PDA

View Full Version : Newer Virus?



Fantum309
08-20-2003, 03:36 AM
SAN FRANCISCO (Aug. 19) - A new mass e-mail worm that attempts to download files from the Internet and potentially leave computers vulnerable to further attack was spreading quickly around the world on Tuesday, anti-virus experts said.

The new worm, dubbed Sobig.F, is at least the fourth new, major Internet worm to hit computers worldwide in the past week, prompting anti-virus vendor F-Secure to declare this the ''worst virus week ever.''

Sobig.F, a variant of an older worm, began spreading on Monday in Europe and has infected an estimated tens of thousands of Windows-based computers, said Patrick Hinojosa, chief technology officer at Panda Software, based in Madrid.

It arrives in e-mail and includes a variety of subject lines, including ''Your details,'' ''Thank you!,'' ''Your application'' and ''Wicked screensaver.'' It has caused some corporate e-mail systems to grind to a halt, according to Sophos Inc.

When the .pif or .scr attachment is opened, Sobig.F infects the computer and sends itself on to other victims using a random e-mail address from the address book.

It also prepares the computer to receive orders and tries to download files from the Internet, said Hinojosa. It was unknown exactly what files they were, he said.

If the infected computer is on a shared network, the worm tries to copy itself to the other computers on that network.

The worm is programmed to stop spreading on Sept. 10.

Network Associates Inc. (NET.N) has rated Sobig.F a medium risk because of the quick rate of spread, said Jimmy Kuo, research fellow at Network Associates, an anti-virus software vendor.

Sobig.F was spreading at an ''alarming rate,'' accounting for nearly 80 percent of all infection reports recorded on Tuesday, according to anti-virus provider Central Command.

Sobig.F comes on the heels of the Blaster, or LoveSan, worm which hit hundreds of thousands of computers worldwide last week, spreading to victims through a security hole in the Windows operating system and crashing them.

On Monday, another worm surfaced that was written to remove Blaster from infected computers and patch the hole. That worm, dubbed ''Welchia'' or ''Nachi,'' was temporarily paralyzing many corporate networks, experts reported.

In addition, an e-mail hoax was circulating, purporting to be a patch from Microsoft for the security hole Blaster exploits. But the e-mail instead contains a Trojan application that installs itself on the computer as a back door enabling an attacker remote access to the system.

There has not been so much virus activity since the Code Red and Nimda worms hit about a year ago, experts said.

Reuters 18:36 08-19-03

FlameRush
08-20-2003, 04:26 AM
OHLY ****
I got an email from one of my bros clan members saying the Coporate email stuff...
Im glad I didnt open it if it wasnt a hoax...

Slice
08-20-2003, 04:50 AM
Ha ha I just clicked that link in your sig VS. Looks like you got suspended for some reason from the project host. Gee I wonder what i could be. :rolleyes:

ME BIGGD01
08-20-2003, 05:13 AM
this virus was just sent to me an hour ago. nortons picked it right up :thumbs:

ME BIGGD01
08-20-2003, 05:14 AM
:bandhead:

OUTLAWS BIOHAZARD
08-20-2003, 05:16 AM
All this virus mess hasen't hit me yet but if it does I will be alot of fun to get it off.

Thanks alot!
BIOHAZARD

V98ci
08-20-2003, 05:32 AM
Originally posted by ME BIGGD01@Aug 20 2003, 12:14 AM
:bandhead:
Dam Bigg, that sux! :bandhead: :bandhead: :bandhead:
Thank God for Norton! :thumbs: :thumbs: :thumbs:

Elessar
08-20-2003, 05:35 AM
Glad i only use hosted emails that i never even use :drink:

Fantum309
08-20-2003, 05:44 AM
Originally posted by ME BIGGD01@Aug 20 2003, 01:13 AM
this virus was just sent to me an hour ago. nortons picked it right up :thumbs:
wow, that scares me! I have Norton, but I still worry about these damn virus's. I just updated my virus def's, scanned my system, and then backed up all my important files and pics. I guess I'm ready.

FlameRush
08-20-2003, 07:19 AM
Originally posted by Slice@Aug 19 2003, 11:50 PM
Ha ha I just clicked that link in your sig VS. Looks like you got suspended for some reason from the project host. Gee I wonder what i could be. :rolleyes:
Yes, I did the project, and was going to make a website, but the admin suspended it, because no website, now I just added a comment in the Project page, and now hopefully they see it, so it can get up and running...
If anyone wants to join, they have to have a moddb name, so I can put it in if the project is accepted...

YoungGun
08-20-2003, 02:41 PM
another blaster worm? http://securityresponse.symantec.com/avcen...lchia.worm.html (http://securityresponse.symantec.com/avcenter/venc/data/w32.welchia.worm.html)

Death-Dude
08-20-2003, 04:09 PM
Originally posted by V98ci+Aug 19 2003, 11:32 PM--></span><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td>QUOTE (V98ci @ Aug 19 2003, 11:32 PM)</td></tr><tr><td id='QUOTE'> <!--QuoteBegin--ME BIGGD01@Aug 20 2003, 12:14 AM
:bandhead:
Dam Bigg, that sux&#33; :bandhead: :bandhead: :bandhead:
Thank God for Norton&#33; :thumbs: :thumbs: :thumbs: [/b][/quote]
No, it doesn&#39;t suck, he had it stopped&#33; :jammin:

Good to keep your AV updated daily while this junk is teeming, and do a system scan if you&#39;re AFK for a while.

OUTLAWS Ada
08-20-2003, 05:59 PM
I had 8 emails the same in my msn hotmail in box about a net messenger update - looked dodgey so I deleted them all. Thought I say incase anyone els had the same.

Morpheus
08-20-2003, 11:40 PM
Originally posted by OUTLAWS Ada@Aug 20 2003, 01:59 PM
I had 8 emails the same in my msn hotmail in box about a net messenger update - looked dodgey so I deleted them all. Thought I say incase anyone els had the same.
There wasn&#39;t a messenger update today, i have it on auto update. :thumbs: