Computer Virii

Thread Tools
 
Search this Thread
 
  #1  
Old 08-17-2006, 10:56 AM
UrbanCowboy's Avatar
Senior Member
Thread Starter
Join Date: Mar 2000
Location: Westminster, CO
Posts: 481
Likes: 0
Received 0 Likes on 0 Posts
Computer Virii

So One of the 60 computers here in my office has a virus? How do I know this? Because we're getting a bunch of returned email that makes it quite obvious one of the machines is emailing out a bunch of SPAM. The problem is, that the From: field is modified so I can't tell which computer is sending the emails. Suggestions?
 
  #2  
Old 08-17-2006, 10:59 AM
Arctic Cat F7's Avatar
Senior Member
Join Date: Jul 2003
Location: The Deep Back Woods of The Great White North
Posts: 502
Likes: 0
Received 0 Likes on 0 Posts
Nice sig UC. Where have I seen that before?

I still have your sig you made me in my computer.
 
  #3  
Old 08-17-2006, 11:12 AM
jamzwayne's Avatar
Senior Member
Join Date: Mar 2004
Location: Your moms house
Posts: 1,336
Received 1 Like on 1 Post
Packet sniffer?
 
  #4  
Old 08-17-2006, 12:28 PM
TeckBargins's Avatar
Senior Member
Join Date: Aug 2003
Location: Southern Cali
Posts: 998
Likes: 0
Received 0 Likes on 0 Posts
search in the header for the ip address and trace it back with that.
 
  #5  
Old 08-17-2006, 12:38 PM
Bluejay's Avatar
Global Moderator &
Senior Member

Join Date: Mar 2005
Location: Burleson/Athens/Brownsboro, TX
Posts: 26,016
Received 68 Likes on 64 Posts
Unplug the machines one at a time till it quits coming back.


P. S. As much junk as you do on the net, I would start with yours!
 
__________________
Jim
  #6  
Old 08-17-2006, 12:40 PM
henkyjenky's Avatar
Senior Member
Join Date: Jul 2006
Location: Phoenix
Posts: 242
Likes: 0
Received 0 Likes on 0 Posts
Header IP is a good shot.

It could be an outside computer that knows you, who is using your address as a return address.

Update all virus defs and run scans.

Check mail server logs to see where they are coming from and block that IP for a day or two (if it's from India or something).
 
  #7  
Old 08-17-2006, 12:43 PM
jamzwayne's Avatar
Senior Member
Join Date: Mar 2004
Location: Your moms house
Posts: 1,336
Received 1 Like on 1 Post
Originally Posted by bluejay432000
Unplug the machines one at a time till it quits coming back.


P. S. As much junk as you do on the net, I would start with yours!


That's what we call "process of elimination". It's a looong process, but it works. I wouldn't recommend that to anyone, but if push comes to shove.....
 
  #8  
Old 08-17-2006, 12:49 PM
jamzwayne's Avatar
Senior Member
Join Date: Mar 2004
Location: Your moms house
Posts: 1,336
Received 1 Like on 1 Post
Originally Posted by henkyjenky
Header IP is a good shot.

It could be an outside computer that knows you, who is using your address as a return address.

Update all virus defs and run scans.

Check mail server logs to see where they are coming from and block that IP for a day or two (if it's from India or something).

True.

Keep in mind, the IP address will only give you the "Whois" of the IP owner (***, Comcast, Cebridge, Suddenlink, etc). Now, if the IP is a static, and has a reverse set, then maybe. A packet sniffer will show you what Work station is the one with the virus...bandwidth usage. It's best to check after hours also.
 
  #9  
Old 08-17-2006, 12:51 PM
UrbanCowboy's Avatar
Senior Member
Thread Starter
Join Date: Mar 2000
Location: Westminster, CO
Posts: 481
Likes: 0
Received 0 Likes on 0 Posts
Will a packet snifer work in my situation?

All network computers run to three Cisco routers. Our DSL modem also runs to one of the routers. A Windows 2000 Server establishes IP addresses but the Internet should work without that server in the loop. Where would I install a sniffer?

I did get header info from one of the replies; it was not helpful as we all have the same IP address as far as the external world is concerned.
 
  #10  
Old 08-17-2006, 12:56 PM
jamzwayne's Avatar
Senior Member
Join Date: Mar 2004
Location: Your moms house
Posts: 1,336
Received 1 Like on 1 Post
Originally Posted by UrbanCowboy
Will a packet snifer work in my situation?

All network computers run to three Cisco routers. Our DSL modem also runs to one of the routers. A Windows 2000 Server establishes IP addresses but the Internet should work without that server in the loop. Where would I install a sniffer?

I did get header info from one of the replies; it was not helpful as we all have the same IP address as far as the external world is concerned.

I sent you a PM...
 
  #11  
Old 08-17-2006, 01:14 PM
F150 Duke's Avatar
Senior Member
Join Date: Apr 2005
Location: In a van down by the river
Posts: 3,009
Likes: 0
Received 0 Likes on 0 Posts
We have the same problem here. I wish out IT department would start working on it like you are working on yours.

It's a real pain in the **** getting Viagra and other herbal emails every day or hearing how some rich guy in Africa left me his life savings.

Duke
 
  #12  
Old 08-17-2006, 01:18 PM
jamzwayne's Avatar
Senior Member
Join Date: Mar 2004
Location: Your moms house
Posts: 1,336
Received 1 Like on 1 Post
Originally Posted by F150 Duke
We have the same problem here. I wish out IT department would start working on it like you are working on yours.

It's a real pain in the **** getting Viagra and other herbal emails every day or hearing how some rich guy in Africa left me his life savings.

Duke

Is this a personal email you get that trash in, or is it your Corp email acct?
 
  #13  
Old 08-17-2006, 01:19 PM
henkyjenky's Avatar
Senior Member
Join Date: Jul 2006
Location: Phoenix
Posts: 242
Likes: 0
Received 0 Likes on 0 Posts
You're having a different problem.

If you want your SPAM to go away, give IT a bunch of money to purchase, setup, and tune a good filter.
 
  #14  
Old 08-17-2006, 01:30 PM
jamzwayne's Avatar
Senior Member
Join Date: Mar 2004
Location: Your moms house
Posts: 1,336
Received 1 Like on 1 Post
Originally Posted by henkyjenky
You're having a different problem.

If you want your SPAM to go away, give IT a bunch of money to purchase, setup, and tune a good filter.
or never use/give your email address on the net at ANY website.
 
  #15  
Old 08-17-2006, 01:30 PM
UrbanCowboy's Avatar
Senior Member
Thread Starter
Join Date: Mar 2000
Location: Westminster, CO
Posts: 481
Likes: 0
Received 0 Likes on 0 Posts
I am the IT Dept. We are sending out the Spam not receiving it. I just dont know what computer has the spam virus.
 


Quick Reply: Computer Virii



All times are GMT -4. The time now is 12:14 PM.