I've been trying to set up rules to stop or at least filter/monitor email that has double extensions. For example the recent W32Badtrans virus which has the double extension with either .scr or .pif. and the W32.Goner.1@mm virus that has .scr. How would I set up rules to scan the email body for attachments with double extensions (e.g. "file_name.doc.scr") and if it finds a match either Kill it or send someplace where it can be viewed? I've tried what the KB instructed but couldn't get it to work correctly. This is what I had in the rules B~name=".*\.exe":NUL Any help or direction would be appreciated. Thanks!
Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
