R. Scott Perry wrote:
>> Running McAfee WebShield 4.5 MR1a on a mailrelay before my mailserver
>> (with Declude)
>> with with Scan engine version 4.3.20 DAT version 4.3.4332 and it's
>> detecting W32/[EMAIL PROTECTED]
>
> Is it detecting the one with "Dear user  of your_domain.com e-mail
> server gateway..." (or similar text)?  Is it detecting them in an
> encrypted
> file?  It may be that the virus is spreading in non-encrypted .ZIP
> files as well.

Sorry, I'm at home at the moment.
This is the (edited) message send by Webshield:

An email from <[EMAIL PROTECTED]>, addressed to <[EMAIL PROTECTED]> ,
with subject E-mail account disabling warning. was infected with the virus
W32/[EMAIL PROTECTED] in attachment unknown. The infected attachment has been
cleaned and quarantined.(from MAILRELAY IP 192.87.68.214 user SYSTEM running
WebShield 4.5 MR1a '_')

I forgot to mention that I update the dat-files every 2 hours with the daily
super-dat files (SDATDAILY.EXE)
These dat-files are updated several times each day when seemed needed by NAI

Erminio

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to