virus warning message

Avery Todd avery@ev1.net
Tue, 26 Aug 2003 08:46:36 -0500


Jim,

We've had LOT of trouble with that and the Blaster worm at the university.
I've downloaded app. 800 messages with one of those 6-7 different subject
lines of the SoBigF virus. Thankfully, the virus had already been stripped.
I also had mail I had not sent returned to me as undeliverable because it
"had a virus in it". As careful as I've tried to be, I'm pretty sure I'm
clean.

If I understand it correctly. SoBig is in someone's computer who has your/my
e-mail address in their address book and if so, it "spoofs" a message using
that address as the sender. It also does this randomly using the other
addresses, so it's next to impossible to figure out where the message actually
came from.

With SoBigF, I "believe" one is safe as long as the attachment isn't opened.
Right now, I'm updating & scanning at work several times a week just to be
sure some new variant hasn't started, which I understand, because of its
history of doing that, is expected in the near future.

Avery

At 08:40 AM 08/26/03 -0400, you wrote:
>Hey y'all I got this post from Mailer Dameon...I didn't send this stuff so be
>careful opening anything from me with this subject line...OK?
>Jim Bryant (FL)
>-----------------------------------
>The original message was received at Mon, 25 Aug 2003 23:51:15 -0600
>The message was sent from: <JIMRPT@AOL.COM>
>
>The virus found was: Win32:Sobig-F [Wrm]
>
>
>Received: from VTRAN ([64.172.25.77])
>         by mail.point2homes.biz (Merak 6.0.5) with SMTP id DSU74274
>         for <Shan@ShanSaigal.com>; Mon, 25 Aug 2003 23:51:01 -0600
>From: <JIMRPT@AOL.COM>
>To: <Shan@ShanSaigal.com>
>Subject: Re: Re: My details
>Date: Mon, 25 Aug 2003 22:53:16 --0700
>_______________________________________________
>pianotech list info: https://www.moypiano.com/resources/#archives



This PTG archive page provided courtesy of Moy Piano Service, LLC