VIRUS!!!!!!!!!!! ALERT!!!!!

Chat about anything and everything... (well almost anything) Whether it be the front porch or the pot belly stove or news of interest or a topic of your liking, this is the place to post it.

Moderator: S2k Moderators

Message
Author
Rainband

VIRUS!!!!!!!!!!! ALERT!!!!!

#1 Postby Rainband » Wed Aug 20, 2003 9:06 pm

DON"T OPEN ANY EMAIL LIKE THIS!!!!

System Anti-Virus Ad... // Virus found in sent message "Re: That movie"

This was in the topic line!!! More later
0 likes   

Rainband

#2 Postby Rainband » Wed Aug 20, 2003 9:08 pm

Dear John,

A new variant of W32/Sobig, W32/Sobig.f@MM is a High Risk mass-mailing worm. It arrives as an email attachment with a .pif or .scr extension. When run, it infects the host computer, then emails itself (using its own SMTP engine) to harvested email addresses from the victim's machine. In addition, when it propagates, the worm "spoofs" the "from: field", using one of the harvested email addresses.

Note: The worm copies itself onto the infected machine as: C:\WINNT\WINPPR32.EXE

Caution: An infected email can come from addresses you recognize and may contain the following information:

WHAT TO LOOK FOR:

Subject: [content varies]
- Your details
- Thank you!
- Re: Thank you!
- Re: Details
- Re: Re: My details
- Re: Approved
- Re: Your application
- Re: Wicked screensaver
- Re: That movie

Body: [content varies]
- See the attached file for details
- Please see the attached file for details

Attachment: [content varies]
- your_document.pif
- document_all.pif
- thank_you.pif
- your_details.pif
- details.pif
- document_9446.pif
- application.pif
- wicked_scr.scr
- movie0045.pif



Learn More about W32/Sobig.f@MM
Scan for W32/Sobig.f@MM



Subscribe to a full year of VirusScan Online for just $34.95 and get SpamKiller free*!

Learn More...


* After $30 mail-in rebate.
SpamKiller stops spam from polluting your inbox. SAVE $15, now only
0 likes   

User avatar
mf_dolphin
Category 5
Category 5
Posts: 17758
Age: 68
Joined: Tue Oct 08, 2002 2:05 pm
Location: St Petersburg, FL
Contact:

#3 Postby mf_dolphin » Wed Aug 20, 2003 9:09 pm

That's part of the SoBig virus Johnathan. You're right though...Don't Open the Attachment. Road runner is blocking all of those coming in for me but I still get a message saying that they blocked it because of the virus. :-(
0 likes   

Rainband

#4 Postby Rainband » Wed Aug 20, 2003 9:12 pm

Mine is on hotmail..but didn't look right!!!! After the email..I realized the term "RE: The Move" after getting the alert email from Mcafee... good thing I have good retention!! :wink:
0 likes   

weatherlover427

#5 Postby weatherlover427 » Wed Aug 20, 2003 9:17 pm

Thanks for the alert Johnathan! :) Norton is crapping on me again :cry: so I have to be extra careful right now :o :( :cry: .
0 likes   

User avatar
mf_dolphin
Category 5
Category 5
Posts: 17758
Age: 68
Joined: Tue Oct 08, 2002 2:05 pm
Location: St Petersburg, FL
Contact:

#6 Postby mf_dolphin » Wed Aug 20, 2003 9:35 pm

So far I've received three e-mails with SOBig from board members. :-( The virus will only get on your system if you open the attachment! Be careful out there :-)
0 likes   

User avatar
breeze
Category 5
Category 5
Posts: 9110
Age: 62
Joined: Sat Feb 08, 2003 4:55 pm
Location: Lawrenceburg, TN

#7 Postby breeze » Wed Aug 20, 2003 9:40 pm

So far, so good on Norton 2003 program!

(Sweatin' and fingers crossed!)

Thanks, Johnathan!
0 likes   

User avatar
ameriwx2003
Category 4
Category 4
Posts: 980
Joined: Tue Jul 22, 2003 10:45 am

#8 Postby ameriwx2003 » Wed Aug 20, 2003 10:04 pm

Yep, so far Norton is hanging in for me. They said this is the fastest spreading virus yet. When will this end?
0 likes   

User avatar
streetsoldier
Retired Staff
Retired Staff
Posts: 9705
Joined: Wed Feb 05, 2003 11:33 pm
Location: Under the rainbow

#9 Postby streetsoldier » Wed Aug 20, 2003 10:37 pm

I have Norton 2002 with updates on my PC in general, and McAfee scanning my home server and Hotmail inboxes...both have done well in quaranteeing and deletion of the 60+ E-mails I've received with this SoBig.F version.

The attacks have subsided for now...but, there's always tomorrow!
0 likes   

User avatar
wx247
S2K Supporter
S2K Supporter
Posts: 14279
Age: 41
Joined: Wed Feb 05, 2003 10:35 pm
Location: Monett, Missouri
Contact:

#10 Postby wx247 » Thu Aug 21, 2003 7:40 am

I have received over 75 of these e-mails in my Hotmail account. I have closed this account as of yesterday because I can't deal with the hours of deletion it is taking to keep all the terrible junk mail out so I can read the two or three e-mails from friends and colleagues.
0 likes   
Personal Forecast Disclaimer:
The posts in this forum are NOT official forecast and should not be used as such. They are just the opinion of the poster and may or may not be backed by sound meteorological data. They are NOT endorsed by any professional institution or storm2k.org. For official information, please refer to the NHC and NWS products.

User avatar
Colin
Category 5
Category 5
Posts: 5086
Joined: Fri Apr 18, 2003 4:17 pm
Location: Catasauqua, PA
Contact:

#11 Postby Colin » Thu Aug 21, 2003 11:17 am

I have Norton AntiVirus 2001 - but with the LiveUpdate, which I don't know what it does...but I'm hoping it catches it if it comes! :o Thanks for the alert Johnathan! :)
0 likes   

Guest

#12 Postby Guest » Thu Aug 21, 2003 11:25 am

Well I just checked my home email here from work via my isp server - I had over 60 emails with the sobig virus. I deleted everyone one of them from the internet side - haven't been opened at home yet. My isp be caught 50 of them and sent me notice saying I was send a virus. With my ISP and my McAfee virus protection - I am hoping I am protected.

This one is bad Folks.
0 likes   

User avatar
Stephanie
S2K Supporter
S2K Supporter
Posts: 23843
Age: 63
Joined: Thu Feb 06, 2003 9:53 am
Location: Glassboro, NJ

#13 Postby Stephanie » Thu Aug 21, 2003 11:42 am

Thanks Johnathan for the heads up!

That's what I was seeing on Monday night in my e-mail - I'd say 70 of the 80 e-mails I received had something to do with that virus. Prodigy did send me an e-mail stating that they blocked others that tried to come through that had the Sobig virus on it. :(
0 likes   

User avatar
vbhoutex
Storm2k Executive
Storm2k Executive
Posts: 29113
Age: 73
Joined: Wed Oct 09, 2002 11:31 pm
Location: Cypress, TX
Contact:

#14 Postby vbhoutex » Thu Aug 21, 2003 1:05 pm

I'm being hit right and left too! Thank you RR!!!! Plus I have a firewall on my comp!!! plus Mcafee!! My McAfee hasn't caught anything of late, but I presume that is because of the excellent job RoadRunner does and the firewall. DEFINITELY A BAD ONE FOLKS! I've gotten at least one notice saying I sent one, but I don't even trust the notice.
0 likes   
Skywarn, C.E.R.T.
Please click below to donate to STORM2K to help with the expenses of keeping the site going:
Image

Guest

#15 Postby Guest » Thu Aug 21, 2003 1:17 pm

Same thing here David - I'm getting an aol notice that I sent one - I have no one in my address box with the name timebomb - and my computer has been shut down and turned off at home since 6:00 a.m. this morning.

I don't know what's going on....this is a bad one...they need to find who did this and lock them up for life.
0 likes   

User avatar
azskyman
S2K Supporter
S2K Supporter
Posts: 4104
Joined: Thu Mar 13, 2003 7:36 am
Location: Scottsdale Arizona
Contact:

#16 Postby azskyman » Thu Aug 21, 2003 7:54 pm

Running through Phoenix, too. Sobig is doing its thing. Not terrible volatile here, but a nuisance nonetheless.

I'm cleaning the computer daily with Norton...which says I don't have the virus...just the effects of it.

Have had trojan horse viruses a couple of times before. The Sobig is pesky.
0 likes   

pojo
Military Member
Military Member
Posts: 8016
Age: 43
Joined: Thu Feb 06, 2003 9:16 pm
Location: Houston

#17 Postby pojo » Thu Aug 21, 2003 7:59 pm

My grandma has the virus and thankfully, she is aware that the virus has attacked her computer....she is working with Nortons right now to end the harmful effects of the Virus.
0 likes   

User avatar
southerngale
Retired Staff
Retired Staff
Posts: 27418
Joined: Thu Oct 10, 2002 1:27 am
Location: Southeast Texas (Beaumont area)

#18 Postby southerngale » Fri Aug 22, 2003 4:23 pm

Goodness!! Headlines at Drudge:

NY TIMES SHUTS DOWN COMPUTER SYSTEMS...
Infected PCs await orders from hacker...
Virus Expanding Its Reach...


When will this end???

I have been lucky so far. I haven't had a single contaminated email. *crosses fingers*
0 likes   
Please support Storm2k by making a donation today. It is greatly appreciated! Click here: Image

Image my Cowboys Image my RocketsImage my Astros

User avatar
Lindaloo
Category 5
Category 5
Posts: 22658
Joined: Sat Mar 29, 2003 10:06 am
Location: Pascagoula, MS

#19 Postby Lindaloo » Sat Aug 23, 2003 5:40 pm

I thought the only way the virus could get into your computer is if you opened the attachment.

How would you know if you got the virus? Does anyone know what the computer does with this virus upon being infected?
0 likes   

User avatar
mf_dolphin
Category 5
Category 5
Posts: 17758
Age: 68
Joined: Tue Oct 08, 2002 2:05 pm
Location: St Petersburg, FL
Contact:

#20 Postby mf_dolphin » Sat Aug 23, 2003 8:21 pm

Lindaloo wrote:I thought the only way the virus could get into your computer is if you opened the attachment.

How would you know if you got the virus? Does anyone know what the computer does with this virus upon being infected?


Viruses and worms find there way onto your PC any number of ways. E-mail is one of the more prevelant (and easiest to prevent) ways. With the expansion of full time internet access, (DSL / Cable) there are an increasing number of direct attacks via internet worms. Worms usually target PC's unprotected by a properly configured firewall. A worm is usually the carrier of what's called a payload. The payload is another program that can be everything from "Spyware" to another virus. It's a dangerous world anymore on the internet.
0 likes   


Return to “Off Topic”

Who is online

Users browsing this forum: No registered users and 14 guests