Hi:

The BADTRANS virus has uncovered a few shortcomings that we could improve
with Declude Virus.

I am enclosing my current SENDER.EML file.

The BADTRANS virus uses different "FROM:" date in the message envelope (from
the SMTP conversation) vs. what's in the SMTP "From:" headers.  I've had
several people who seemingly got mail from themselves (e.g., the FROM in the
envelope was my customer, so was the TO.)   However, in EACH case, the SMTP
"From:" header contained a different person's email address.

Furthermore, it was confusing, because the %ALLRECIPS% seems to show BOTH
the original recipient AND the ultimate recipient - something that my
clients do NOT wish to publish.

Thus - I have the following suggestions:

a) if SENDER and RECIPIENT are one and the same - don't send TWO
notifications.  Suppress the SENDER notification.

b) ALLRECIPS should only show the ORIGINAL recipient

c) There should be a way to show the ENVELOPE "from" and the HEADER "from" -
and there should be a way to notify EITHER - IF they are different!

Best Regards
Andy Schmidt

H&M Systems Software, Inc.
600 East Crescent Avenue
Suite 203
Upper Saddle River, NJ 07458-1846

Phone:  +1 201 934-3414 x20 (Business)
Fax:    +1 201 934-9206

http://www.hm-software.com/


-----Original Message-----
From: [EMAIL PROTECTED]
To: %MAILFROM%
Subject: Our Virus Firewall has Rejected Your Email!

Argos Networks' Virus Firewall has rejected an %INOROUT% message sent by
%MAILFROM% to:

  %ALLRECIPS%.

The message with the subject of "%SUBJECT%" carried a virus:

  File:   "%VIRUSFILE%"
  Result: Found%VIRUSNAME%

For more information see http://vil.mcafee.com/.

Please note that many viri will send automated messages to every person in
your address book, even without your knowledge.  This is how they propagate
themselves and it explains why you may not recall to ever having sent such a
message.

Other viri attach themselves to any email formatted in "HTML" format.  In
that case you have to resend your message in "PLAIN TEXT" format.  Consult
your email software on how to send messages in "PLAIN TEXT".

If the virus was embedded in a document attachment, then try saving or
exporting your orgininal document to a generic format that does not include
macro code.  E.g., instead of saving your documents in MS-WORDS format, save
your documents in "RTF" format before attaching it to your email.  This will
exclude any hidden macro virus.

Ultimately, you are advised to urgently install (or upgrade) a virus
scanning software to identify the specific virus on your system and to avoid
further complications.  It may also be appropriate for you to notifiy other
persons in your address book and warn them about possible infections by any
past email originating from your PC.


TRACKING INFORMATION

  Your Server:   %REMOTEHOST% for %SENDERHOST%
  Message ID:    %MSGID%
  Our Server:    %LOCALHOST% for %RECIPHOST%
  Queue ID:      %QUEUENAME%

For security reasons, you cannot respond to this email directly.  If you
need to contact us, please compose a new message addressed to
[EMAIL PROTECTED]

Sincerely,
Argos Networks
http://www.ArgosWeb.net/

---

This E-mail came from the Declude.JunkMail mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.JunkMail".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .

Reply via email to