Computer Virii

Thread Tools
 
Search this Thread
 
Old Aug 17, 2006 | 10:56 AM
  #1  
UrbanCowboy's Avatar
Thread Starter
|
Senior Member
Joined: Mar 2000
Posts: 481
Likes: 0
From: Westminster, CO
Computer Virii

So One of the 60 computers here in my office has a virus? How do I know this? Because we're getting a bunch of returned email that makes it quite obvious one of the machines is emailing out a bunch of SPAM. The problem is, that the From: field is modified so I can't tell which computer is sending the emails. Suggestions?
 
Reply
Old Aug 17, 2006 | 10:59 AM
  #2  
Arctic Cat F7's Avatar
Senior Member
Joined: Jul 2003
Posts: 502
Likes: 0
From: The Deep Back Woods of The Great White North
Nice sig UC. Where have I seen that before?

I still have your sig you made me in my computer.
 
Reply
Old Aug 17, 2006 | 11:12 AM
  #3  
jamzwayne's Avatar
Senior Member
Joined: Mar 2004
Posts: 1,336
Likes: 1
From: Your moms house
Packet sniffer?
 
Reply
Old Aug 17, 2006 | 12:28 PM
  #4  
TeckBargins's Avatar
Senior Member
Joined: Aug 2003
Posts: 998
Likes: 0
From: Southern Cali
search in the header for the ip address and trace it back with that.
 
Reply
Old Aug 17, 2006 | 12:38 PM
  #5  
Bluejay's Avatar
Global Moderator &
Senior Member
20 Year Member
Joined: Mar 2005
Posts: 26,080
Likes: 82
From: Burleson/Athens/Brownsboro, TX
Unplug the machines one at a time till it quits coming back.


P. S. As much junk as you do on the net, I would start with yours!
 
__________________
Jim
Reply
Old Aug 17, 2006 | 12:40 PM
  #6  
henkyjenky's Avatar
Senior Member
Joined: Jul 2006
Posts: 242
Likes: 0
From: Phoenix
Header IP is a good shot.

It could be an outside computer that knows you, who is using your address as a return address.

Update all virus defs and run scans.

Check mail server logs to see where they are coming from and block that IP for a day or two (if it's from India or something).
 
Reply
Old Aug 17, 2006 | 12:43 PM
  #7  
jamzwayne's Avatar
Senior Member
Joined: Mar 2004
Posts: 1,336
Likes: 1
From: Your moms house
Originally Posted by bluejay432000
Unplug the machines one at a time till it quits coming back.


P. S. As much junk as you do on the net, I would start with yours!


That's what we call "process of elimination". It's a looong process, but it works. I wouldn't recommend that to anyone, but if push comes to shove.....
 
Reply

Trending Topics

Old Aug 17, 2006 | 12:49 PM
  #8  
jamzwayne's Avatar
Senior Member
Joined: Mar 2004
Posts: 1,336
Likes: 1
From: Your moms house
Originally Posted by henkyjenky
Header IP is a good shot.

It could be an outside computer that knows you, who is using your address as a return address.

Update all virus defs and run scans.

Check mail server logs to see where they are coming from and block that IP for a day or two (if it's from India or something).

True.

Keep in mind, the IP address will only give you the "Whois" of the IP owner (***, Comcast, Cebridge, Suddenlink, etc). Now, if the IP is a static, and has a reverse set, then maybe. A packet sniffer will show you what Work station is the one with the virus...bandwidth usage. It's best to check after hours also.
 
Reply
Old Aug 17, 2006 | 12:51 PM
  #9  
UrbanCowboy's Avatar
Thread Starter
|
Senior Member
Joined: Mar 2000
Posts: 481
Likes: 0
From: Westminster, CO
Will a packet snifer work in my situation?

All network computers run to three Cisco routers. Our DSL modem also runs to one of the routers. A Windows 2000 Server establishes IP addresses but the Internet should work without that server in the loop. Where would I install a sniffer?

I did get header info from one of the replies; it was not helpful as we all have the same IP address as far as the external world is concerned.
 
Reply
Old Aug 17, 2006 | 12:56 PM
  #10  
jamzwayne's Avatar
Senior Member
Joined: Mar 2004
Posts: 1,336
Likes: 1
From: Your moms house
Originally Posted by UrbanCowboy
Will a packet snifer work in my situation?

All network computers run to three Cisco routers. Our DSL modem also runs to one of the routers. A Windows 2000 Server establishes IP addresses but the Internet should work without that server in the loop. Where would I install a sniffer?

I did get header info from one of the replies; it was not helpful as we all have the same IP address as far as the external world is concerned.

I sent you a PM...
 
Reply
Old Aug 17, 2006 | 01:14 PM
  #11  
F150 Duke's Avatar
Senior Member
Joined: Apr 2005
Posts: 3,009
Likes: 0
From: In a van down by the river
We have the same problem here. I wish out IT department would start working on it like you are working on yours.

It's a real pain in the **** getting Viagra and other herbal emails every day or hearing how some rich guy in Africa left me his life savings.

Duke
 
Reply
Old Aug 17, 2006 | 01:18 PM
  #12  
jamzwayne's Avatar
Senior Member
Joined: Mar 2004
Posts: 1,336
Likes: 1
From: Your moms house
Originally Posted by F150 Duke
We have the same problem here. I wish out IT department would start working on it like you are working on yours.

It's a real pain in the **** getting Viagra and other herbal emails every day or hearing how some rich guy in Africa left me his life savings.

Duke

Is this a personal email you get that trash in, or is it your Corp email acct?
 
Reply
Old Aug 17, 2006 | 01:19 PM
  #13  
henkyjenky's Avatar
Senior Member
Joined: Jul 2006
Posts: 242
Likes: 0
From: Phoenix
You're having a different problem.

If you want your SPAM to go away, give IT a bunch of money to purchase, setup, and tune a good filter.
 
Reply
Old Aug 17, 2006 | 01:30 PM
  #14  
jamzwayne's Avatar
Senior Member
Joined: Mar 2004
Posts: 1,336
Likes: 1
From: Your moms house
Originally Posted by henkyjenky
You're having a different problem.

If you want your SPAM to go away, give IT a bunch of money to purchase, setup, and tune a good filter.
or never use/give your email address on the net at ANY website.
 
Reply
Old Aug 17, 2006 | 01:30 PM
  #15  
UrbanCowboy's Avatar
Thread Starter
|
Senior Member
Joined: Mar 2000
Posts: 481
Likes: 0
From: Westminster, CO
I am the IT Dept. We are sending out the Spam not receiving it. I just dont know what computer has the spam virus.
 
Reply



All times are GMT -4. The time now is 04:18 PM.