----- Original Message ----- Since we run SAV and greylisting, the senders are verified and the sending IPs are re-trying, meaning they are probably legit MTAs. Is anybody else seeing a lot of Bagle.?? and almost nothing of anything else?
The majority of viruses that we are seeing are a mix of mytob and bagle. Overall our virus numbers are way down over a year or two ago. As for greylisted IP's resending, we are beginning to see a significant increase in the number of infected/trojaned subscriber hosts resending. Enough so that we have moved greylisting a few notches lower in our testing order. Anyone care to share the domains that you SAV? We have kept our pretty short thus far (hotmail.com and a couple of common national ISPs) but I have been thinking we might get more bang for our buck if we expanded ours. -NB