![]() |
| How to filter emails generated by w32.beagle.j |
|
jamie
HostMySite Sales Rep
![]()
|
By setting up filters in Web Messaging, you can actually filter the annoying messages generated by the Beagle.J virus (the ones warning you about your email account be 'disabling').
Here's how an IpSwitch Imail walkthrough on how to do so: (located at http://support.ipswitch.com/kb/IM-20040303-DF01.htm) NOTE: This walkthrough is given from the server-side point of view. When configuring the client-side webmail application you will not be able to follow step by step; simply setup your rules to match the ones described below. Question/Problem: How do I configure IMail to block the new Beagle.J virus? Answer/Solution: The virus transmits itself inside an encrypted (password protected) .zip file which AV applications currently cannot decode to scan the file contents. To trap the messages, create a rule that searches for the subjects used by the emails generated by the virus. It is recommended the rule be configured to forward the virus-infected emails to an account for review. Upon review, the headers of the infected messages will show the connecting IP in the 'Received' path. This IP can be blocked from connecting to the IMail server by adding it to the SMTP Control Access list. 1. Select the 'Inbound Rules' tab and click 'Add'. 2. In the 'Rules' dialog, select 'If the Subject' from the 'Select Rule' menu. Also, select 'Contains'. 3. In the 'Search Text' field type: e-mail account disabling warning 4. Click 'Add Condition' and then click 'Insert OR'. 5. In the 'Search Text' field, remove the text currently entered and type: e-mail account security warning 6. Click 'Add Condition' and then click 'Insert OR'. 7. In the 'Search Text' field, remove the text currently entered and type: email account utilization warning 8. Click 'Add Condition' and then click 'Insert OR'. 9. In the 'Search Text' field, remove the text currently entered and type: important notify about your e-mail account 10. Click 'Add Condition' and then click 'Insert OR'. 11. In the 'Search Text' field, remove the text currently entered and type: notify about using the e-mail account 12. Click 'Add Condition' and then click 'Insert OR'. 13. In the 'Search Text' field, remove the text currently entered and type: notify about your e-mail account utilization 14. Click 'Add Condition' and then click 'Insert OR'. 15. In the 'Search Text' field, remove the text currently entered and type: warning about your e-mail account 16. Click 'Add Condition' and then click 'OK'. 17. Select 'Forward' and in the 'Address:' field, enter the complete email address to which you want the emails forwarded. This can be an existing user account or you can create a new account just for the viruses. The rules engine will not create the account if it does not exist. 18. Click 'Apply'. More information on the virus can be found at the Symantec website:[url] http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.j@mm.html[/url] |
||||||||||||
|
|
|||||||||||||
| How to filter emails generated by w32.beagle.j |
|
||
|



