Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | virus in emails!!???

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Virgin Media Services > Virgin Media Internet Service > Webspace, E-Mail & Browsing Issues
Register FAQ Community Calendar

virus in emails!!???
Reply
 
Thread Tools
Old 05-09-2003, 10:18   #1
bigboab5
Inactive
 
Join Date: Jun 2003
Location: Glasgow
Services: V+, Extra Box, XL TV Service, XL Phone Service, 20mb Broadband
Posts: 215
bigboab5 is on a distinguished roadbigboab5 is on a distinguished road
virus in emails!!???

Ok guys, a wee question,

We have 5 email accounts, I have 4 and my wife 1. My email is clear. BUT. My wife keeps getting emails informing her of "Your message could not be delivered" or "underliverable mail" all from alleged Postmasters or Mail administrators (daemon, Telus, postmaster etc), this has been going on for just over a week. Each suspect email has the original attatchments and upon further inspection the virus has been removed by Norton, that virus being W32.Sobig.F@mm. The email is formatted like it is a returned email originally sent through her account. And i know the virus can do this but I am buggered if I can find it. I have looked with both the symantec removal tool and with norton anti virus(which is fully up to date!!). In each case it says we don't have it. So do we have the virus or not, or is this an email with the virus purporting to be sent from her addy and not really, but she is getting a lot of them. rough count about 50 or 60, maybe more. AND more importantly, i have not had one in any of my email accounts. strange eh!!!

edit - Just noticed, returns from Yahoo groups now!!

Oh and is there a way to discover if we were in fact the originator of the email??



Any thoughts?

bigboab5
bigboab5 is offline   Reply With Quote
Advertisement
Old 05-09-2003, 10:28   #2
Lord Nikon
Inactive
 
Join Date: Jun 2003
Location: NW UK
Posts: 3,546
Lord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze array
Lord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze array
http://securityresponse.symantec.com...obig.f@mm.html

Specifically this part :-

Quote:
Email spoofing
W32.Sobig.F@mm uses a technique known as "spoofing," by which the worm randomly selects an address it finds on an infected computer. The worm uses this address as the "From" address when it performs its mass-mailing routine. Numerous cases have been reported in which users of uninfected computers received complaints that they sent an infected message to another individual.

For example, Linda Anderson is using a computer infected with W32.Sobig.F@mm. Linda is neither using an antivirus program nor has the current virus definitions. When W32.Sobig.F@mm performs its email routine, it finds the email address of Harold Logan. The worm inserts Harold's email address into the "From" portion of an infected message, which it then sends to Janet Bishop. Then, Janet contacts Harold and complains that he sent her an infected message; however, when Harold scans his computer, Norton AntiVirus does not find anything, because his computer is not infected.
Lord Nikon is offline   Reply With Quote
Old 05-09-2003, 10:45   #3
Nemesis
Inactive
 
Join Date: Jun 2003
Location: Surrey
Age: 57
Services: Virgin stuff
Posts: 6,407
Nemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny star
Nemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny star
Send a message via MSN to Nemesis
I have received numerous calls about this one .....

Frustrating to say the least

To absolutely check for no infection, download the removal tool form Symantec.
Nemesis is offline   Reply With Quote
Old 05-09-2003, 11:19   #4
bigboab5
Inactive
 
Join Date: Jun 2003
Location: Glasgow
Services: V+, Extra Box, XL TV Service, XL Phone Service, 20mb Broadband
Posts: 215
bigboab5 is on a distinguished roadbigboab5 is on a distinguished road
Ok guys,

Thanks for the replies, that has put my mind at rest, but what i do find strange is, are these prob coming from one source, ie someone we know, or is it from several sources!!!

and yes i have scanned with the removal tool,, several times in fact. TY

Bigboab
bigboab5 is offline   Reply With Quote
Old 05-09-2003, 12:03   #5
trebor
Inactive
 
trebor's Avatar
 
Join Date: Aug 2003
Location: up shi* creak
Services: DIRTY DEEDS DONE DIRT CHEAP
Posts: 564
trebor has much to be proud oftrebor has much to be proud oftrebor has much to be proud oftrebor has much to be proud oftrebor has much to be proud oftrebor has much to be proud oftrebor has much to be proud oftrebor has much to be proud oftrebor has much to be proud oftrebor has much to be proud of
if you look at the message headers it will give you some idea of where the message came from and the route it took.
just be aware that this information can be spoofed just like the from address field.
right click the message, select properties, then the details tab.
trebor is offline   Reply With Quote
Old 05-09-2003, 12:11   #6
Chris
Trollsplatter
Cable Forum Team
 
Chris's Avatar
 
Join Date: Jun 2003
Location: North of Watford
Services: Humane elimination of all common Internet pests
Posts: 36,929
Chris has a golden auraChris has a golden auraChris has a golden auraChris has a golden aura
Chris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden auraChris has a golden aura
Quote:
Originally posted by bigboab5
Ok guys,

Thanks for the replies, that has put my mind at rest, but what i do find strange is, are these prob coming from one source, ie someone we know, or is it from several sources!!!

and yes i have scanned with the removal tool,, several times in fact. TY

Bigboab
It's frustrating - we went through a phase of getting p0rno email attachments, apparently from the minister who married us, thanks to a virus that was spoofing his address. The virus in question was randomly attaching files from the infected PC, which apparently also had the minister's email addy in its address book!
Chris is offline   Reply With Quote
Old 07-09-2003, 21:26   #7
bigboab5
Inactive
 
Join Date: Jun 2003
Location: Glasgow
Services: V+, Extra Box, XL TV Service, XL Phone Service, 20mb Broadband
Posts: 215
bigboab5 is on a distinguished roadbigboab5 is on a distinguished road
Quote:
Originally posted by towny
The virus in question was randomly attaching files from the infected PC, which apparently also had the minister's email addy in its address book!
Oohhh er, how embarrassing!!!


bigboab
bigboab5 is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 01:14.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.