[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
Re: [APML] OT: Help with Virus info
Hello Brian
There is a good chance that you are not infected. There are two things
that the sobib.f virus does, which is the one that has the subject you
listed.
1) It sends out email using email address found on the infected
computer as the 'sender'. So, somewhere it has found your email address
on someones computer and it sent an email out that was infected.
Because the receiving system thinks it is you, it replied to your email
address.
2) It sends out 'fake' virus software response emails. There will be
an attachement that has the infected file in it. If your email was
caught by a legitimate virus package and a note sent to you I don't
think it would send the virus back.
Walter
Brian Larmay wrote:
>Hi, I havent been posting lately due to a possible vius that I may have.
>2 day s ago I was bombed by at least 200 virus emails with headers such as
>"your application", "your approved", "thank you", "Wicked Screensaver",
>etc., etc.
>
>Since then, the virus attacks have stopped, but now I get emails saying my
>mail is undeliverable which I havent even sent.
>
>I upgraded to AVG 7.0 antivirus and it cant find any virus in my OS.
>
>I recieved one email back which reads:
>
>
><snip>
>
>This is the Postfix program at host mail.messagingengine.com.
>
>I'm sorry to have to inform you that the message returned
>below could not be delivered to one or more destinations.
>
>For further assistance, please send mail to <postmaster>
>
>If you do so, please include this problem report. You can
>delete your own text from the message returned below.
>
>The Postfix program
>
><riceman@fastmail.fm>: host 10.202.2.150[10.202.2.150] said: 552 Common
>virus
> payload files .pif and .scr blocked (eg. W32/Sobig). To send this file,
> please zip it first (in reply to end of DATA command)
>
><snip>
>
>There is an attachment that came with it that reads: "Your application",
>with a file size of: 2.97 kb
>
>My assumption is that I am being used to deliver these viruses.
>
>Ive also scanned my OS with the Symantec W32.Sobig.E@mm removal tool and
>found nothing.
>
>Help!!
>
>Brian
>
>_______________________________________________
>Astro-Photo mailing list
>Astro-Photo@seds.org
>http://seds.org/mailman/listinfo/astro-photo
>
>
>
>
_______________________________________________
Astro-Photo mailing list
Astro-Photo@seds.org
http://seds.org/mailman/listinfo/astro-photo