Worm Sobig.F

I don’t know what is going on today but I have already received nearly two dozen emails that are infected with the sobig.f worm.

The Subject lines have included:

Re: Details
Re: Approved
Re: Re: My details
Re: Thank you!
Re: That movie
Re: Wicked screensaver
Re: Your application
Thank you!
Your details

The messages simply say:

See the attached file for details

or

Please see the attached file for details.

The attachments are alway .pif or .scr files with these names:

your_document.pif
document_all.pif
thank_you.pif
your_details.pif
details.pif
document_9446.pif
application.pif
wicked_scr.scr
movie0045.pif

More info at Trend Micro or Symantec

This worm has been around since August 17 but this is the first time I have seen it in my email inbox. I have simply deleted them so there is no problem with them infecting my computer. Has anybody else been getting a large number worm infected emails today?

I got loads at work last week. Not at home because, 1)very very few have my home email address and 2) I have an Apple.
Yes, I know Apples aren’t totally immune, but they’re 1000 times safer at least.

I got 5 in one hit to my ‘proper’ email address, but that’s all.

My yahoo box must have had close to 300, which is odd because it’s a new account and hasn’t been widely circulated. My hotmail, which is years old and gets 20 spam messages a day, hasn’t had one.

They’ve all apparently come from .tw domains.

Why has no one invented a virus for mp3s yet? One that appends itself to all the illegal music files in the world and circulates through p2p networks?

I’m sure the music industry would (quietly) pay a fortune to have something like that discouraging file sharing.

I’ve had a steady 3 or 4 per day for the last week (to my Yahoo account), with varied subject lines as described by Tye Phoodza.

I guess none of these idiots have ever read their EULA. :unamused:

Microsoft urged to compensate virus victims

Microsoft should compensate users of its flawed operating system is vulnerable to computer viruses, Taiwan’s Consumers Foundation said yesterday.

Citing the law protecting consumers, the foundation said the software giant should make up the losses stemming from its inferior products.

Alleged defects in the design has made Microsoft’s operating systems vulnerable to viruses, which wreaked havoc on the Internet causing huge losses worldwide last month.

Microsoft cannot be exempt from any responsibility only with a disclaimer attached to its products, the foundation said.

It called on the government’s Consumer Protection Commission to intervene, and promised to file a legal suit against Microsoft for compensation on behalf of victimized consumers. Microsoft must fix the problems and provide a safer system, the foundation said at a press conference it arranged.

Taiwan’s Microsoft was invited to the press conference, but declined to send representatives.

chinapost.com.tw/detail.asp? … A&id=20353

If you’re not ready to ditch Windows for Linux, as least use Opera. Opera doesn’t allow your e-mail to do damaging things to your computer. Why Microsoft thought it would be a cool idea to let emails automatically run code I’ll never know. Even more strange, why would Microsoft want to allow emails to access the web for you and download things without asking permission from the user?

Speaking of which, Taiwan’s very own Richard Storey has a just published report on Debian Linux here:

distrowatch.com/dwres.php?re … iew-debian

and the discussion is at osnews.com/ :

osnews.com/comment.php?news_id=4419

I’m getting an average of maybe 40 a day or so… Since each one is 100k, that’s about 4 megs or so a day… I normally only have 3 megs of space open, so if I don’t clear out my Bulk folder every few hours, I run out of space.

Thanks be to the wonderful people out there that do stuff like this.

I’ve been getting 5 to 15 a day for a couple weeks. What a pain! :smiling_imp:

I get about 10-15 a day in each of my two e-mail accounts. Most of the domains are either .tw or .jp. I’m really getting annoyed … when is this crap gonna stop!!! :imp: :imp: :imp:

It will stop when M$ gets it together, which is to say probably never. Stop whinging and buy a Mac or run Linux.

Doesn’t that trick work where the first entry in your Outlook address book is “!!!0000?”

I had been getting about 50 per day, I set up a filter to move all of them to the trash automatically, one day last week I got about 100, but there was no attachment, luckily!

“!!!0000?” is suppoviely only supposed to work for outgoing messages. I set up a fake email account in my outlook I call it virus.email.com, it doesn’t exist and I made it my default for sending mail in hopes if I get a virus it won’t be able to send anything because there is no where for it to go, so far so good.

[quote=“Quirky”]Doesn’t that trick work where the first entry in your Outlook address book is “!!!0000?”[/quote]Nope, it doesn’t
cnet.com/techtrends/0-731112 … 148-1.html
vmyths.com/hoax.cfm?id=263&page= … on-experts

I am still getting dozens of infected emails from all over the world every day. Hopefully this worm will die down soon.

[quote=“Symantec”]* The worm de-activates on September 10, 2003. The last day on which the worm will spread is September 9, 2003.

  • The aforementioned de-activation date applies only to the mass-mailing, network propagation, and email address collection routines. This means that a W32.Sobig.F@mm-infected computer will still attempt to download the updates from the respective list of master servers during the associated trigger period, even after the infection de-activation date. Previous variants of Sobig exhibited similar behavior.[/quote]

Did everyone scan to see if their computer was infected with the worm? Anybody here get infected? My computer was clean.

Symantec Security Response page for the sobig.f worm
.

Speaking of which, Taiwan’s very own Richard Storey has a just published report on Debian Linux here:

distrowatch.com/dwres.php?re … iew-debian

and the discussion is at osnews.com/ :

osnews.com/comment.php?news_id=4419[/quote]

The second installment has just been published and is here:

distrowatch.com/dwres.php?re … iew-debian

[quote=“Tye Phoodza”]I am still getting dozens of infected emails from all over the world every day. Hopefully this worm will die down soon.

[quote=“Symantec”]* The worm de-activates on September 10, 2003. The last day on which the worm will spread is September 9, 2003.

  • The aforementioned de-activation date applies only to the mass-mailing, network propagation, and email address collection routines. This means that a W32.Sobig.F@mm-infected computer will still attempt to download the updates from the respective list of master servers during the associated trigger period, even after the infection de-activation date. Previous variants of Sobig exhibited similar behavior.[/quote][/quote]

I was getting 30 a day for several weeks. Didn’t get anything yesterday evening and nothing so far today. Maybe Symantec is right and the worm de-activated Sept. 10. If so, this round is finally over. I am afraid though that whatever comes in the future is going to be worse.