I am running the latest beta 1.78. I have the following in my virus.cfg file:
BANEXT scr BANEXT pif BANEXT bat BANEXT exe DELETEVIRUSES ON Yet I am still seeing e-mails with .PIF extensions being held in the virus subfolder. I'm concerned that these are making it this far. Shouldn't these just be deleted? This is a header from one such held e-mail: Received: from prudentialrand.com [64.115.120.37] by mail.prudentialrand.com with ESMTP (SMTPD32-7.15) id A3981BD00DE; Mon, 01 Mar 2004 10:15:36 -0500 From: [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject: Re: My details Date: Mon, 1 Mar 2004 09:50:37 -0500 MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----=_NextPart_000_0003_000014FE.00000C4E" X-Priority: 3 X-MSMail-Priority: Normal Message-Id: <[EMAIL PROTECTED]> X-Declude-Sender: [EMAIL PROTECTED] [64.115.120.37] X-Declude-Spoolname: D539801bd00de78ce.SMD X-Note: This E-mail was scanned by Declude JunkMail (www.declude.com) for spam. X-Spam-Tests-Failed: None [0] X-Country-Chain: X-Note: This E-mail was sent from ([64.115.120.37]). This is a multi-part message in MIME format. ------=_NextPart_000_0003_000014FE.00000C4E Content-Type: text/plain; charset="Windows-1252" Content-Transfer-Encoding: 7bit See the attached file for details. ------=_NextPart_000_0003_000014FE.00000C4E Content-Type: application/octet-stream; name="my_details.pif" Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="my_details.pif" --- [This E-mail scanned for viruses by Declude Virus] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.