Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Sobig virus removal 1

Status
Not open for further replies.

aaronjonmartin

Technical User
Jul 9, 2002
475
GB
Everybody on my exchange server got infected with the Sobig virus yesterday, I updated my symantec antivirus and scanned and removed everything. However I have come in this morning and everybody has recieved the emails again, but there are no attachments. The subject lines vary but are mostly re: your application and the message body says see attached file but there are no attachments and any of them. I have recieved about 51 mails this morning all like this, does this mean we are still infected? Im not sure what to do, any thoughts?
 

or


Good luck, hope this helps. My regular business e-mail is down from register.com and these guys are GOOD!

Glen A. Johnson
Johnson Computer Consulting
MCP W2K
glen@nellsgiftbox.com

Want to get great answers to your Tek-Tips questions? Have a look at FAQ219-2884

"Once the game is over, the king and the pawn return to the same box."
 
Do you think because the worm has its own SMTP engine once i have been infected it will remember all the email addresses it infected and even though I have removed the virus it will still keep sending it me because it "knows" the addressess. This could explain the emails, and the reason there is no attachments is that the virus was removed and my av is up to date and stopping any dangers? Just a guess, any thoughts?
 
I thought the same thing, as one of my users got it yesterday. Same thing, after removal, we were still getting it about 15 times an hour. I started checking the headers on the incoming E-mail, and it was not coming from internal. So we were clean, just getting a ton of these as everyone else is... I don't believe that if the winppr32 is not running that it keeps infecting. It is probably coming from the Internet, as this was reported the fastest spreading virus ever. Check the headers of your E-mail by selecting the mail and going to options, in case you didn't know.
I actually found almost all of them coming from 3 different mail servers. I blocked their IP with an ACL, and now the amount we are receiving has dropped to about 4 every 2 hours...
Just my experiences dealing with this issue......

Thanks,

Matt Wray
MCSE, MCSA, MCP, CCNA

 
Mine may not be the same as what you need to block. When you receive one of these messages, highlight it, right-click, choose options and look at the Internet headers.
You will see Microsoft Mail Headers blah, blah. After that you will see Received from mailserver.domain.com([IPADDRESS]). That is the one to block.....

Thanks,

Matt Wray
MCSE, MCSA, MCP, CCNA

 
Here's a star Matt. I started getting tons of e-mail Monday, before sobig was even reported by Trend. I called a friend and asked if he had heard anything. "Nope, nothing goin on here." Next day it was on the news. Think it's starting to die out finally. No attachments today. Finally. Good luck all, we're gonna need it in the "Week of the Worms" as it's being called.

Glen A. Johnson
Johnson Computer Consulting
MCP W2K
glen@johnsoncomputers.us

Want to get great answers to your Tek-Tips questions? Have a look at FAQ219-2884

"Once the game is over, the king and the pawn return to the same box."
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top