OK, I now have only one rule:
Deny Rule:
Priority: 90
From contains:
To contains:
Subject contains:
Body contains:
Attachments: .vbs
Action: Copy & Deny
Mark with: xxx
Probability Increase: 0
Here is my config:
Instance ID
This is a string of six characters or less, should be the same for every server in your organisation (KS_IID). Farcom
Default action
This is the default action to be taken when one of the hard coded rules is matched (KS_DEFAULTACTION). 0 - Accept
Default probability increase
The default probability increase, only used if increase probability is selected for the default action (KS_DEFAULT_PROB_INC). 10%
Mark messages with a reason field?
Add KS_REASON item to an email if a rule is matched (KS_MARK). Yes
Reload configuration every hour?
(KS_RELOAD). Yes
Show statistics?
Log statistics under smtp.kSpam.* (KS_STATS). Yes
Minimum "From:" header length?
Minimum length of the From: header (KS_MIN_FROM_LENGTH). 2
Maximum numbers in sender's username?
Maximum number of integers in the sender's username (KS_MAX_FROM_INTS). 20
First character in "From:" header must not be a number?
(KS_FILTER_FROM_INT). No
Other forms to scan?
Forms other than Memo and Reply delimited by commas (KS_INTERESTING_FORMS).
Add recipients list to copied and denied messages?
Add KS_RECIPIENTS readers field to denied messages, username in email address must me included in the recipients username field in their person document. ( KS_RECIPIENTS). No
Copied mail database
Database to copy copied messages to, default is mailspam.nsf (KS_COPIED_DB). mailspam.nsf
Turn on debugging?
Create log in ks_debug.txt (KS_DEBUG). Yes
I do not see a ks_debug.txt file anywhere. Any ideas?
Thanks