Computer Virus Problem.

Ysgarran

Registered User
I recieved a computer virus from a mongoosepublishing e-mail address earlier this month (1 July). I've tried contacting mongoosepublishing but have not gotten any replies.

It was the "W32.Sobig.E@mm" virus. Now, AFAIK, there is no way to tell if the e-mail address has been forged or not. Usually "W32.Sobig.E@mm" will forge a yahoo e-mail address.

I think it is very important that mongoosepublishing makes sure that their machines are not infected, but then I haven't been able to get a reply from them.

Questions:
1. Anyone else have any problems?
2. Can anyone suggest a contact e-mail address for mongoosepublishing? I've sent e-mail to the address available at the mongoosepublising.com site and the contact e-mail address for the people who run the mongoosepublishing.com .

I have to say that I'm a bit annoyed because I've never let a machine under my control get infected by computer virus before. Letting my guard down in this instance was very aggravating.

Ysgarran.

p.s.
I want to stress that mongoosepublishing may not have anything to do with this. I just would feel better if they would respond saying that they have looked into the problem and verified their machines are clean.
 

log in or register to remove this ad

As you seem to have suspected, this virus is a "spoofer." Take a look here: http://vil.mcafee.com/dispVirus.asp?virus_k=100429

Note this sentence: "This variant spoofs, or forges, the from address. Therefore the perceived sender is likely not a pointer to the infected user."

So it's likely that the virus actually came from someone who has Mongoose in their address book and not from Mongoose themselves.
 

Yep, I looked it up on the Symantec site:
http://securityresponse.symantec.com/avcenter/venc/data/w32.sobig.e@mm.html

OTOH, it is a decent possibility that the mongoosepublishing people have been sent this virus also. Now they probably weren't as foolish as I was and didn't get them selves infected.

As a precaution I have my own address as the very first e-mail address in my address book. It is a warning flag that if this e-mail address is used I know that I have a problem.

It comes down to the fact that I think this is an important issue. This virus took me about a half-hour to clean from my computer. Not a huge loss of time but still very annoying.

EricNoah said:
As you seem to have suspected, this virus is a "spoofer." Take a look here: http://vil.mcafee.com/dispVirus.asp?virus_k=100429

Note this sentence: "This variant spoofs, or forges, the from address. Therefore the perceived sender is likely not a pointer to the infected user."

So it's likely that the virus actually came from someone who has Mongoose in their address book and not from Mongoose themselves.
 


Given my luck, my e-mails are being filtered away as spam...

Ysgarran.

Psionicist said:
Sneaky people use their own e-mail server that will filter away spam and virus. I love technology. :D
 

More information.

Bringing in some of the system guys where I work I've traced back the e-mail headers. The e-mail definately did NOT come from mongoosepublishing.

Still, I believe that it is a good chance that the server that did sent this also hit mongoosepublishing.com .

later,
Ysgarran.
 

If this is the virus I think it is from, it grab email addresses from YOUR address book and will send them to everyone incuding your self. I remember my sister getting it, and getting an email from MY old Email address. Also she got lots of mail from herself to herself but they all had different "from" addresses. Chances are Mongoose never got any mail from you (I am sure they have filters) but you sent yourself a mail from mongoose. It even searches through text files to find email addresses to use as fake From.
 

Ysgarran said:
Given my luck, my e-mails are being filtered away as spam...

Funny, I would have thought they'd have been pr0n...

There are a bunch of these viruses now. Seri's work was getting "your e-mail is infected with x" replies from mail servers because someone else's computer was sending out virus laiden e-mails claiming to be her work. Never did track that computer down :( The best I could do is tell the ISP what provider and IP address they were using, not that either ISP involved did anything.
 

Remove ads

Top