Forum Moderators: phranque
For some reason in the last two hours I have received 30 attacks all of which where stopped by Norton with no problems.
The virus is sending it self to any email address found on html, htm, txt files and more on the internet.
So now I am taking all my addresses of all my high ranking web sites and using php to protect my email accounts.
Has anyone else seen a sudden increase of attacks from this virus?
What a week its turning out to be :(
Now instead of deleting each email manually, I am running a command-line query to delete all the emails with the following subjects:
Subject:
Re: Details
Re: Approved
Re: Re: My details
Re: Thank you!
Re: That movie
Re: Wicked screensaver
Re: Your application
Thank you!
Your details
And its working very fast :) But the emails are also multiplying fast. So I have temporarily made a setting on the server that all mails bigger than 25kb should not be received ;) Of course, all above 25kb are 99% spam...
I posted in this earlier thread:
[webmasterworld.com...] but this one seems to be moving better so will ask again here:
Whether there is anyway to turn off the NAV warnings as the pop ups telling me NAV 2003 has found a virus and requiring me to click finish sometimes makes my comp crash as there are just so many of them.
In fact just typing this I have had to click 'finish' 7 times!
I can't block emails above 25k as people send me images and most of them are above 40k etc so I am stuck at the moment.
Never seen a mass mailing virus like this so strong.
I am now starting to receive emails from the ISP as well telling me that I have sent viruses. Mind you I have had the virus appearing from big companies, what a mess.
As I said before its not the actual harm of the virus its the extra work load thats causing the problem :(
This actual strain came about at the beginning of the year named W32.Sobig.A@mm with similar effects but not as strong.
Since then their has been version B,C,D,E and now F.
F being the most strongest.
The person has managed to tweek it from just htm pages to many other extensions plus manipulate the from address. Origianlly it use to come from either Microsoft or Yahoo now it comes from the last person it had sent to.
Can anyone suggest away of deleting all .piff files from an email automatically using Eudora?
Although now my Zone Alarm firewall is working like crazy, its blocking all sorts of access attempts.
I never used to have a firewall before and now I see why I got one, you never know whats happening other wise.
I would hate to see what the virus does to your system if you where infected :(
It's amazing that people haven't yet learned to be very suspicious of any email with attachments (especially executable ones), no matter who they are from.
In any case the Internet is terrorists best friend how else do you think they communicate.
My firewall is working very well as everytime a virus comes in before the Norton picks it up something tries to access my computer either through UDP or TCP and Port 129.
I hope this ends soon as I find my self deleting so many emails and have had to restore a few after deleting the wrong ones.
Someone sent me an email like this
FW: option date
And I deleted it by mistake as it was amoungst emails with titles like
RE: Thank you and FW: Your details
Very frustrating :(
Also it is annoying that you get replys from people thinking that you send the damn virus to them as it is making it out its coming from us to some people!
Just sit it out I suppose and see what happens.
Now those free email accounts that manage to stop the attachments are great but all those ISP warnings are now filling up those in boxes.
This is the worst spam virus I have ever known in all the years I have been working with computers.
I just changed our Norton to check for updates every hour instead of every day. Man, this is sure a waste of time.
[edited by: MarkHutch at 3:36 pm (utc) on Aug. 20, 2003]
I have mailwasher and I am receiving loads of these things. I have set it up so it marks them all for delete but is there any way to auto delete them
Click "View", "Filter Sidebar". In your filter, check it to "Add to blacklist", then go to Blacklist tab, options, then choose "Auto-delete blacklisted messages".
not sure whether I must post this, but sometimes I suspect that such viruses are sponsored and backed by the anti-virus companies themselves to increase business.
No one in my family has received any of these yet. Does anyone know if ISPs are screening this stuff out?
not sure whether I must post this, but sometimes I suspect that such viruses are sponsored and backed by the anti-virus companies themselves to increase business. Of course, thats only what I think. It may be true or may not be true.
I think they're busy enough with the real viruses. In any case, if they were trying to generate bsuiness they'd create lots of little virus attacks, rather then one big one (you'll only buy a cure for W32.Sobig.F@mm once).
What's interesting is that all of the ones I've been getting bounced back were supposedly sent to AOL users. I haven't verified the IPs through the whole header. My real job keeps getting in the way!
second person just started getting them. poor bloke does not know what is going to hit him. but his site has even less exposure.
Thank GOD, that i spoof all the email addresses on my website and all the emails of my members, should they wish to post them. Am running a classifieds board and spoof them too. so hopefully my members should not regret having signed up to my community.
with spoofing I mean using javascript to randomly cut the email in two, assign the pieces to two variables and merging them with javascript again. Workes great, not 1 single virus. TOUCH WOOD.!
I don't think that it is ISP related. get some silly virus every day into my inbox. from the same person! anything from that email simply goes to the trash. so my ISP is not filtering too well if at all.
Also one of my mates is on the same provider and receives the virus. so definately no link there.
What I do think is that the size matters. The bigger the website the more damage. obviously the bigger the site, the more people will have your pages in their cache.
Also I have noticed that the people receiving the virus also get the "you sent me a virus" message. so that is obviously linked. The virus does not only send to the emails it finds in the cache it also uses those emails to disguise itself.
Friend of mine told me his inbox got wiped yeasterday. first thought it was the blaster, but now I'm sure it is this bugger which did it, said he did not open any virus but you never know... has anybod dared taking it to bits to see the workings of it?