Computing.Net > Forums > Security and Virus > Duplicate emails w/Sobig

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Duplicate emails w/Sobig

Reply to Message Icon

Original Message
Name: Steve
Date: August 22, 2003 at 06:18:21 Pacific
Subject: Duplicate emails w/Sobig
OS: w2k
CPU/Ram: p3
Comment:

I work for a computer consulting firm and we have been working like dogs the past few days on this Sobig virus...

This biggest issue is the amount of emails that keep coming in, even to non-infected computers...

We have one client that now has 54,287 emails in her Outlook inbox...they came in over about a 24 hour period...(yes, that is the correct number!!!)...some of the messages have as many as 15 duplicates, most of them have about 4-8 duplicates...

We have found a utility program to that will hopefully remove the duplicates (LBEtoolbox.com)...and then the client can remove the single ones that she doesn't need...

I know there are a number of techs who are facing the same issues with Sobig and my question is this...

Has anyone found a way to cut back on the number of incoming emails Sobig is creating on clean computers???

Most of our clients are getting between 100 and 400 emails over the past couple of days...and a few clients have recieved essentially no additional emails...but for those that are getting a lot of them, this is a bit of a problem...

Any thoughts???

Thanx
Steve


Report Offensive Message For Removal


Response Number 1
Name: JackG
Date: August 22, 2003 at 07:30:53 Pacific
Reply: (edit)

It called education. Some people like to give out their e-mail address to everyone so they know who they are and how important they are. Others like to keep large e-mail lists on their machines so they know how many people they know.

Others never give out e-mail address and keep very few in their address lists.

Guess who gets lots of infected e-mail when a new virus goes around, or who's system sends out lots of e-mail when it gets infected.

Educate your clients, not to give their e-mail address to everyone. Just those who really need it. Educate them to keep contact e-mail addresses written down, and not in an e-mail list on their machine. Keep their address boot very small, type the address in when needed. Don't give a virus something to work with. Set the FIRST e-mail address in the address book to name AA00virus and e-mail address to AA00virus. Note: no @ or period in e-mail address. If a virus infects machine, it may decide the list is not a valid e-mail list. If not, the address will cause a reject back to the sender and alert them to an infection in their machine.

Then educate them to encourage their contacts not to keep their e-mail address in their address either, but use the Reply to notes.

The case of multiple copies of e-mail sounds like an infected e-mail server that the original passed through. Good luck finding it.

Oh, and encourage them to remove all traces of the OUTLOOK program, and all of its code, from their systems and get a different e-mail program.


Report Offensive Follow Up For Removal

Response Number 2
Name: Steve
Date: August 22, 2003 at 08:41:34 Pacific
Reply: (edit)

Jack...

Thanx for your comments...but that does not
help me with problem at hand...


Report Offensive Follow Up For Removal

Response Number 3
Name: sxshep
Date: August 22, 2003 at 13:26:33 Pacific
Reply: (edit)

No expert here but I believe as a short term solution you can configure Outlook to block emails with attachments. Not a pretty thing to your clients, but given the severity of their current problem it might be the lesser of two evils. Sobig has a shelf life expiration date of 10/10 upon which it is "supposed" to deactivate.
Not elegant but effective.
shep


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 5 Days.
Discuss in The Lounge
Poll History




Data Recovery Software