them though and im gettin flooded with questions and calls saying why do i have a virus and why is this scanner saying i have a virus. The netshield on our server and the client scanners are using the same DAT file too, im not positive if its gee-whiz or not, dont see why it would be. The scan time allowed for each incoming email is set at 65000 milliseconds, should i make that a little longer?

  4. #14
    PHP/PostgreSQL guy
    Join Date
    Dec 2001
    Posts
    1,164
    I personally would disallow all incoming files period. Nothing blocked on the intranet, but as far as outside, hell no. These variants are getting smarter and smarter and I wouldn't trust anything coming inside my network. I can barely trust my users to not bring in floppies or USB drives, but since I have to give some of them some "privileges", I just have to be extra-wary. We have an inbound scanner on our email server and for me, I use sendmail into a chrooted directory.
    We the willing, led by the unknowing, have been doing the impossible for the ungrateful. We have done so much with so little for so long that we are now qualified to do just about anything with almost nothing.

  5. #15
    Senior Member RoadClosed's Avatar
    Join Date
    Jun 2003
    Posts
    3,834
    What is your email server?
    West of House
    You are standing in an open field west of a white house, with a boarded front door.
    There is a small mailbox here.

  6. #16
    Senior Member deftones12's Avatar
    Join Date
    Jan 2003
    Location
    cali forn i a
    Posts
    333
    no way the boss would allow that to happen. so far i mentioned disallowing .com .pif and other extentions that the worm uses but he's not to keen on doin it, i explained users have no reason to be sending those but he sais just wait for the scanner to pick 'em up eventually, which i dont know if it will happen soon since its been happenin since last week, so im kinda stuck on the blocking part. thats why im just tryin to figure out how in the hell i can get netshield to see those virus's. i've posted for help in the mcafee forum but no one has replied. well thanks for all the help im not sure if theres anything you guys can do or suggest. if you have anymore advice pleeeeaaaasssee send my way. i swear im gonna kill the author of that virus. it doesnt help that he released the source code either for more to come. congrats on your soon to come 1000th post vorlin. thanks to everyone.

  7. #17
    Senior Member
    Join Date
    Oct 2001
    Posts
    748
    Originally posted here by deftones12
    For all incoming email, gee-whiz, our email scanner at the gateway, grabs the emails and scans them, using netshield that our servers use to scan the servers and shares. So on the server pretty much our email scanner uses the netshield engine and dat's. Im just wondering why netshield isnt catching them. I have looked through the forums and on the internet the best i can without google and cant find anyone else to be having this problem. Currently so far the virus's that are getting throught are the latest doom variant (the spoofing email of the mail delievery subsystem, to many employees fall for that one :-/) and the bagle-ai, which has been getting through since like tuesday or wenesday i think and its really startin to frustrate me, netshield should be catching those. The client version of mcafee scanner catches them though and im gettin flooded with questions and calls saying why do i have a virus and why is this scanner saying i have a virus. The netshield on our server and the client scanners are using the same DAT file too, im not positive if its gee-whiz or not, dont see why it would be. The scan time allowed for each incoming email is set at 65000 milliseconds, should i make that a little longer?
    What version of the .dats are you running? You have to be running 4381 to be protected from the new mydoom. You need the 4381 to be protected from bagle.ak. They just came out today.

  8. #18
    Senior Member deftones12's Avatar
    Join Date
    Jan 2003
    Location
    cali forn i a
    Posts
    333
    yeah i've got 4381. it autoupdates automatically and it did it this morning. 2 of the servers abended after they updated im pretty sure. the i think like 2 previous dats even protect from the bagle-ai even, not sure about the doom. we use groupwise RoadClosed, we have a postoffice agent which transports emails outside (internet) and a local one that just does intercounty, both of them get scanned before the email reaches though with the Gee-Whiz program. So obviously gee-whiz isnt stopping them and its gettin through. We are planning on redoing the webserver though which hosts the gee-whiz and netshield, so maybe redoing it and reinstalling netshield should fix the problem? it wont be anytime soon though like hours or days.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •