Search the web
Sign In
New User? Sign Up
exim-users · Exim MTA
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Want your group to be featured on the Yahoo! Groups website? Add a group photo to Flickr.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Re: [Exim] Mydoom and virus signature updates   Message List  
Reply | Forward Message #69819 of 85778 |
Kjetil Torgrim Homme wrote:

> [Alan J. Flavell]:
>
>>And has someone got a large shovel to get rid of these damned
>>Mydoom-variant nondelivery reports that are getting sent to our
>>postmaster address?
>
>
> I wish... but first I wish we had a working AV. I got my first copy of
> at 12:45 UTC, but Sophos didn't have an updated signature file until
> 16:31. and it still doesn't recognise some variants of it! (I just
> _assume_ ZIP files which contain files named "message.html [80
> more spaces].exe" are malware.)
>
> 9 hours and counting -- that's pretty bad, I think. I'd be interested
> to hear how fast Sophos' competitors issued new virus signatures.
> --
> Kjetil T.
>
>
> --
>
> ## List details at http://www.exim.org/mailman/listinfo/exim-users Exim
details at http://www.exim.org/ ##
>
>

Well, I know Mcafee's dailydats had it when we got hit at 10:00am local
time (UTC-6). ClamAv probably had it shortly also, but I don't know. I
haven't been hit with it yet. I just looked in my virusmails dir and I
have a few copies of Gibe, one of Bagle, and one of Netsky/SomeFool.

To date I don't have a MyDoom.o instance on the machine. As much as I
respect ClamAV I'm really thinking I'm going to put the mcafee unix
virusscan on the system again, to provide an extra layer of protection.



--
-- Dan

--

## List details at http://www.exim.org/mailman/listinfo/exim-users Exim details
at http://www.exim.org/ ##




Tue Jul 27, 2004 8:55 pm

dan@...
Send Email Send Email

Forward
Message #69819 of 85778 |
Expand Messages Author Sort by Date

... Well, I know Mcafee's dailydats had it when we got hit at 10:00am local time (UTC-6). ClamAv probably had it shortly also, but I don't know. I haven't been...
Dan Egli
dan@...
Send Email
Jul 27, 2004
9:00 pm

... ClamAV is calling it Mydoom.M, I think, rather than .o - we've been catching huge numbers of them with it since yesterday, but maybe you're not using a...
Stephen Gran
steve@...
Send Email
Jul 27, 2004
9:04 pm

I am getting them as Mydoom.M so far. I had to update my clamav since I was on a older version and the main.cvd was not updating correctly. Now that I am on...
lists
lists@...
Send Email
Jul 27, 2004
9:12 pm

[Try it again with the subscribe user this time] ... time (UTC-6). ClamAv probably had it shortly also, but I don't know. I haven't been hit with it yet. I...
Kevin Reed
listaccount@...
Send Email
Jul 27, 2004
9:20 pm

... we do this as well. ... replyto doesn't exist, bounces to mailer-daemon are blocked, but we allow postmaster. I'm not too worried about my own mailbox...
Kjetil Torgrim Homme
kjetilho@...
Send Email
Jul 28, 2004
4:25 am

... I should point out that I did get a response from Sophos yesterday, and they told me that these "executables" were just random noise, and harmless. I'm...
Kjetil Torgrim Homme
kjetilho@...
Send Email
Jul 28, 2004
4:12 am

... We are blocking based upon a number of issues, some of which were being done before the outbreak. o helo check on our domain.name A ton of them present...
Kevin W. Reed
hostmaster@...
Send Email
Jul 28, 2004
8:02 am
Advanced

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help