Computing.Net > Forums > Windows 2000 > Sobig32 removal question...

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Sobig32 removal question...

Reply to Message Icon

Name: tenover
Date: September 3, 2003 at 13:11:34 Pacific
OS: W2k server
CPU/Ram: 1.8/512
Comment:

I have one user in our company who is getting
emails containing the SoBig32 virus daily,
probably about 150 a day....Now, this doesn't
neccessarily mean that SHE has the virus
correct? It probably means that she is on
someone else's mailing list who DOES have it,
no? I've scanned her computer and her
mailbox on the Exchange Server, and they
both come up clean. Should I just not worry
about it, or is there anythign I can do to stop
all those damn emails from coming to her?
The emails are getting caught by Norton on the
Exchange server, and I've set it to just delete
the entire email, but it's just bugging me (And
making me a little paranoid) to see them all
coming in every day...Thanks.



Sponsored Link
Ads by Google

Response Number 1
Name: TheShadowONe
Date: September 3, 2003 at 19:00:50 Pacific
Reply:

Correct, the virus can only affect the system if it has been downloaded onto the computer and unzipped. Unfortunatly there is nothing you can do, and i know that you time is precious so you can inform the sender. you can however block the sender but that would take some time aswell


0

Response Number 2
Name: Vanessa
Date: September 3, 2003 at 19:04:09 Pacific
Reply:

We have 4 users (out of approx 50) who were lucky too. They were getting about 150 as well. It bothered me the first few days but I set my scanning for every night and we are fine.

There's not a lot you can do to stop them unless you can figure out the true IP of the source. I found those were often spoofed just like the "from" field.

It sounds like you already set up a filter/rule to auto-delete the emails already but if not, I set up a filter to auto delete any email where the body contains "see the attached file for details" so we don't have to look at them. Unfortunately, they still hit the emailserver and I suspect it slows the performance a tiny bit. I guess that's the price for technology.

Oh, it would probably also help to have DNS verify all IP's otherwise deny the email. Unfortunately that is a double-edged sword because a lot of company's do not have their DNS configured properly and some legitimate emails will be denied. My manager opted against that option even though I tried it for about 1/2 hour and it definitely helped. AOL, AT&T and other companies are all using that now so I would assume people will get their DNS in order soon so it will become a more useable tool.

Have fun!
Vanessa


0

Response Number 3
Name: Vanessa
Date: September 3, 2003 at 19:07:18 Pacific
Reply:

Also, don't bother trying to block a lot of the senders using the email address on the emails received. If you read the specs on the Blaster, you will see they are spoofed.

Good luck - Vanessa


0

Response Number 4
Name: tenover
Date: September 4, 2003 at 10:14:25 Pacific
Reply:

Thanks Vanessa,
Yeah, I've already done everything you recommended, so I guess there's nothing left to do until Sept. 1oth when it stops replicating!


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More


Remove Q324929 please help me



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows 2000 Forum Home


Sponsored links

Ads by Google


Results for: Sobig32 removal question...

Win2k unsafe removal question... www.computing.net/answers/windows-2000/win2k-unsafe-removal-question/12810.html

Win 2K, NAV and Trojan/CodeRed II www.computing.net/answers/windows-2000/win-2k-nav-and-trojancodered-ii/45807.html

Problems removing server name from? www.computing.net/answers/windows-2000/problems-removing-server-name-from/38342.html