PDA

View Full Version : SoBig virus



lava
August 19th, 2003, 05:52 PM
is anyone getting this virus? I'm interesting in knowing how propagated this is... a variant apparently was released this morning, and it hit someone at our office. We don't know who it is yet.

Someone around you has the virus when you get a bunch of emails with the headers:

Your details
Thank you!
Re: Thank you!
Re: Details
Re: Re: My details
Re: Approved
Re: Your application
Re: Wicked screensaver
Re: That movie

Usually, you can't tell who the virus is from, since it has its own SMTP engine to create the email messages, and it uses the addresses on the victim's machine.

Let me know if you've been affected.
Thanks
raf

DariusMonsef
August 19th, 2003, 05:56 PM
Yes it's out in full force. I have received 53 virus emails today and they keep rolling in.

... do people not know that anti-virus software exists?

λ
August 19th, 2003, 05:58 PM
I can just imagine the shame... everybody in your office has to have a virus scan, and it turns out to be you :P. Ouch!

That virus doesn't seem too dangerous, because the headers are set, so you know what to expect. Some viruses use phrases picked from files on your hard drive, so they're more dangerous, because you can't tell people to avoid certain emails.

fez
August 19th, 2003, 07:43 PM
weird...ive gotten the spanish ones except from myself, i checked and my machine is clean.


i cant resist...
oh lava, this virus is soooo big

Maxtr0sity
August 19th, 2003, 08:41 PM
I've been getting a LOT of junk mail from random people through Outlook Express that starts with "Re: " in the title. But doesn't seem to affect me, what does it do?

lava
August 19th, 2003, 09:06 PM
the annoyance is that it creates a lot of email traffic. We've eliminated some possibilities as to who the person is. Basically, its someone that hasn't emailed me yet, because the virus isn't sending emails to me. (I'm a pretty new employee where I work.) We've narrowed it down to a couple of people, but so far they have been unreachable, and they work out of the office, so we can't do anything about it. I'm pretty sure my coworkers' mailboxes are bouncing back emails now because they're so full. One of my coworkers was getting 7 emails a minute.

BadMagick
August 19th, 2003, 11:58 PM
That's why I use MSN mail for all my "junk" mail. It's always nice to have a super secret email for the important stuff.

NaliWarCow
August 20th, 2003, 12:02 AM
i'm switching to linux soon if MS doesn't fix al these viruses. This is the most i've seen come out in such a short amount of time.

lava
August 20th, 2003, 01:51 AM
Even then though, you'd still have the annoyance of receiving all those email messages.

I guess someone that had me on their contact list sent out an email faking my school email address to the department of defense... it was kind of funny receiving a rejected email from them.

I doubt that anyone in this forum would fall succeptible to this virus, but it's all the dumb people we know (that would open the stupid attachment) that really screw us.

Jasninder
August 20th, 2003, 02:21 AM
Guess wat?

i m getting viruses from peoples resume, i posted an advertisement in the newspaper couple of days back as i m recruiting few developers/designers and i m getting viruses wid
subjects like " attachecd my cv" "my resume" and so on....
i got 180 mails and 138 had viruses in them and i always get emails like:"last night was great, here are some pics " :P

DariusMonsef
August 20th, 2003, 03:36 AM
I'm up to 200+ viruses today. I have Norton so it alerts me everytime a virus comes in. Problem is I get one every 30 seconds 5 minutes or so. So I have this alert pop-up I have to confirm before it continues to check my mail

Very annoying.

Jasninder
August 20th, 2003, 05:41 AM
oh thats annoying man, have u tried tracing it?

kirupa
August 20th, 2003, 08:41 AM
300+ viruses of that exact same one. Ethan - disable the alert thing in Norton. I have mine set to silenty delete - It works in the background and doesn't bother me.

Niann
August 20th, 2003, 09:56 AM
We had one person in the office get a bunch of emails like that, but Mcafee zapped those little guys dead. =) Otherwise it has yet to bother me. Of course I don't give my work email out to anyone that doesn't need it for work stuff. :)

Cheers!
-Niann

Maxtr0sity
August 20th, 2003, 09:57 AM
I'm considering AVG since all the latest attacks though. Even though I don't use AV softwares. Can someone give me the site for that?

BadMagick
August 20th, 2003, 12:46 PM
In the year that I've had my new laptop, I have not recieved a virus in the mail, my regular inbox or my junk mail account on MSN.

The only viruses I've gotten were when I was crawling the school's network looking for movies/songs to download, and shared printers to use on people's computers. Nortons picked them up right away ... even got rid of those files on the other computers causing the infection!

I take extra special care of my computer, and it takes extra special care of me :)

- Just an update, PA's government network is down from this virus ... you wouldn't believe how many stupid people work for the state

DariusMonsef
August 20th, 2003, 07:28 PM
Mother. F*****

I have received 500+ of these now and I just had a client email me who was very, very upset because he is getting spammed. I had to explain to him that this is not mine or his websites fault.

Does anyone know if the virus sends to everyone in an address book as everyone in the address book. So my address book with 10 people will end up sending 100 emails?

lava
August 20th, 2003, 07:42 PM
it takes the email addresses from your address books and from any html files you might have on your computer.

if the emails come from you, it doesn't mean that you have. It means that someone who has your email address has it. The virus doesn't really send it as coming from the infected computer.

lava
August 20th, 2003, 07:43 PM
Oh, here's more information on the virus... wow, network associates upgraded it from medium to high risk...
http://us.mcafee.com/virusInfo/default.asp?id=helpCenter&hcName=sobig

DariusMonsef
August 20th, 2003, 07:44 PM
Yeah I know about the spoofing, jsut wondering if it justs sends one to each person or one to each person from each person.

Thanks for the info though.

awligon
August 23rd, 2003, 11:05 PM
I have been infected with the kirupaForum mailer virus. I get like 20-50 emails a day from this spoofed name. No hope for removal.

Voetsjoeba
August 24th, 2003, 01:06 AM
The servers of my IP are down at certain times because of e-mail overflow due to this virus. I've never got those mails though.

The Don
August 24th, 2003, 02:30 AM
Yeah, it does scan all of the files in your computer for traces of any email address that it might find. This also means Temporary Internet Files (but they usually get deleted on close of IE.)

So Far, I haven't been hit by big time viruses like Blaster or SoBig. But my hotmail account gets a whole bunch of RE: STUFF YOU DON'T NEED!!!11 Spam mail but none has any attachments of any kind...