Additional notes: Seems like F-Prot with Viruscode 8 is catching this for over an hour now. Mcafee does not.
As there are always (?) pif,scr,... attachments it will be catched also by banned extensions. (Do you send out bannotifies?) But I've seen also .xls.zip attachments hold as unknwon virus by f-prot. There are also other similar body parts written in german but with the same "error" part. ======================================================= ... 109.175.41.103_does_not_like_sender. % 499: Remote_host_said:_Requested_action_not_taken STOP mailer ======================================================= Seems like this new worm intends to create a little bit of confusion on user side. Markus --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.
