hi, gibe-f (variante 1- microsoft) is catched by ms but the second variante gibe-f is only tagged as {dangerous-content} sophos seems to be ok. $ LANG=C sweep -mime -archive Announcement.eml >>> Virus 'W32/Gibe-F' found in file Announcement.eml/axria.exe $ rpm -q mailscanner mailscanner-4.26.8-1 -- shrek-m