ATTN 24.45.168.164 (virus)

Posted by ZaZ 
ATTN 24.45.168.164 (virus)
Date: September 01, 2003 08:50PM
Posted by: ZaZ
If you recognize your ip can you pleaaaaaase do a virus scan?
I'm not 100% sure that this is the correct ip. But its probably from somewhere around new york.
And can all people who have me in their adressbook do a scan too please?
I know that it must be from someone of the gpx community because it says the messages were sent by:
gpxsat@blabla@wanadoo.nl <gpxsat@blabla@wanadoo.nl>
rhummerich@blabla@debitel.net <rhummerich@blabla@debitel.net>
gpxpatch@blabla@xs4all.nl <gpxpatch@blabla@xs4all.nl>
lauri2000@blabla@ifrance.com <lauri2000@blabla@ifrance.com>

etc... (of course not the blabla part)
The virus is W32.Sobig.F@mm.
I get 42 infected mails each hour and now i can't recieve any real mails.
Thanks in advance







I'd rather have a bottle in front of me than a frontal lobotomy
Re: ATTN 24.45.168.164 (virus)
Date: September 01, 2003 09:40PM
Posted by: Madman271
This is known worm issue since August (probably earlier). It first attach mail server then spread trojan codes to mail client. This is only a new varian from previous sobig worms.

If you never touch those attachments, your system safe. But ensure you check it with latest virus update for your anti-virus software. To stop this worm "bombing" your mail, use mail server which already has latest anti-virus update. free mail accounts such as in Yahoo or Hotmail doesn't provide good anti-virus to block sobig worm. Also consider using good spam-blocker (if you are webmaster) which detect incoming mail hits to get ride this worm.




In reality, doesn't matter who's right but most important is who's left.
Re: ATTN 24.45.168.164 (virus)
Date: September 01, 2003 09:51PM
Posted by: ZaZ
My system is clean and i don't use a free mail account.
I don't really want to use a spam filter because sometimes they filter out other messages too. I'm one of those proud users who almost never recieves spam, so if this virus thingy stops ZaZ is happy again :)
I'll send an angry letter to my ISP too, because they haven't updated their mailserver to block a virus from the stoneage.







I'd rather have a bottle in front of me than a frontal lobotomy
Re: ATTN 24.45.168.164 (virus)
Date: September 02, 2003 01:43AM
Posted by: Madman271
Maybe our system is clean. But perhaps other people has been infected and our e-mail has in their address book. That's why then we get tons of spam mails with "nice" TIF image. :)




In reality, doesn't matter who's right but most important is who's left.
Re: ATTN 24.45.168.164 (virus)
Date: September 02, 2003 01:02PM
Posted by: Todays_Horse
Ive been getting 'mail returned by postmaster' supposedly from me containg that virus. Ive not sent nothing and my PC is clean according to norton. I delete them. Happens every two days for some strange reason, but not today!




'The beak of Ayrton Senna's chicken is pulling ahead!' ~ Murray Walker
Re: ATTN 24.45.168.164 (virus)
Date: September 04, 2003 06:47AM
Posted by: bojan_tarticchio
@ Madman271

I'm using Yahoo mail, and it provides an excellent spam filtering; I'm also getting tons of sobig's every day, but they all end up in bulk folder, which means that those mails are obviously spam, if not dangerous. There's also a quick online virus scan available, just to scan suspicious mail, if you're not sure. Believe me, protection is much better than for average Outlook user. Infact, only virus which I got in 10 years is blaster, recently, which doesn't use mailing for spreading afterall.

@ Todays_Horse

Sobig scan address book on ifected machines and chose one address to send itself, and another to use as a fake origin address. In your case, virus used your address as a fake origin address, but it's not your PC that is infected obviously.



---------------------
Bojan Tarticchio
Re: ATTN 24.45.168.164 (virus)
Date: September 04, 2003 07:03AM
Posted by: Madman271
@Bojan:
That was my point. It should not put to bulk folder, because you can runs out your mail quota just in a day. If they use good anti-virus, such mails must be destroyed or bounced to sender. In the mail header also doesn't have info or indication wether your mails is clean or not.

PS:
I also have e-mail account in Yahoo. ;)




In reality, doesn't matter who's right but most important is who's left.
Sorry, only registered users may post in this forum.

Click here to login

Maintainer: mortal, stephan | Design: stephan, Lo2k | Moderatoren: mortal, TomMK, Noog, stephan | Downloads: Lo2k | Supported by: Atlassian Experts Berlin | Forum Rules | Policy