The Artima Developer Community
Sponsored Link

.NET Buzz Forum
Flooded by W32.Sobig.F@mm

0 replies on 1 page.

Welcome Guest
  Sign In

Go back to the topic listing  Back to Topic List Click to reply to this topic  Reply to this Topic Click to search messages in this forum  Search Forum Click for a threaded view of the topic  Threaded View   
Previous Topic   Next Topic
Flat View: This topic has 0 replies on 1 page
Sascha Corti

Posts: 797
Nickname: sascha
Registered: Aug, 2003

Sascha Corti is a developer evangelist for Microsoft in Switzerland.
Flooded by W32.Sobig.F@mm Posted: Aug 19, 2003 9:49 AM
Reply to this message Reply

This post originated from an RSS feed registered with .NET Buzz by Sascha Corti.
Original Post: Flooded by W32.Sobig.F@mm
Feed Title: Console.WriteLine("Hello World");
Feed URL: http://www.corti.com/WebLogSascha/blogxbrowsing.asmx/GetRss?
Feed Description: A technology blog with a focus on the .NET framework, the Visual Studio .NET tools and the Windows server platform with of course the normal weblog-noise on what's happening in the industry and reviews of the latest geeky gadgets.
Latest .NET Buzz Posts
Latest .NET Buzz Posts by Sascha Corti
Latest Posts From Console.WriteLine("Hello World");

Advertisement

Argh! I returned to my PC after a meeting to find I am flooded by email triggered by the new W32.Sobig.F@mm worm. This variant is turning infected PCs into spam SMTP relays which is spoofing the sender email address.

Now, somewhere out there is a very busy, infected PC sending emails everywhere with my email address as the sender. The result is that I get tons of "undeliverable" or "mail infected and rejected" auto-responses from various domains.

As these notices are all totally different, varying from domain to domain, it's nearly impossible to remove them with an inbox-rule.

Not much I can do about it except wait for the storm to pass...

Disinfection Tool

F-Secure provides the special tool to disinfect the Sobig.F worm. The tool and disinfection instructions are available on their ftp site:

ftp://ftp.f-secure.com/anti-virus/tools/f-sobig.zip 
ftp://ftp.f-secure.com/anti-virus/tools/f-sobig.txt 
ftp://ftp.f-secure.com/anti-virus/tools/f-sobig.exe 

Admins can lock the following ports:

UDP 99x (incoming)
UDP 8998 (outgoing)

to stop the worm from turning the machine into a SPAM relay server.

Read: Flooded by W32.Sobig.F@mm

Topic: Stop ranting about the blaster worm Previous Topic   Next Topic Topic: Where were you when the power went out?

Sponsored Links



Google
  Web Artima.com   

Copyright © 1996-2019 Artima, Inc. All Rights Reserved. - Privacy Policy - Terms of Use