Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype

Dhawal Doshy dhawal at netmagicsolutions.com
Wed Jan 18 17:12:38 GMT 2006


Dhawal Doshy wrote:
> Dhawal Doshy wrote:
>> Julian Field wrote:
>>> -----BEGIN PGP SIGNED MESSAGE-----
>>>
>>> I have just released 4.50.9 which will decode the UU-encoded file  
>>> attached to these messages, so that the virus scanners should all  
>>> catch it, filename traps will work on the .scr file inside the .bhx  
>>> file, filetype traps will work on it too.
>>
>> Just successfully upgraded a couple of production servers..
> 
> I notice this in the logs..
> Jan 18 20:54:00 mx1 MailScanner[13545]: Infected message 
> 73CEF28ABDE.D9736 came from
> 
> The IP address is blank :-(, i'll try and run this through the debug 
> sometime later.

The debug mode didn't tell me anything (apart from the EOCD thingy).. 
how do i track this problem?

Jan 18 22:40:53 mx2 MailScanner[21952]: Infected message 
77CE7288647.0EFC0 came from <== this is blank

However the same thing works fine for spam
Jan 18 22:40:55 mx1 MailScanner[13710]: Message 57DC728AC5B.E055B from 
58.20.176.23 (info at galaxy-wars.com) to netmagicsolutions.com is spam, 
SpamAssassin (score=12.361, required 5, BAYES_99 4.00, DCC_CHECK 2.17, 
DRUGS_ERECTILE 0.22, HTML_30_40 0.02, HTML_MESSAGE 0.00, MIME_HTML_ONLY 
0.18, SARE_MILLIONSOF 0.32, URIBL_BLACK 4.00, URIBL_WS_SURBL 1.46)

- dhawal


More information about the MailScanner mailing list