WreckRman2
07-21-2001, 08:29 PM
Over the last 2 days I have recieved NUMEROUS emails from "ROBERTO STEWART <rstewart@cob.megared.net.mx>" and "Christian Baker <chris@universitywafer.com>" which includes a doc file with a virus. I want to block email from them as most of the IP is the same and host name. I emailed the ISP but they ignored it saying it had a virus. DUH! Stupid people... But it is getting worse. I just checked my mail and 4 of 6 messages were this.
This email says:
Hi! How are you?
I send you this file in order to have your advice
See you later. Thanks
Is anyone else getting it?
Chicken
07-22-2001, 09:22 AM
This is the same virus that is going around (was discussed here: http://webhostingtalk.com/showthread.php?&threadid=15874 ). I would email these two addresses and let them know that their computer is infected (always a nice thing to do).
jaime
07-23-2001, 04:55 AM
Hi,
I have had to disable my emails for all the domains in my raqs.
In three days I have received over 2.3 Gb of emails containing that virus (SIRCAM worm).
The first day I also replied the emails telling them that they were infected by that virus and the removal instructions but the distribution of this virus has been so high in so little time that I have had to disable all email in my raqs (just one email account was increasing over 300 kb's per minute !!!).
There is a real plague here in Spain and also in Sudamerica. All the pop3 email accounts have become inoperative.
I would like to know how can I block and bounce the emails matching several BODY messages patterns.
Could anyone post how to do it using Procmail or should I install another utility?