I am running the latest beta 1.78.
I have the following in my virus.cfg file:

BANEXT          scr
BANEXT          pif
BANEXT          bat
BANEXT          exe

DELETEVIRUSES   ON

Yet I am still seeing e-mails with .PIF extensions being held in the virus
subfolder.  I'm concerned that these are making it this far. Shouldn't these
just be deleted?

This is a header from one such held e-mail:
Received: from prudentialrand.com [64.115.120.37] by mail.prudentialrand.com
with ESMTP
  (SMTPD32-7.15) id A3981BD00DE; Mon, 01 Mar 2004 10:15:36 -0500
From: [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Subject: Re: My details
Date: Mon, 1 Mar 2004 09:50:37 -0500
MIME-Version: 1.0
Content-Type: multipart/mixed;
        boundary="----=_NextPart_000_0003_000014FE.00000C4E"
X-Priority: 3
X-MSMail-Priority: Normal
Message-Id: <[EMAIL PROTECTED]>
X-Declude-Sender: [EMAIL PROTECTED] [64.115.120.37]
X-Declude-Spoolname: D539801bd00de78ce.SMD
X-Note: This E-mail was scanned by Declude JunkMail (www.declude.com) for
spam.
X-Spam-Tests-Failed: None [0]
X-Country-Chain:
X-Note: This E-mail was sent from  ([64.115.120.37]).

This is a multi-part message in MIME format.

------=_NextPart_000_0003_000014FE.00000C4E
Content-Type: text/plain;
        charset="Windows-1252"
Content-Transfer-Encoding: 7bit

See the attached file for details.

------=_NextPart_000_0003_000014FE.00000C4E
Content-Type: application/octet-stream;
        name="my_details.pif"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
        filename="my_details.pif"

---
[This E-mail scanned for viruses by Declude Virus]

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to