Daragh Mc Grath daragh.ilug at eircom.net
Wed Nov 19 11:15:16 GMT 2003

Phil Deane wrote:

> Hi Folks
> It has been over 2 months now since this bloody virus starting sending emails 
> to people, and I am still getting up to 100 a day. I know this because I 
> installed spamassassin at the time, which is good at filtering out 
> spams.(Over 2000 in 2 months!!!, not including virus!)
> But these fecking things are not spams, and are getting through, on a dial up 
> modem it kills me to have to download 11Mb of email when I come home from 
> work, for maybe 100 real 2 k emails and the rest 154K virus'
> It must stop, it is driving me mad. I didn't want to us the likes of 
> mailfilter as then I dint get an option of what I delete, it just does it, 
> but it might be my only option.
> Advice anyone?


Unfortunately I think it's going to be a case of 'grin and bear it'. 
Virus / spam mails are part and parcel of daily internet life the now 
and we all have to deal with it, and it costs us all money. As an 
interesting aside, we implemented a virus filter on one of our 
production servers yesterday which produced some interesting figures:

 From ~3pm to midnight yesterday

We blocked

2466 W32/Dumaru.A at mm
1952 W32/Swen.A at mm
113  W32/Lentin.F at mm
81   W32/Klez.H at mm
28   W32/Mimail.C at mm
20   W32/Sobig.F at mm

Total:     4660 of 136,462 messages (3.41% of total)

Per hour:   518

 From Midnight to 8:30am today we blocked

238  W32/Dumaru.A at mm
269  W32/Swen.A at mm
8    W32/Lentin.F at mm
23   W32/Klez.H at mm
19   W32/Mimail.C at mm
11   W32/Sobig.F at mm

Total:    568 of 79,727 messages (0.7% of total)

Per Hour:  67

We assume between 9am and 3pm today we will block about 4000 more
messages. Time will tell.

But we have blocked over 2200 Swen messages at ~150k each which is a 
total saving of 330 Meg of disk space or bandwidth (depending if the 
message was to a local or remote account) Over our 10 mail servers, this 
amounts to over 3 Gig.

So, as you can see, that's a whole lot of time and a whole lot of money 
tied up in dealing with stuff like this


