I've been trying to set up rules to stop or at least filter/monitor email 
that has double extensions. For example the recent W32Badtrans virus which 
has the double extension with either .scr or .pif. and the W32.Goner.1@mm 
virus that has .scr.
How would I set up rules to scan the email body for attachments with double 
extensions (e.g. "file_name.doc.scr") and if it finds a match either Kill 
it or send someplace where it can be viewed? I've tried what the KB 
instructed but couldn't get it to work correctly.
This is what I had in the rules
B~name=".*\.exe":NUL
Any help or direction would be appreciated.
Thanks!

Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Reply via email to