----- Original Message ----- From: "R. Scott Perry" <[EMAIL PROTECTED]>
> >Scott, attached is the raw source of this BOFRA.B message, it looks like > >HTML to me. In fact, when I scan the D*.SMD file from the command-line, > >TrendMicro identifies the file as "HTML_BOFRA.B" and ClamAV as > >"HTML.Mydoom.email-gen-1". > > What does the Declude Virus log file show for this E-mail? > > Declude Virus definitely should have sent the HTML segment to the virus > scanner (except if PRESCAN ON is being used). Oh, and we have PRESCAN OFF in our virus.cfg. Here is a sampling of other HTML messages that Declude Virus is tagging: Declude AntiVirus caught HTML_MYDOOM.AH Declude AntiVirus caught HTML/[EMAIL PROTECTED] Declude AntiVirus caught HTML/[EMAIL PROTECTED] Declude AntiVirus caught HTML_SUNFRAUD.B Declude AntiVirus caught HTML_BOFRA.B Note that even BOFRA is caught sometimes, but mostly it's not. Again, I can send you Q&D files for these caught and uncaught BOFRA messages, if that would help any. Bill --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.
