>From this morning on (09:00 am GMT+1) on we can see a lot of "unknown viruses"
As this messages contains from one to many recipients there are comming back a lot of NDR's from our warning messages. (Scott: you know we can not SKIPIF unknown virus) So at the momen I've disabled all warning messages on our server. Looking at the messages there are often file attachments (pif, scr xls.zip ...) Here's a sample content of the body: Note that "HTWM", "htwm.de" in this case is part of the forged sender. It is different in practically every infected message. The same for "INDEPENDENT" and "www.independent.it" - in this case the recipients Domain. ========================================================= This mail was generated automatically. More info about --HTWM-- under: http://www.htwm.de ------- Occured_Errors: 26.186.253.126_does_not_like_sender. # 547: mailbox_unavailable # 158: This_account_has_been_disabled_[#206]. # 373: Remote_host_said:_Requested_action_not_taken # 516: MAILBOX NOT FOUND End ------- The corrected mail is attached. Auto_Mail.System: [htwm] *-*-* Attachment: No Virus found *-*-* INDEPENDENT- Anti_Virus Service *-*-* http://www.independent.it ========================================================= --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.
