Mexico Connect
Forums  > Specific Focus > Technical Mexico


johanson / Moderator


Aug 19, 2003, 4:32 PM

Post #1 of 3 (461 views)

Shortcut

NEW infection W32.Sobig.F@mm

Can't Post | Private Reply
One of my emails that my ISP spam filter SpamAssassin sent to my spam file had a Virus in it. It was just discovered and it (W32.Sobig.F@mm) was the subject of the patch that Norton sent out this morning. So Norton caught it before I had a chance to be infected. But this is too close for comfort. Here is what Norton said about this spam

W32.Sobig.F@mm Discovered on: August 19, 2003 Last Updated on: August 19, 2003 09:24:02 AM


Due to the number of submissions received from customers, Symantec Security Response has upgraded this threat to a Category 3 from a Category 2 threat.

W32.Sobig.F@mm is a mass-mailing, network-aware worm that sends itself to all the email addresses that it finds in the files with the following extensions:
  • .dbx .eml
  • .hlp .htm
  • .html .mht
  • .wab .txt




N2Futur

Aug 20, 2003, 8:55 AM

Post #2 of 3 (449 views)

Shortcut

More info on NEW infection W32.Sobig.F@mm (McAfee)

Can't Post | Private Reply
Here's an e-mail that I just received from Corporate Security at MCI (where I work) regarding this virus :

A new variant of W32/Sobig, W32/Sobig.f@MM is a High Risk mass-mailing worm. It arrives as an email attachment with a .pif or .scr extension. When run, it infects the host computer, then emails itself (using its own SMTP engine) to harvested email addresses from the victim's machine. In addition, when it propagates, the worm "spoofs" the "from: field", using one of the harvested email addresses.Note: The worm copies itself onto the infected machine as: C:\WINNT\WINPPR32.EXE Caution: An infected email can come from addresses you recognize and may contain the following information:

Subject:
- Your details
- Thank you!
- Re: Thank you!
- Re: Details
- Re: Re: My details
- Re: Approved
- Re: Your application
- Re: Wicked screensaver
- Re: That movie

Attachment:

- your_document.pif
- document_all.pif
- thank_you.pif
- your_details.pif
- details.pif
- document_9446.pif
- application.pif
- wicked_scr.scr
- movie0045.pif

Body:

- See the attached file for details
- Please see the attached file for details
Current and up-to-date VirusScan users are protected from this threat.

Learn more about W32/Sobig.f@MM:

==>
http://us.mcafee.com/root/campaign.asp?cid=8449

Scan for W32/Sobig.f@MM:

==>
http://us.mcafee.com/root/campaign.asp?cid=8450

Elke
___________________________
"When choosing between two evils, I always like to pick the one I never tried before." - Mae West

(This post was edited by N2Futur on Aug 20, 2003, 11:28 AM)


johanson / Moderator


Aug 20, 2003, 5:55 PM

Post #3 of 3 (428 views)

Shortcut

Re: [N2Futur] More info on NEW infection W32.Sobig.F@mm (McAfee)

Can't Post | Private Reply
Thanks. That's a mouthful. Hey it's been a whole day now since my Norton found a virus.

I did get another automatic update from Msft today though.

Pete
 
 
Search for (advanced search) Powered by Gossamer Forum v.1.2.4