Jump to content

Back For More : Sobig


Redhat
 Share

Recommended Posts

From BigFix...

Virus: W32.Sobig.F@mm 

W32.Sobig.F@mm is a mass-mailing, network-aware worm that sends itself to all the email addresses it finds in the files with the following extensions:

.dbx

.eml

.hlp

.htm

.html

.mht

.wab

.txt

The worm uses its own SMTP email engine to propagate and will attempt to create a copy of itself on accessible network shares if your computer is on a network.

The email message has the following characteristics:

From: Spoofed address (which means that the sender in the "From" field is most likely not the real sender).

The worm may use the address [email protected] as the sender.

Subject:

Re: Details

Re: Approved

Re: Re: My details

Re: Thank you!

Re: That movie

Re: Wicked screensaver

Re: Your application

Thank you!

Your details

Body:

See the attached file for details

Please see the attached file for details.

- If you receive this mail delete it immediately.

We recommend that you always update your Virus scanner regularly.

For more info click the link below:-

Click HERE for more information and removal tool.

Also a story HERE. Linked from MSFN.

;)

Link to comment
Share on other sites

OK, without trying to sound blasé about this, we have been having some trouble on our work network with this for some time now. Fortunately our network AV is up to scratch, but it was still a pain to get several phone calls a day from users saying "I've just had an email with a virus, what should I do about it?" to which the reply would always go.... "Did you do as the virus scanner suggested, and delete the infected file?"

However, we did notice the trend, and put a rule in our mail server that intercepted anything with a .pif extension. What a result!!!! In the last two weeks, we have stopped nearly 1500 mails from reaching their intended recipients. I hate to think how many phone calls we would have had otherwise.

My point is, that nobody these days needs to use .pif files, and as these seem to be the main virus spreading route for the current batch of infections, why the hell can't ISP's block these at their mail servers and save everybody a whole load of grief??????????????

Mr. M.

Link to comment
Share on other sites

My point is, that nobody these days needs to use .pif files, and as these seem to be the main virus spreading route for the current batch of infections, why the hell can't ISP's block these at their mail servers and save everybody a whole load of grief??????????????

because mr m. that would be logical and make everybodies life easier and its just not the done thing.

Its like when in an office full of men, all is working well so what happens? The powers that be decide to throw in a woman and all hell brakes loose. Logic goes out of the window and no-one knows whats going on any more......

anyway, well done on stopping the virii dead in their tracks, perhaps you should start your own ISP..............i know i'd subscribe!

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy