> It shows that I'm running 1.76i1 but still I've found today messages on > hold with suspicious double extension attachments like .xls.pif. Also > pif is in my list of banned extensions.
I would do a test. Put both Virus and Hijack logs into DEBUG mode and then send an attachement to yourself. Just create a text file and then rename it to example.txt.pif. Then post the log snippets. Also, you might want to post the full D file of one that you suspect, or send off-list to Scott to double check. (The later is probably better.) John Tolmachoff MCSE CSSA Engineer/Consultant eServices For You www.eservicesforyou.com --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.