Message Sniffer has rules in place for this (about 30+ of them). We've also lifted the delay restriction on the demo license temporarily so that ANYONE can get this protection by running the demo license (sniffer2.snf) with Declude Junkmail. BE SURE TO DOWNLOAD THE LATEST VERSION OF THE RULEBASE -
http://www.sortmonster.com/MessageSniffer/Try-It.html I am about to take off the group differentiation temporarily so that Declude can be set up to test for the specific rule group result for malware under the demo license. (We will keep the restrictions off of the demo license (sniffer2.snf) until the biggest problems with Sobig are over.) That result code for the malware rule group is: 55. USE CAUTION! We _think_ we've got good filters in place for all variants of sobig.f, however we have seen minor changes showing up and nothing is perfect. We do seem to be catching almost all of it though... Hope this helps, _M |-----Original Message----- |From: [EMAIL PROTECTED] |[mailto:[EMAIL PROTECTED] On Behalf Of junk mail |Sent: Friday, August 22, 2003 12:48 PM |To: [EMAIL PROTECTED] |Subject: Re: [Declude.JunkMail] OT: Declude notification and |SoBig assault. | | |We are only running Declude JunkMail is anyone setting up any |rules to filter out the SoBig virus other than using Declud |virus software. | |Thanks, |Dom | | |--- |[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.JunkMail mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.JunkMail". The archives can be found at http://www.mail-archive.com. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.JunkMail mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.JunkMail". The archives can be found at http://www.mail-archive.com.
