|
Since surfacing
late on Monday, Sobig.F has been crippling corporate e-mail networks
and filling home users' in boxes with a glut of messages. Hypponen
estimated that Sobig.F had generated close to 100 million emails.
Once the file
is opened, Sobig.F resends itself to scores of email addresses from
the infected computer and signs the email using a random
name and address from the infected computer's address book. this
means that the person who appeared to send you the virus was not
the sender.
The worm de-activates
on September 10, 2003. The last day on which the worm will spread
is September 9, 2003 so we will all be annoyed for quite some time
to come.
What
is it?
W32.Sobig.F@mm is a mass-mailing, network-aware worm that sends
itself to all the email addresses it finds. The worm uses its own
SMTP engine to propagate from
Spoofed
address (which means that the sender in the "From" field
is most likely not the real sender). The worm may also use the address
admin@internet.com as the sender.
NOTES:
The spoofed addresses and the Send To addresses are both taken from
the files found on the computer. Also, the worm may use the settings
of the infected computer's settings to check for an SMTP server
to contact.
The choice of the internet.com domain appears to be arbitrary and
does not have any connection to the actual domain or its parent
company.
Subject:
Re: Details
Re: Approved
Re: Re: My details
Re: Thank you!
Re: That movie
Re: Wicked screensaver
Re: Your application
Thank you!
Your details
What
do you do?
Keep your virus protection updated both Symantec
and McAfee have added updates
that protect against this virus, If you have not updated your virus
definitions since 8-20-2003 do so immoderately, this will protect
you from future mail containing the virus. Don't waste your
time contacting people who sent you the virus - they weren't the
real sender. Protect your computer and hopefully by September 10th
you will stop receiving these messages.
How
do you get rid of the Virus?
Both Symantec and McAfee
have removal tools available from their web sites. click the links
and follow the instructions by either vendor (choose the vendor
of the anti virus software you currently use)
Related
Articles
Symantic
- Sobig Virus Info
McAfee
Security - Sobig Virus Info
Global Race Against the Clock to Beat Sobig Virus Fri
Aug 22, 9:23 AM ET
Survey: Worm Infects 30 Pct of China E-Mail Users Fri
Aug 22, 3:23 AM ET
Virus
That Infects E-Mails Expanding Its Reach Thu
Aug 21, 8:24 PM ET
SoBig
Worm Aims to Turn PCs Into Spam Machines Thu
Aug 21,10:03 AM ET
|