Author Topic: W32.Sobig.F@mm virus  (Read 494 times)

Offline Eagler

  • Plutonium Member
  • *******
  • Posts: 18758
W32.Sobig.F@mm virus
« on: August 20, 2003, 06:22:54 AM »
had over 300 emails before I left for work with this thing in it ...

you now how long Norton AV takes to step through 300 infected emails?

whats the story with this thing?
"Masters of the Air" Scenario - JG27


Intel Core i7-13700KF | GIGABYTE Z790 AORUS Elite AX | 64GB G.Skill DDR5 | 16GB GIGABYTE RTX 4070 Ti Super | 850 watt ps | pimax Crystal Light | Warthog stick | TM1600 throttle | VKB Mk.V Rudder

Offline Roscoroo

  • Plutonium Member
  • *******
  • Posts: 8424
      • http://www.roscoroo.com/
W32.Sobig.F@mm virus
« Reply #1 on: August 20, 2003, 01:13:44 PM »
http://www.trendmicro.com/vinfo/vir...SOBIG.F&VSect=T

you can read about it in the url i posted ... its a older virus that can be very malicous and keeps getting reborn in a little different form . your safe as long as you dont open/run an email that has it in it.   the worst part is its one of those mass emailing virus's like the klez worm and just as destructive or even more.
Roscoroo ,
"Of course at Uncle Teds restaurant , you have the option to shoot them yourself"  Ted Nugent
(=Ghosts=Scenariroo's  Patch donation

Offline Eagler

  • Plutonium Member
  • *******
  • Posts: 18758
W32.Sobig.F@mm virus
« Reply #2 on: August 20, 2003, 02:12:20 PM »
where does it get the return address from? seems like it copied from my address book as many are valid email addresses
"Masters of the Air" Scenario - JG27


Intel Core i7-13700KF | GIGABYTE Z790 AORUS Elite AX | 64GB G.Skill DDR5 | 16GB GIGABYTE RTX 4070 Ti Super | 850 watt ps | pimax Crystal Light | Warthog stick | TM1600 throttle | VKB Mk.V Rudder

Offline Skuzzy

  • Support Member
  • Administrator
  • *****
  • Posts: 31462
      • HiTech Creations Home Page
W32.Sobig.F@mm virus
« Reply #3 on: August 20, 2003, 02:22:25 PM »
Address books is what it pilfers, for sending and using as a return address.

This is a nasty bugger.  Stealing Internet bandwidth at a horrific rate and typing up email servers at a faster rate.  Basically, this thing is mounting a DOS attack on the Internet adn is being somewhat successful.

Many of our players have this virus and probably do not know it.
Roy "Skuzzy" Neese
support@hitechcreations.com

Offline Eagler

  • Plutonium Member
  • *******
  • Posts: 18758
W32.Sobig.F@mm virus
« Reply #4 on: August 20, 2003, 02:27:26 PM »
so I have to be infected if it is using addresses from my address book as return addy's?

read to check for a certain line in the registry- I did not see it so I thought I was clean.

running AV scan now but slow with 4 big drives
"Masters of the Air" Scenario - JG27


Intel Core i7-13700KF | GIGABYTE Z790 AORUS Elite AX | 64GB G.Skill DDR5 | 16GB GIGABYTE RTX 4070 Ti Super | 850 watt ps | pimax Crystal Light | Warthog stick | TM1600 throttle | VKB Mk.V Rudder

Offline Skuzzy

  • Support Member
  • Administrator
  • *****
  • Posts: 31462
      • HiTech Creations Home Page
W32.Sobig.F@mm virus
« Reply #5 on: August 20, 2003, 02:39:47 PM »
No Eagler, it could have gotten the return address from someone you know that has your address in their address book.
Roy "Skuzzy" Neese
support@hitechcreations.com

Offline boxboy28

  • Gold Member
  • *****
  • Posts: 2265
      • http://none
W32.Sobig.F@mm virus
« Reply #6 on: August 21, 2003, 07:44:51 AM »
hey im getting returned demon mailers (that i didnt send out) with the titles that,  that worm sends out does that mean im infected?
^"^Nazgul^"^    fly with the undead!
Jaxxo got nice tata's  and Lyric is Andre the giant with blond hair!

Offline Shane

  • Platinum Member
  • ******
  • Posts: 7945
W32.Sobig.F@mm virus
« Reply #7 on: August 21, 2003, 07:52:04 AM »
if the "sent to" is from your address book, possibly, if not, then someone who has *you* listed in their address book is.

i was getting this week and half ago... figured it was a guy who had my addy on his mail list for softball since i came up clean for any worm and had already patched that exploit about a month prior.
Surrounded by suck and underwhelmed with mediocrity.
I'm always right, it just takes some poepl longer to come to that realization than others.
I'm not perfect, but I am closer to it than you are.
"...vox populi, vox dei..."  ~Alcuin ca. 798
Truth doesn't need exaggeration.

Offline boxboy28

  • Gold Member
  • *****
  • Posts: 2265
      • http://none
W32.Sobig.F@mm virus
« Reply #8 on: August 21, 2003, 07:54:15 AM »
must be ive got my PCcillian upto date and cant find those files in my registry.
^"^Nazgul^"^    fly with the undead!
Jaxxo got nice tata's  and Lyric is Andre the giant with blond hair!

Offline Eagler

  • Plutonium Member
  • *******
  • Posts: 18758
update
« Reply #9 on: August 22, 2003, 11:53:47 AM »
"Masters of the Air" Scenario - JG27


Intel Core i7-13700KF | GIGABYTE Z790 AORUS Elite AX | 64GB G.Skill DDR5 | 16GB GIGABYTE RTX 4070 Ti Super | 850 watt ps | pimax Crystal Light | Warthog stick | TM1600 throttle | VKB Mk.V Rudder