Forum Moderators: phranque
This morning I have been receiving an average of 200/300 emails an HOUR !! All seemingly from the same person and all attached with the virus W32.Yaha.F@mm
Is anyone else having problems with this virus or could this be some form of DOS attack ?
Any ideas and suggestions are appreciated. NAV and NIS detect the virus and quarantine it but this sheer number of emails is very worrying.
Thanks
Somkiat
Plus how do I find out the sending address, without opening the email ? I am always concerned about opening such an email even if the virus has been quarantined ?
Thanks
Somkiat
If not using an MS product, right clicking on the name/address should allow you to see the address through one option or another.
It is likely that it is safe to open the email though, as it sounds as if the virus is coming in as a standard attachment and your AV software is quarantining it. If a virus comes in as a standard file attachment, there is no danger in optening the email itself - just don't open the attached file.
Contact whoever holds that email address for you - if it's using the same domain name as your site then probably your hosting company I imagine? I've found they can be a bit snippy about blocking an address, but if you point out the number of infected emails coming in and be firm about it they should take action on it.
It looks like this is the nasty you're receiving. If it fits the description F-Secure gives here, then it is quite safe to open the email itself (it's not activated by opening the email like Badtrans was), but don't open the file attachment that will be in the email.
As the ISP is in Singapore a very strict country, I am sure they will look into it but as you say sometimes the sender is not even the sender or they are totally unaware.
Even still, it is highly unusual for an infected computer to send an 200 / 300 emais an hour out !!
We get affected by all the viruses but they come from different people and at irregular times. This one is a little suspicious.