Hi: The BADTRANS virus has uncovered a few shortcomings that we could improve with Declude Virus.
I am enclosing my current SENDER.EML file. The BADTRANS virus uses different "FROM:" date in the message envelope (from the SMTP conversation) vs. what's in the SMTP "From:" headers. I've had several people who seemingly got mail from themselves (e.g., the FROM in the envelope was my customer, so was the TO.) However, in EACH case, the SMTP "From:" header contained a different person's email address. Furthermore, it was confusing, because the %ALLRECIPS% seems to show BOTH the original recipient AND the ultimate recipient - something that my clients do NOT wish to publish. Thus - I have the following suggestions: a) if SENDER and RECIPIENT are one and the same - don't send TWO notifications. Suppress the SENDER notification. b) ALLRECIPS should only show the ORIGINAL recipient c) There should be a way to show the ENVELOPE "from" and the HEADER "from" - and there should be a way to notify EITHER - IF they are different! Best Regards Andy Schmidt H&M Systems Software, Inc. 600 East Crescent Avenue Suite 203 Upper Saddle River, NJ 07458-1846 Phone: +1 201 934-3414 x20 (Business) Fax: +1 201 934-9206 http://www.hm-software.com/ -----Original Message----- From: [EMAIL PROTECTED] To: %MAILFROM% Subject: Our Virus Firewall has Rejected Your Email! Argos Networks' Virus Firewall has rejected an %INOROUT% message sent by %MAILFROM% to: %ALLRECIPS%. The message with the subject of "%SUBJECT%" carried a virus: File: "%VIRUSFILE%" Result: Found%VIRUSNAME% For more information see http://vil.mcafee.com/. Please note that many viri will send automated messages to every person in your address book, even without your knowledge. This is how they propagate themselves and it explains why you may not recall to ever having sent such a message. Other viri attach themselves to any email formatted in "HTML" format. In that case you have to resend your message in "PLAIN TEXT" format. Consult your email software on how to send messages in "PLAIN TEXT". If the virus was embedded in a document attachment, then try saving or exporting your orgininal document to a generic format that does not include macro code. E.g., instead of saving your documents in MS-WORDS format, save your documents in "RTF" format before attaching it to your email. This will exclude any hidden macro virus. Ultimately, you are advised to urgently install (or upgrade) a virus scanning software to identify the specific virus on your system and to avoid further complications. It may also be appropriate for you to notifiy other persons in your address book and warn them about possible infections by any past email originating from your PC. TRACKING INFORMATION Your Server: %REMOTEHOST% for %SENDERHOST% Message ID: %MSGID% Our Server: %LOCALHOST% for %RECIPHOST% Queue ID: %QUEUENAME% For security reasons, you cannot respond to this email directly. If you need to contact us, please compose a new message addressed to [EMAIL PROTECTED] Sincerely, Argos Networks http://www.ArgosWeb.net/ --- This E-mail came from the Declude.JunkMail mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.JunkMail". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com .
