emails saying infected with sober.g in email

  • Thread starter Thread starter Thorny
  • Start date Start date
T

Thorny

I keep getting emails saying that I am infected with sober.g virus but
neither AVG nor Panda has been able to say that I am infected. AVG is
the free version and is up to date. I can't find any automated
removal for sober.g nor can I be certain that the messages are true or
bogus. Anyone know anthing about this? Help is appreciated.

I will attach the message.

Thorny




VIRUS ALERT

Our virus checker found
virus: Worm.Sober.G
in your email to the following recipients:

(... large list of email addresses snipped out...)

Delivery of the email was stopped!

Please check your system for viruses,
or ask your system administrator to do so.

For your reference, here are headers from your email:
------------------------- BEGIN HEADERS -----------------------------
Received: from jthornburg.net (unknown [10.0.0.228])
by ethoserver.ezone.net (Postfix) with SMTP
id A070859435; Sun, 16 May 2004 11:56:15 -0500 (CDT)
From: (e-mail address removed)
To: (e-mail address removed)
Date: Sun, 16 May 2004 16:53:56 GMT
Subject: error in dbase
Importance: Normal
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
Message-ID: <[email protected]>
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="40f271967d53"
Content-Transfer-Encoding: 7bit
-------------------------- END HEADERS ------------------------------
 
Thorny said:
I keep getting emails saying that I am infected with sober.g virus but
neither AVG nor Panda has been able to say that I am infected. AVG is
the free version and is up to date. I can't find any automated
removal for sober.g nor can I be certain that the messages are true or
bogus. Anyone know anthing about this? Help is appreciated.

Sober.G forges the sender adddress. Sober.G probably sent itself from
another computer using your address in the "From" field. Then it was
caught by a badly configured AV on a server (badly configured in that it
sends back warnings to the forged sender address).
 
Sober.G forges the sender adddress. Sober.G probably sent itself from
another computer using your address in the "From" field. Then it was
caught by a badly configured AV on a server (badly configured in that it
sends back warnings to the forged sender address).

Thank you -

My ISP says they do not show any virus-like activity from my account,
so between what you said and what they say it looks like I am OK.
Thanks again.

Thorny
 
Back
Top