Update your virus definitions!!

Remember that virus that went around a while ago, when I complained about getting a lot of e-mails containing the virus? Well today I received well over 100 e-mails with the subjects 'Re: Details', 'Re: Approved', 'Re: Your Details', 'Re: My Details', and every other variation under the sun from someone who's clearly infected with this virus and has a huge e-mail address book for the virus to play with.

Among the other addresses in this person's address book are many users of this site, which leads me to believe that it's someone here. So please can everyone make sure that they have up-to-date virus checking enabled on their machines and that they remove my e-mail address from their address book? For someone like me who's still using a 56k modem it just destroys my internet connection to have to receive all this pointless crap every day.

>
5,276 views 22 replies
Reply #1 Top
It has to be someone from here, I only use this email for user contact through this site...I just checked my email 10 minutes ago and got bombarded by over 50 emails all infected with w32.sobig.f@mm >

Somebody here has me in their address book

If they keep coming in I guess I'll just delete that account...what a pain in the arse.
Reply #2 Top
I had a few rogue e-mails today but I used Mailwasher to bounce them
Reply #3 Top
I'm clean, nor do i have anyones address in my email account



Reply #4 Top

I got swamped with emails containing that virus today also. None of the 'from' addresses looked familiar, I suspect it's a spider collecting email addresses from sites.

Was quite a flood... I hope this goes away soon.

Reply #5 Top
I have also got many of these emails today, one even fron ([email protected]) with the subject "Thank You", luckily BT intercepted them and I used mailwasher to delete and bounce them, but thanks for the warning



Powered by SkinBrowser!
Reply #6 Top
Don't click the link above it came out wrong, it shouls have said support @ stardock without spaces, sorry about that



Powered by SkinBrowser!
Reply #7 Top
The problem with 'bouncing back' these e-mails is that you're only adding to the problem by bouncing back a mail to someone who didn't send it in the first place. Probably about a third of the e-mails I received were 'returned' mails from people who obviously believed the 'from' address on the mail was the actual sender.

Just delete any mails you get and make absolutely sure that you're using current virus definitions.
Reply #8 Top
Here's the BBC's take: http://news.bbc.co.uk/1/hi/technology/3164861.stm
Reply #9 Top
I got just one, but it says I send an e-mail to that address with a virus, look:

-----------------------
This e-mail is generated by the pop.familyvoice.com mail server to warn you that the e-mail
sent by [email protected] to [email protected] is infected with virus: Win32/Sobig.F@mm.

Please contact your system administrator for further information.

If you are the sender:
-------------------
The scanned e-mail has your address in the header field. Either your
computer is infected or someone's computer having your e-mail address in
the address book has been infected.

(Please note that some viruses are sending e-mails directly from your computer.
Our advise is to check your computer using an up-to-date antivirus product).

If you are the receiver:
---------------------
Please contact the sender: very probably he/she doesn't know he/she has a computer virus.

Actions taken for the infected files:
-------------------------------------


The infected file was saved to quarantine with name: 1061311352-RAV22458.
The file (part0002:thank_you.pif) attached to mail (with subject:Your details) sent by [email protected] to [email protected]
is infected with virus: Win32/Sobig.F@mm.
Cannot clean this file.
The file was successfully deleted by Family Voice AntiVirus.
------------------------
this is a copy of the e-mail header:

Received: from unknown (HELO JJ6CY21) (198.62.73.67)
by pop.familyvoice.com with SMTP; 19 Aug 2003 16:42:30 -0000


Registered version for 3 domain(s).
Running on host: pop.familyvoice.com

Scan engine 8.11 for i386.
Last update: Tue, 19 Aug 2003 03:32:18 -04
Scanning for 81518 malwares (viruses, trojans and worms).

Reply #10 Top
Not me, I don't even keep an address book, but I am also very security conscience anyway that no virus can get in.
And I just received this Virus Update:This update contains solution for the new virus W32.Nachi.A
and W32.Sobig.F.




Powered by SkinBrowser!
Reply #12 Top
I'm getting a bucketload of them aswell
Reply #13 Top
I've only four peoples emails whom I've had contact with from this site soooo.

NIS, NAV and SpamKiller 4 tend to keep things playing nice on my network, though my dumb ass-matic son Chris barrowed my laptop and turned everything off so he could download porn to it showing off for his friends and loaded it chalk full of crap... it isn't on the network for now and I am going to hoze the drive and restore a ghost of it from the server tonight. Finally got tired of messing with it. Sometimes the best place to start is the place you end up...


Reply #14 Top
Well today alone I have now had over 300 of these mails, and they're still coming in a constant stream. At last check, if I hadn't been deleting them as they came in my mailbox would have contained over 25Mb of these mails alone!

It's beyond a joke now...
Reply #15 Top
Thats bad grayhaze!I'm lucky so far(keeping fingers crossed)

IPlural,how old is he?And isnt that dumb ass-o-matic?
Reply #16 Top
I have gotten over 600 emails today, untill my mailbock started rejecting. I have blocked all of the offending subjects. But now none will be able to reight me with the subject "Details" or "Thanks You"
Reply #17 Top
Does anyone know if it is safe to store addresses in an online address book?
Reply #18 Top
Someone probably ran a site spyder and pulled the juice(email addies) from the links. Unless that isn't possible because of how T-Man has things setup. As far as it being someones address book, I dunno if that is a positive thing because of spyders and such...




Powered by SkinBrowser!
Reply #19 Top
I've posted a news story with links for removal of the virus, which I want everyone (no exceptions!) to read and act on immediately. Read it here: https://www.wincustomize.com/newsBoard.asp?ID=1876
Reply #20 Top
No

Nodding head yes

oh all right, shaking head no



Powered by SkinBrowser!
Reply #21 Top
nope, not an issue, my Outlook will not open attachment unless I force it to selectively. Sooo, nope...



ok fine?




Powered by SkinBrowser!
Reply #22 Top
Guys... this virus isn't just using the address book of an infected machine to send out the emails.

It ALSO uses the internet temp cache on the machine - so it will scan for emails within the temp files of recent web pages that the infected machine has visited.

This means that anyone with a website or visible public email address on the net is going to get even more mails sent to them.