>From this morning on (09:00 am GMT+1) on we can see a lot of "unknown
viruses"

As this messages contains from one to many recipients there are comming back
a lot of NDR's from our warning messages. (Scott: you know we can not SKIPIF
unknown virus)
So at the momen I've disabled all warning messages on our server.

Looking at the messages there are often file attachments (pif, scr xls.zip
...)
Here's a sample content of the body:

Note that "HTWM", "htwm.de" in this case is part of the forged sender. It is
different in practically every infected message.
The same for "INDEPENDENT" and "www.independent.it" - in this case the
recipients Domain.


=========================================================
This mail was generated automatically.
More info about --HTWM-- under: http://www.htwm.de

-------
Occured_Errors:

26.186.253.126_does_not_like_sender.
# 547: mailbox_unavailable
# 158: This_account_has_been_disabled_[#206].
# 373: Remote_host_said:_Requested_action_not_taken
# 516: MAILBOX NOT FOUND

End
-------

The corrected mail is attached.

Auto_Mail.System: [htwm]


*-*-* Attachment: No Virus found
*-*-* INDEPENDENT- Anti_Virus Service
*-*-* http://www.independent.it
=========================================================


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to