Autor: Dennis Davis Data: Para: exim-users Assunto: Re: [Exim] MyDoom filtering?
>From: Richard Welty <rwelty@???> >Subject: Re: [Exim] MyDoom filtering?
>To: exim-users@???
>Date: Tue, 27 Jan 2004 11:07:13 -0500 (EST)
>
>rather than behaving reactively to these things, i suggest it's
>well worthwhile to install exiscan and clamav. the clamav folks got
>a signature out for this new festivity pretty quickly, and i've not
>been bothered by it much at all. the best part is that i didn't
>have to do anything except leave freshclam running to fetch the
>updated signatures.
Or, if you have a commercial virus detection engine available, use
that. We're running with exiscan + Sophos + the sophie daemon and
have been rejecting this virus since about 01:00AM GMT this morning
when the mail servers picked up a Sophos IDE file to detect this
virus...
>my rejectlog is currently showing 572 rejects for this thing over
>the past 11 hours.
...resulting in us having seen ~7300 copies on this virus so far
today. However, unless the numbers start climbing rapidly, I doubt
that it'll reach the same dizzy heights reached by the W32/Sobig-F
virus last August :-(