Shortly after adding ClamAV to the Imail Server a few days ago, my system
started sending virus notices on Mytob (and so far, only Mytob) even though
I have SKIPIFFORGING in the sender.eml, recip.eml and postmaster.eml, plus I
have Mytob in the list of forging viruses in the virus.cfg. In the
I have also been experiencing this, for over a week. I'm only using
F-Prot, but have added the appropriate lines to eml and virus.cfg files
as John has. The only other difference is that I'm using SmarterMail.
Shayne
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL
I know this is a rookie question but
anyway:
Does BANnotify.eml file send the email with or
without the attachment/s?
Without the attachments.
Darrell
Check out http://www.invariantsystems.com for utilities for Declude And
Imail. IMail/Declude Overflow Queue Monitoring, SURBL/URI integration, MRTG
Integration, and Log Parsers.
Shayne:
I haven't heard anything from anyone else. To the existing SKIPIFFORGING, I
have added the following to sender, recip, and postmaster eml's. I know it
is just covering up the underlying problem, but a cure is a cure. Will let
you know if it helps.
SKIPIFVIRUSNAMEHAS Mytob
John
I also had to add the SKIPIFVIRUSNAMEHAS Mytob to my eml files.
- Original Message -
From: John Carter [EMAIL PROTECTED]
To: Declude.Virus@declude.com
Sent: Friday, April 15, 2005 2:53 PM
Subject: RE: [Declude.Virus] Skipifforging not working on Mytob
Shayne:
I haven't heard anything
I am getting lots of banned attachment notices and lots of bounces in the
last 90 minutes.
THANKFULLY, I am blocking zip files which contain executables otherwise
these would have all be delivered to users.
Any one have an idea of what this one is, it is kind of acting like Bagle.
John T
Hi,
Any particular subject/attachment name that we can recognize it by?
Also, for half a day I've seen lots of no subject and the attachmen of
Unknown Err. Seems as if Declude is choking on something here:
04/15/2005 16:43:42 Q275DA0790152A6BF Warning: file#=123456 (123456.EXE ...
)
04/15/2005
Looks like yesterday's RAR's coming in as ZIPs. And my F-Prot/ClamAV and
desktop Trend Micro still don't see anything!! Deleting them nevertheless.
John
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of John Tolmachoff
(Lists)
Sent: Friday, April 15,
You guys are all pretty funny with your "thankfully" stuff. Remember,
this is all just a collection of opinions. I have no issues, and
haven't for some time.
Anyway, I don't bounce messages for any tagged virus so I haven't been
having issues with Mytob causing backscatter since Declude
I've seen one sample in the last few minutes. It arrives as jokes.zip, and
www.virustotal.com describes the enclosed 123456.exe as:
This is a report processed by VirusTotal on 04/16/2005 at 00:11:32 (CET) after
scanning the file 123456.exe file.
Antivirus Version Update Result
AntiVir
11 matches
Mail list logo