Scott, my list also longer then the list in the sender.eml file. You are
missing
Avril

I can't seem to find any indication that Avril is a forging virus.


Gibe

This appears to use the sender's E-mail address as the return address.


Hybris

This is indeed a forging virus. The files will be updated to reflect this.


Sefex

That one is a trojan that should get caught with the "Trojan" entry.


Swen.

This one appears to use the sender's E-mail address as the return address (although the From: header is forged).


Also you have Dumar in stead of Dumaru. Sophos does not know a Dumar virus
but does know of a Dumaru virus. Same for F-prot.

It is Dumaru -- but there's another AV company (Command?) that uses "Dumaro", so using "Dumar" catches them both. :)


Maybe a good idea to have these standard in the virus.cfg file and adapt the
*.eml files into using the line SKIPIFSENDER [Forged], that way all
maintenance is done at one place, no need to update multiple eml files, no
confusing the user with invalid e-mail addresses.

We're working on that (albeit slowly).



-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask about our free 30-day evaluation.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to