Release 4.50.9 : Re: Worm.VB-8 not detected by
filename or filetype
Dhawal Doshy
dhawal at netmagicsolutions.com
Wed Jan 18 17:12:38 GMT 2006
Dhawal Doshy wrote:
> Dhawal Doshy wrote:
>> Julian Field wrote:
>>> -----BEGIN PGP SIGNED MESSAGE-----
>>>
>>> I have just released 4.50.9 which will decode the UU-encoded file
>>> attached to these messages, so that the virus scanners should all
>>> catch it, filename traps will work on the .scr file inside the .bhx
>>> file, filetype traps will work on it too.
>>
>> Just successfully upgraded a couple of production servers..
>
> I notice this in the logs..
> Jan 18 20:54:00 mx1 MailScanner[13545]: Infected message
> 73CEF28ABDE.D9736 came from
>
> The IP address is blank :-(, i'll try and run this through the debug
> sometime later.
The debug mode didn't tell me anything (apart from the EOCD thingy)..
how do i track this problem?
Jan 18 22:40:53 mx2 MailScanner[21952]: Infected message
77CE7288647.0EFC0 came from <== this is blank
However the same thing works fine for spam
Jan 18 22:40:55 mx1 MailScanner[13710]: Message 57DC728AC5B.E055B from
58.20.176.23 (info at galaxy-wars.com) to netmagicsolutions.com is spam,
SpamAssassin (score=12.361, required 5, BAYES_99 4.00, DCC_CHECK 2.17,
DRUGS_ERECTILE 0.22, HTML_30_40 0.02, HTML_MESSAGE 0.00, MIME_HTML_ONLY
0.18, SARE_MILLIONSOF 0.32, URIBL_BLACK 4.00, URIBL_WS_SURBL 1.46)
- dhawal
More information about the MailScanner
mailing list