Yet Another Bulletin Board

Welcome, Guest. Please Login or Register.
Nov 25th, 2024, 9:56am

Home Home Help Help Search Search Members Members Member Map Member Map Login Login Register Register
Clusterheadaches.com Message Board « WARNING---W32/Sober.p@MM »


   Clusterheadaches.com Message Board
   New Message Board Archives
   2005 General Board Posts
(Moderator: DJ)
   WARNING---W32/Sober.p@MM
« Previous topic | Next topic »
Pages: 1  Reply Reply Notify of replies Notify of replies Send Topic Send Topic Print Print
   Author  Topic: WARNING---W32/Sober.p@MM  (Read 184 times)
The  mad viking
CH.com Alumnus
New Board Hall of Famer
Norway 
*****




Always Look on The Bright Side of Life

  svennthorn2003@yahoo.no  
WWW Email

Gender: male
Posts: 3135
WARNING---W32/Sober.p@MM
« on: May 4th, 2005, 7:57pm »
Quote Quote Modify Modify

What is it?
Another variant of the Sober virus, W32/Sober.p@MM is a Medium Risk mass-mailing worm hiding inside an email attachment. When run, the worm displays a fake error message, infects the host computer and sends itself to the email addresses that are harvested from the infected machine. Like many Sober variants, this variant uses several different email messages randomly, in either English or German depending on the version of Windows.  
 
 
What should I look for?
 
FROM: Varies (forged addresses taken from infected system)  
SUBJECT: Examples: English: Your Password  
German: WM-Ticket-Auslosung  
BODY: Examples:  
English: Account and Password Information are attached!  
German: Herzlichen Glueckwunsch,
beim Run auf die begehrten Tickets für die 64 Spiele der Weltmeisterschaft 2006 in Deutschland sind Sie dabei.  
ATTACHMENT: account_info.zip, autoemail-text.zip, LOL.zip, Fifa_Info-Text.zip, mail_info.zip, okTicket-info.zip, our_secret.zip, _PassWort-Info.zip  
 
 
How do I know if I've been infected?  
When the ZIP archive is extracted and the contained PIF file is manually executed, the virus may display a fake error message which reads "Error: CRC not complete".  
 
 
 
How do I find out more?
 
View details about W32/Sober.p@MM here.    http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=13 3409&cid=14461
 
 
You know what to do folks
 
Svenn
« Last Edit: May 4th, 2005, 7:58pm by The  mad viking » IP Logged

Always Look on The Bright Side of Life
Jonny
CH.com Alumnus
New Board Hall of Famer
USA 
*****




Give me a shovel Ill dig my own grave!

   
WWW Email

Gender: male
Posts: 26213
Re: WARNING---W32/Sober.p@MM
« Reply #1 on: May 4th, 2005, 8:12pm »
Quote Quote Modify Modify

If you dont know who sent it....dont open it  Wink
 
Night Night Grin
IP Logged

It is up to YOU to educate yourself and then help your doctor plan your treatment. If you just sit down in front of your doctor and say "make me better" you are setting yourself up for a great deal of pain.

- Guiseppi


Charlie
CH.com Alumnus
New Board Hall of Famer
USA 
*****




Happy to be here

135447360 135447360   mondocharlie   mondocharlie
Email

Gender: male
Posts: 14968
Re: WARNING---W32/Sober.p@MM
« Reply #2 on: May 4th, 2005, 8:18pm »
Quote Quote Modify Modify

Thanks Svenn.  
 
Yikes. They're really out in force today. Getting lots of warnings but I even check them first.
 
Charlie
IP Logged

There is nothing more satisfying than being shot at without result---Winston Churchill
Gator
CH.com Alumnus
New Board Hall of Famer

*****





   


Gender: male
Posts: 4556
Re: WARNING---W32/Sober.p@MM
« Reply #3 on: May 4th, 2005, 9:43pm »
Quote Quote Modify Modify

on May 4th, 2005, 8:12pm, Jonny wrote:
If you dont know who sent it....dont open it  Wink
 
Night Night Grin

 
 
Even if you do know the person who sent it, be careful.  That person's infected computer may be sending you a virus without his/her knowledge.
 
IP Logged
Opus
New Board Hall of Famer
USA 
*****




(Insert witty comment here)

  pjbgravely   pjbgravely
WWW Email

Gender: male
Posts: 2509
Re: WARNING---W32/Sober.p@MM
« Reply #4 on: May 5th, 2005, 12:13am »
Quote Quote Modify Modify

on May 4th, 2005, 7:57pm, Svenn wrote:
W32/Sober.p@MM is a Medium Risk mass-mailing worm hiding inside an email attachment.  

What a contradiction in terms, by definition , a Worm is Malware that doesn't need to be clicked on to infect and spread. There really are no mass mailing worms since they would have to infect without even being read.
 
These Viruses must know I use Linux, I never seem to get them anymore, but my wife still does.
 
Opus/Paul smokin
IP Logged

Zed-Zed-nine plural-Zed alpha,

There is no place like home.
ExplodingEyeBall
New Board Hall of Famer
USA 
*****




I can't think of anything clever to put here.

   


Gender: male
Posts: 2589
Re: WARNING---W32/Sober.p@MM
« Reply #5 on: May 5th, 2005, 9:51am »
Quote Quote Modify Modify

on May 4th, 2005, 8:12pm, Jonny wrote:
If you dont know who sent it....dont open it  Wink
 
Night Night Grin

 
If you weren't expecting it and it came from someone you know, call them and ask about it before you open it.
 
If you don't know the sender, delete it.
IP Logged

Just poke out my eye and get it over with!!!
nani
CH.com Alumnus
New Board Hall of Famer
USA 
*****




Got kudzu?

   
WWW

Gender: female
Posts: 7953
Re: WARNING---W32/Sober.p@MM
« Reply #6 on: May 5th, 2005, 9:53am »
Quote Quote Modify Modify

I've probably gotten another 50 of them since yesterday. The attachment size is 73KB and they come from all kinds of "official" looking addresses.
IP Logged

Others may come and go, but MY power is MINE.
sandie99
New Board Hall of Famer
Finland 
*****




Wish it, dream it, do it - inspite the pain!

   


Gender: female
Posts: 10429
Re: WARNING---W32/Sober.p@MM
« Reply #7 on: May 5th, 2005, 9:58am »
Quote Quote Modify Modify

Thanks for the warning!  Smiley
IP Logged

CH happends, Live anyway! PF days to us all!

"Do what you can and let God take care of the rest. Leave your heart wide open and always wish for the best" (Sanna Hillu)

"No matter how far out your dreams are, it's possible" (Marketa Irglova)


Kirk
CH.com Alumnus
New Board Hall of Famer
USA 
*****




VINIMUS, VIDIMUS, DOLAVIMUS

161860987 161860987   kirk_jones511   krkevrtt
Email

Gender: male
Posts: 1914
Re: WARNING---W32/Sober.p@MM
« Reply #8 on: May 5th, 2005, 12:41pm »
Quote Quote Modify Modify

smartass2
IP Logged

Pages: 1  Reply Reply Notify of replies Notify of replies Send Topic Send Topic Print Print

« Previous topic | Next topic »


Clusterheadaches.com Message Board » Powered by YaBB 1 Gold - SP 1.3.1!
YaBB © 2000-2003. All Rights Reserved.


©1998-2010 Web Vision Enterprises All rights reserved. All information on this site is protected by international copyright laws. You may not re-distribute any information from this site without written permission from Web Vision Enterprises and the webmaster of this site. Violators will be prosecuted.
You may view our privacy policy and financial disclosure statement here

test rss