----- Original Message ----- 
From: "R. Scott Perry" <[EMAIL PROTECTED]>

> >Scott, attached is the raw source of this BOFRA.B message, it looks like
> >HTML to me.  In fact, when I scan the D*.SMD file from the command-line,
> >TrendMicro identifies the file as "HTML_BOFRA.B" and ClamAV as
> >"HTML.Mydoom.email-gen-1".
>
> What does the Declude Virus log file show for this E-mail?
>
> Declude Virus definitely should have sent the HTML segment to the virus
> scanner (except if PRESCAN ON is being used).

Oh, and we have PRESCAN OFF in our virus.cfg.  Here is a sampling of other
HTML messages that Declude Virus is tagging:

Declude AntiVirus caught HTML_MYDOOM.AH
Declude AntiVirus caught HTML/[EMAIL PROTECTED]
Declude AntiVirus caught HTML/[EMAIL PROTECTED]
Declude AntiVirus caught HTML_SUNFRAUD.B
Declude AntiVirus caught HTML_BOFRA.B

Note that even BOFRA is caught sometimes, but mostly it's not.  Again, I can
send you Q&D files for these caught and uncaught BOFRA messages, if that
would help any.

Bill

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to