[mou] Trouble with the network

David Cahlander david@cahlander.com
Fri, 29 Aug 2003 23:41:13 -0500


There is a lot of bad traffic going over the email network.  It
seems to be coming from a machine that has the IP address:

    dyn-4176.mnsu.edu [134.29.4.176]

I assume that this person has many mou-net people in his (or her)
address book, since the way this email is generated, is that a
"from address" is selected from the email address book and a "to
address" is also selected from the email address book, and email is sent
out with an attachment.

I do not know who has this problem, just that it appears that it
is coming from the above address.  My personal account is receiving 
20 bogus email messages/hour, and mou-net is also receiving a similar
amount of traffic.  We have been able to filter out the messages so
they do not go out on the mou-net, but I assume that the machine is
sending these bogus messages to all the people in the address book.

If you receive one of these messages, do not open the attachment.
If you do, it will infect your computer.  The name of this problem
is Worm.Sobig.F.

The computer that has this problem is connected 24 hours/day.
If you think that it is you, please disconnect your machine from
the network until you get the problem fixed.

I can provide the address book names, if you think that you may 
be the one who has the problem.  A few of the addresses are:

    birdnird@yahoo.com
    bbeneke@brigham.net
    dandersn@prodigy.net
    jmiller@smumn.edu
    bwright@uwsp.edu
     Anthony Hertzel <axhertzel@sihope.com>

I think this machine's email goes through the server in mankato, but I'm
not sure.

Any help in getting rid of this bad problem will help.

Thanks.
---
David Cahlander david@cahlander.com Burnsville, MN 952-894-5910