Koozali.org: home of the SME Server

Flooded with virus emails

Offline bosco555

  • *****
  • 152
  • +0/-0
Flooded with virus emails
« on: May 09, 2005, 09:28:43 AM »
Hi All,

I am being flooded with virus e-mails, the antivirus stops them, but then it keeps in quarantine for a period of 10 days.  the server crawls and I have to reboot it frequently. Where is this quarantine situated, so that I can delete the contents or is there a way to delete these emails upon arrival??

Thanks and regards

GB


Offline bosco555

  • *****
  • 152
  • +0/-0
Flooded with virus emails
« Reply #2 on: May 09, 2005, 09:52:47 AM »
thanks a million, Just what the Doc ordered.
Thanks also to everyone who contributes to all this,

best regards to all

GB

Offline bosco555

  • *****
  • 152
  • +0/-0
Doomsday
« Reply #3 on: May 10, 2005, 10:54:59 AM »
Hi All,

well I have tried that, but to no avail, the server is crawling to a standstill.  I need a couple of clarifications if you guys don't mind please:

1) Do I have to install spamassassin before the antivirus?

2) I have to save user's emails, where are they kept? (/var/spool...????I dunno)

3) In case of virus infection, (in this case sober worm), how do I get rid of the virus?

I am sorry if these seem like stupid questions to you, but hey, I need to know

Thanks again and regards to all

GB

Offline raem

  • *
  • 3,972
  • +4/-0
Re: Doomsday
« Reply #4 on: May 10, 2005, 11:40:01 AM »
bosco555

> well I have tried that....

What do you think we are, mind readers, what on earth is "that" !


> 1) Do I have to install spamassassin before the antivirus?

either one first is OK


> 2) I have to save user's emails, where are they kept? (/var/spool...????I dunno)

/home/e-smith/files/users/username/Maildir


> 3) In case of virus infection, (in this case sober worm), how do I get rid of the virus?

Well that would be on your Windows workstations, so you would run a virus scan using AVG, NAV or whatever you have (on all the workstations connected to your LAN).
...

Offline bosco555

  • *****
  • 152
  • +0/-0
Flooded with virus emails
« Reply #5 on: May 10, 2005, 11:50:15 AM »
Hi Ray,

hehehehe, sorry, had a terrible day, what I meant is that I tried installing your howto on deleteing email with virus attached and by the way, thanks heaps for all your hard work, I surely appreciate it.  Anyway, from the log I have the sober.zip worm.  I have prepared another server at home now and busy doing all the virus/spam howtos so that it will be ready for tomorrow.

Thanks heaps again for all the help in this forum, and greetings from Perth WA

regards

GB

Offline bosco555

  • *****
  • 152
  • +0/-0
Flooded with virus emails
« Reply #6 on: May 12, 2005, 08:17:05 AM »
The antivirus, spamassassin etc. posed a real burden on the old server, so I upgraded it.  New motherboard, 1GB ram, 2800AMD, and it has worked wonders.  Now, it just cuises.

Thanks again to all

regards

GB