Is anyone getting on either of these lists getting slammed with <mailto:[EMAIL PROTECTED]>[EMAIL PROTECTED] virus?
Our customers are seeing Swen account for about 10% of the viruses (excluding vulnerabilities).
Out Symantec AV is set to email the administrator warnings.
Reading through the warnings, they're coming from everywhere outside of the us & canada.
Are you referring to the From: or return address ("[EMAIL PROTECTED]") or the country of the IP address (which is highly accurate)?
The weird part is they're only going at the email address I use for these boards which was created when I setup imail. I don't use that email for any other boards or lists.
Then it sounds like someone with IMail caught the Swen virus, and it's getting sent out to you.
IIRC, the return address of Swen is correct. So if you can find the return address (from an X-Declude-Sender: header or "MAIL FROM" in the IMail SMTP log file) you should find the person who was sending it to you.
-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask about our free 30-day evaluation.
--- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
--- This E-mail came from the Declude.JunkMail mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.JunkMail". The archives can be found at http://www.mail-archive.com.
