Michael, ok, I was verifying that my IMGate "content reject" was really caused by body_check, and not header checks, voila the proof, from pflogsumm report today: cleanup body 5 Content-Type: application/octet-stream; name="dwarf4you.exe"; from=<> to=<lconrad@go2france.com> These 5 are being sent from the avcheck machine with the virus attached, rather than just the headers to the virus sender. Len