Hi; The virus appears to always come from: [EMAIL PROTECTED] So simply add that to the kill list in Imail. That way any email comes with that return address the server would not accept it.
This is what Symantec says about this: ======================================== The W32.Sobig.A@mm worm sends itself to all the addresses it finds in the .txt, .eml, .html, .htm, .dbx, and .wab files. The email message has the following characteristics: From: [EMAIL PROTECTED] Subject: The subject will be one of these: ======================================== Regards, Kami -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] On Behalf Of Jeff Maze - Hostmaster Sent: Wednesday, February 05, 2003 3:47 PM To: [EMAIL PROTECTED] Subject: [Declude.Virus] [EMAIL PROTECTED] & [EMAIL PROTECTED] Hello, It appears as though the Sobig virus is making it's rounds again. I've gotten three or four Undeliverable mails today. Anyway, I remember reading somewhere in this list (when the virus first hit) that there was a way for Declude to block these message before the server even tried to send them out. I've looked again, but am unable to locate the messages. Can someone give me the lo-down on how to block these. Thanks.. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.