R. Scott Perry wrote: >> Running McAfee WebShield 4.5 MR1a on a mailrelay before my mailserver >> (with Declude) >> with with Scan engine version 4.3.20 DAT version 4.3.4332 and it's >> detecting W32/[EMAIL PROTECTED] > > Is it detecting the one with "Dear user of your_domain.com e-mail > server gateway..." (or similar text)? Is it detecting them in an > encrypted > file? It may be that the virus is spreading in non-encrypted .ZIP > files as well.
Sorry, I'm at home at the moment. This is the (edited) message send by Webshield: An email from <[EMAIL PROTECTED]>, addressed to <[EMAIL PROTECTED]> , with subject E-mail account disabling warning. was infected with the virus W32/[EMAIL PROTECTED] in attachment unknown. The infected attachment has been cleaned and quarantined.(from MAILRELAY IP 192.87.68.214 user SYSTEM running WebShield 4.5 MR1a '_') I forgot to mention that I update the dat-files every 2 hours with the daily super-dat files (SDATDAILY.EXE) These dat-files are updated several times each day when seemed needed by NAI Erminio --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.
