I'm using exim+exiscan-acl+clamav, with demime on, which would feed Clam with a directory containing orignal mail, decoded message (I think), and all attachments. Could it be that different FortNight variants connects to different URLS? That would make the pattern different too, right?
Diego d'Ambra wrote: Hmm, here Clam has detected several JS.FortNight.E, the mentioned IFRAME tag looks same as mine. Are you sure you let Clam have "a go" on the e-mail? JS.FortNight.E is not an attachment, just an IFRAME HTML tag. Best regards, Diego d'Ambra --------------------------------------------------------------------- To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]