VIRUS!!!!!!!!!!! ALERT!!!!!
Moderator: S2k Moderators
VIRUS!!!!!!!!!!! ALERT!!!!!
DON"T OPEN ANY EMAIL LIKE THIS!!!!
System Anti-Virus Ad... // Virus found in sent message "Re: That movie"
This was in the topic line!!! More later
System Anti-Virus Ad... // Virus found in sent message "Re: That movie"
This was in the topic line!!! More later
0 likes
Dear John,
A new variant of W32/Sobig, W32/Sobig.f@MM is a High Risk mass-mailing worm. It arrives as an email attachment with a .pif or .scr extension. When run, it infects the host computer, then emails itself (using its own SMTP engine) to harvested email addresses from the victim's machine. In addition, when it propagates, the worm "spoofs" the "from: field", using one of the harvested email addresses.
Note: The worm copies itself onto the infected machine as: C:\WINNT\WINPPR32.EXE
Caution: An infected email can come from addresses you recognize and may contain the following information:
WHAT TO LOOK FOR:
Subject: [content varies]
- Your details
- Thank you!
- Re: Thank you!
- Re: Details
- Re: Re: My details
- Re: Approved
- Re: Your application
- Re: Wicked screensaver
- Re: That movie
Body: [content varies]
- See the attached file for details
- Please see the attached file for details
Attachment: [content varies]
- your_document.pif
- document_all.pif
- thank_you.pif
- your_details.pif
- details.pif
- document_9446.pif
- application.pif
- wicked_scr.scr
- movie0045.pif
Learn More about W32/Sobig.f@MM
Scan for W32/Sobig.f@MM
Subscribe to a full year of VirusScan Online for just $34.95 and get SpamKiller free*!
Learn More...
* After $30 mail-in rebate.
SpamKiller stops spam from polluting your inbox. SAVE $15, now only
A new variant of W32/Sobig, W32/Sobig.f@MM is a High Risk mass-mailing worm. It arrives as an email attachment with a .pif or .scr extension. When run, it infects the host computer, then emails itself (using its own SMTP engine) to harvested email addresses from the victim's machine. In addition, when it propagates, the worm "spoofs" the "from: field", using one of the harvested email addresses.
Note: The worm copies itself onto the infected machine as: C:\WINNT\WINPPR32.EXE
Caution: An infected email can come from addresses you recognize and may contain the following information:
WHAT TO LOOK FOR:
Subject: [content varies]
- Your details
- Thank you!
- Re: Thank you!
- Re: Details
- Re: Re: My details
- Re: Approved
- Re: Your application
- Re: Wicked screensaver
- Re: That movie
Body: [content varies]
- See the attached file for details
- Please see the attached file for details
Attachment: [content varies]
- your_document.pif
- document_all.pif
- thank_you.pif
- your_details.pif
- details.pif
- document_9446.pif
- application.pif
- wicked_scr.scr
- movie0045.pif
Learn More about W32/Sobig.f@MM
Scan for W32/Sobig.f@MM
Subscribe to a full year of VirusScan Online for just $34.95 and get SpamKiller free*!
Learn More...
* After $30 mail-in rebate.
SpamKiller stops spam from polluting your inbox. SAVE $15, now only
0 likes
- mf_dolphin
- Category 5
- Posts: 17758
- Age: 68
- Joined: Tue Oct 08, 2002 2:05 pm
- Location: St Petersburg, FL
- Contact:
- mf_dolphin
- Category 5
- Posts: 17758
- Age: 68
- Joined: Tue Oct 08, 2002 2:05 pm
- Location: St Petersburg, FL
- Contact:
- ameriwx2003
- Category 4
- Posts: 980
- Joined: Tue Jul 22, 2003 10:45 am
- streetsoldier
- Retired Staff
- Posts: 9705
- Joined: Wed Feb 05, 2003 11:33 pm
- Location: Under the rainbow
- wx247
- S2K Supporter
- Posts: 14279
- Age: 41
- Joined: Wed Feb 05, 2003 10:35 pm
- Location: Monett, Missouri
- Contact:
I have received over 75 of these e-mails in my Hotmail account. I have closed this account as of yesterday because I can't deal with the hours of deletion it is taking to keep all the terrible junk mail out so I can read the two or three e-mails from friends and colleagues.
0 likes
Personal Forecast Disclaimer:
The posts in this forum are NOT official forecast and should not be used as such. They are just the opinion of the poster and may or may not be backed by sound meteorological data. They are NOT endorsed by any professional institution or storm2k.org. For official information, please refer to the NHC and NWS products.
The posts in this forum are NOT official forecast and should not be used as such. They are just the opinion of the poster and may or may not be backed by sound meteorological data. They are NOT endorsed by any professional institution or storm2k.org. For official information, please refer to the NHC and NWS products.
Well I just checked my home email here from work via my isp server - I had over 60 emails with the sobig virus. I deleted everyone one of them from the internet side - haven't been opened at home yet. My isp be caught 50 of them and sent me notice saying I was send a virus. With my ISP and my McAfee virus protection - I am hoping I am protected.
This one is bad Folks.
This one is bad Folks.
0 likes
- vbhoutex
- Storm2k Executive
- Posts: 29113
- Age: 73
- Joined: Wed Oct 09, 2002 11:31 pm
- Location: Cypress, TX
- Contact:
I'm being hit right and left too! Thank you RR!!!! Plus I have a firewall on my comp!!! plus Mcafee!! My McAfee hasn't caught anything of late, but I presume that is because of the excellent job RoadRunner does and the firewall. DEFINITELY A BAD ONE FOLKS! I've gotten at least one notice saying I sent one, but I don't even trust the notice.
0 likes
Same thing here David - I'm getting an aol notice that I sent one - I have no one in my address box with the name timebomb - and my computer has been shut down and turned off at home since 6:00 a.m. this morning.
I don't know what's going on....this is a bad one...they need to find who did this and lock them up for life.
I don't know what's going on....this is a bad one...they need to find who did this and lock them up for life.
0 likes
- azskyman
- S2K Supporter
- Posts: 4104
- Joined: Thu Mar 13, 2003 7:36 am
- Location: Scottsdale Arizona
- Contact:
Running through Phoenix, too. Sobig is doing its thing. Not terrible volatile here, but a nuisance nonetheless.
I'm cleaning the computer daily with Norton...which says I don't have the virus...just the effects of it.
Have had trojan horse viruses a couple of times before. The Sobig is pesky.
I'm cleaning the computer daily with Norton...which says I don't have the virus...just the effects of it.
Have had trojan horse viruses a couple of times before. The Sobig is pesky.
0 likes
- southerngale
- Retired Staff
- Posts: 27418
- Joined: Thu Oct 10, 2002 1:27 am
- Location: Southeast Texas (Beaumont area)
- mf_dolphin
- Category 5
- Posts: 17758
- Age: 68
- Joined: Tue Oct 08, 2002 2:05 pm
- Location: St Petersburg, FL
- Contact:
Lindaloo wrote:I thought the only way the virus could get into your computer is if you opened the attachment.
How would you know if you got the virus? Does anyone know what the computer does with this virus upon being infected?
Viruses and worms find there way onto your PC any number of ways. E-mail is one of the more prevelant (and easiest to prevent) ways. With the expansion of full time internet access, (DSL / Cable) there are an increasing number of direct attacks via internet worms. Worms usually target PC's unprotected by a properly configured firewall. A worm is usually the carrier of what's called a payload. The payload is another program that can be everything from "Spyware" to another virus. It's a dangerous world anymore on the internet.
0 likes
Who is online
Users browsing this forum: No registered users and 14 guests