New E-Mail Virus?

H

Harvey Taylor

Hi Folks,

I've had my XP System for 6 months now, I'm running the current version of
Norton Internet Security, my virus signatures are always up-to-date, and I
run manual scans at least every other day. Never a problem until now.

I'm on optimum (cable) online, I use OE for e-mail and for the past two days
I've been getting returned e-mail from AOL stating:

----- The following addresses had permanent fatal errors -----
<[email protected]>

----- Transcript of session follows -----
.... while talking to air-xg04.mail.aol.com.:<<< 554 TRANSACTION FAILED - Unrepairable Virus Detected. Your mail has not
been sent.
554 <[email protected]>... Service unavailable

I have no idea who (e-mail address removed) is, apparently, I am sending e-mail to
(not known to me) aol addresses with .dat attachments that are infected, and
each time I begin to open the .dat attachment, the name (number) of the .dat
file changes, and Norton after countless scans tells me that my machine is
clean. The messages only come from AOL.

No other problems or symptoms, I had no issue with the blaster worm, I had
installed patches prior to the outbreak. In closing, I am getting reports
from friends that they are having the same e-mail symptoms.

Is this a new worm? Can anybody shed any light on what I'm reporting?

Whoa, just received a pop-up notice from my Norton software that has
identified the worm I have as W32.Sobig.F@mm . Now let's see if I can
remove it from my system.

Thanks in advance, <<Harvey>>
 
A

Alex Nichol

Harvey said:
I have no idea who (e-mail address removed) is, apparently, I am sending e-mailto
(not known to me) aol addresses with .dat attachments that are infected,and
each time I begin to open the .dat attachment, the name (number) of the ..dat
file changes, and Norton after countless scans tells me that my machine is
clean. The messages only come from AOL.

There is a nasty new variant of the SoBIG virus around. What is
happening is that it has been caught by some machine on AOL that has
your e-mail address in its address book. When it sends itself out, to
as many addresses as it can find, it picks an address from the book to
'spoof' as the one the mail is from - it has picked yours. SO when AOLs
antivirus spots the infected e-mail and bounces it (why it does not just
delete I don't know) it bounces to that From address - to you. Which is
highly annoying and there is not a thing you can do short of changing
email account.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top