SOWPub Small Business Forums  
 

Click Here to see the latest posts!

Ask any questions related to business / entrepreneurship / money-making / life
or share your success stories (and educational "failures")...

Sign up for the Hidden Business Ideas Letter Free edition, and receive a free report straight to your inbox: "Idea that works in a pandemic: Ordinary housewife makes $50,000 a month in her spare time, using a simple idea - and her driveway..."

NO BLATANT ADS PLEASE
Also, please no insults or personal attacks.
Feel free to link to your web site though at the end of your posts.

Stay up to date! Get email notifications or
get "new thread" feeds here

 

Go Back   SOWPub Small Business Forums > Main Category > Original SOWPub Forum Archive
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Poll: YFEBT2
Poll Options
YFEBT2

 
 
Thread Tools Search this Thread Display Modes
  #1  
Old August 20, 2003, 08:53 AM
Adam
 
Posts: n/a
Default Help! Virus/Worm Sending Me 600+ e-mails a day!!!

Help!

What should I do? I'm now getting about 12 e-mails a minute (and this went on all yesterday, but it was about 1 e-mail per minute!) that are from the virus/worm, code-named W32/Sobig.F-mm The e-mails have subject headers that say things like:

"Re: Thank you!"
or
"Re: My details"
or
"Wicked Screensaver"

With file attachments.

How do I get this thing to stop clogging my e-mail account??? I'm afraid that my ISP may shut me down for receiving too many e-mails!!!

Thanks,
Adam.
  #2  
Old August 20, 2003, 09:17 AM
Michael Ross (Aust, Qld)
 
Posts: n/a
Default Join the club

As well as those, the ones arriving in my email box also sometimes say, "approved."

The interesting thing though is that they are all going to one email address - at least all the one's I opened anyway (I have Pegasus Mail so I can open stuff like this without infection).

Only thing I can think of is: figure out WHO is the person who is infected who has your email address on their system (I assume this is how this virus/worm works - sending itself out to email address in your address book or whatever email address it finds, and maybe using From addresses you have too).

Which raises the point... if someone has had any dealings with [email protected] or anything remotely like that, then you may be infect with a computer virus. Granted, the from address could come from anywhere. But hey. It is worth a shot.

What to do. Add @yahoogroups.com to your filters. Move all incoming emails that have Thank You in their subject line. Create a filter to delete all Wicked Weasel emails. Creat filter to move emails with Approve in subject line. Five minutes of creating a few filters gives much peace.

Michael Ross


Not filters needed
  #3  
Old August 20, 2003, 10:32 AM
Dien Rice
 
Posts: n/a
Default It's affecting everybody. It looks like it's the work of the "Sobig" worm...

The "From" address on the email is not the real computer the email is coming from. It grabs that email address at random from places like email address books, and fakes it as the "From" email address.

Don't open the attachments!

I didn't receive any attachments with mine, as all my email is filtered through www.Spamcop.net - which automatically detects viruses and removes them from the email. It's a pretty good service....

You can read more about this virus at the link below.

- Dien Rice


Sobig worm returns
  #4  
Old August 20, 2003, 01:38 PM
Boyd Stone
 
Posts: n/a
Default Here's the weird way my computer started acting

Hi,

Yesterday afternoon while filling out a form at eLance my WinXP machine suddenly rebooted itself. It hadn't ever done that before, but I've had plenty of Windows machines that had, so I wasn't terribly concerned. As soon as I got back online I noticed that something on my machine was sending a lot of bytes off into the internet. I keep my wife's computer and my other computer well protected, but the one I was using yesterday is a fairly new one and I had unwisely failed to protect it.

As soon as I noticed that something was sending a lot of stuff off into the net (it wasn't very obvious that it was happening but I noticed because I'm very in tune with how my computers behave) I got offline and then I downloaded the install file for ZoneAlarm on another computer and copied onto my sick computer. Among other messages ZoneAlarm told me that DLLHOST.EXE was wanting to send to 209.244.0.3:DNS so I researched that at google groups, and heard about something called TrojanHunter ( http://www.misec.net/trojanhunter/ ) and I downloaded the evaluation version and ran it. It reported a possible trojan that seemed related to the dllhost message that ZoneAlarm gave. I'm in the process of trying to discover if it's really a trojan.

I wish I could spank people who write virii, worms and trojans....

Best,

- Boyd
  #5  
Old August 20, 2003, 03:24 PM
Boyd Stone
 
Posts: n/a
Default I had the Welchia worm (MSBLAST.D) [DNO]

dno
  #6  
Old August 21, 2003, 02:32 AM
Michael Ross (Aust, Qld)
 
Posts: n/a
Default Hope you took something for it :o) (DNO)

  #7  
Old August 21, 2003, 09:09 PM
K.L.
 
Posts: n/a
Default Not the Lawrence Welchia worm, I hope. (dno.)

> dno
..
  #8  
Old August 21, 2003, 10:53 PM
Dennis Bevers
 
Posts: n/a
Default Re: Maybe you need Welch-Ade (DNO-NM)

DNO-NM = Do Not Open - No Message inside. all the contents are in the subject line.

Dennis Bevers
  #9  
Old August 22, 2003, 07:27 AM
K.L.
 
Posts: n/a
Default Is that the stuff they use for sour grapes? (dno.)

> DNO-NM = Do Not Open - No Message inside.
> all the contents are in the subject line.

> Dennis Bevers
..
  #10  
Old August 21, 2003, 08:35 AM
Oliver Peters
 
Posts: n/a
Default Tool to remove Sobig.F worm

F-Secure provides a free special tool to disinfect the Sobig.F
worm. The tool and disinfection instructions are available on
their ftp site:

ftp://ftp.f-secure.com/anti-virus/tools/f-sobig.zip
or
ftp://ftp.f-secure.com/anti-virus/tools/f-sobig.txt
+
ftp://ftp.f-secure.com/anti-virus/tools/f-sobig.exe

Hope that helps

Oliver Peters


f-sobig.zip file
 


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is On
Forum Jump

Other recent posts on the forum...


Seeds of Wisdom Publishing (front page) | Seeds of Wisdom Business forum | Seeds of Wisdom Original Business Forum (Archive) | Hidden Unusual Business Ideas Newsletter | Hotsheet Profits | Persuade via Remote Influence | Affia Band | The Entrepreneur's Hotsheet | The SeedZine (Entrepreneurial Ezine)

Get the report on Harvey Brody's Answers to a Question-Oriented-Person


All times are GMT -4. The time now is 01:51 PM.


Powered by vBulletin Version 3.6.0
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.