How to remove ILOVEYOU worm from mbox format files?

From: Richard Jackson <rjackson_at_portal.gmu.edu>
Date: Fri, 05 May 2000 05:32:13 -0400 (EDT)

Hello,

What are the current safe solutions to scan and remove the worm from
Digital UNIX mbox format files? I have over 60,000+ users with almost
50,000 inboxes alone on one DU box. We use Digital UNIX 4.0D,
sendmail, Qualcomm popper, University of Washington's IMAP4rev1, elm,
pine, mailx, Outlook, Netscape Communicator, Eudora, PC-Pine, etc. As
of 2am EDT May 5, 2000 we have at least a couple hundred inboxes with
the worm.

There seems to be many good solutions and suggestions on how to filter
the ILOVEYOU worm (e.g., via sendmail, procmail, and PostFix) and
remove it from Microsoft Window systems.

http://www.thepope.org/index.pl?node_id=140
NAI: http://download.mcafee.com/extrafiles/love-4.zip
Datafellows: http://www.datafellows.com/download-purchase/updates.html
TrendMicro: http://www.antivirus.com/download/pattern.asp
Sophos: http://www.sophos.com/downloads/ide/index.html#loveleta
F-secure:http://www.europe.f-secure.com/v-descs/love.htm
CERT: http://www.cert.org/advisories/CA-2000-04.html
etc.

I don't manage our Groupwise systems but we support several thousand
users with it. Does anyone have a safe solution to detect and remove
the worm from this environment once it is in the mailstore?

-- 
Regards,
Richard Jackson
Computer Center Lead Engineer,
Central Systems & Dept. UNIX Consulting
University Computing & Information Systems (UCIS)
George Mason University, Fairfax, Virginia
Received on Fri May 05 2000 - 09:34:42 NZST

This archive was generated by hypermail 2.4.0 : Wed Nov 08 2023 - 11:53:40 NZDT