Posted on 04/19/2005 1:52:01 PM PDT by infocats
Virus writers have resurrected the Sober worm with a new variant that is spreading quickly over the Internet.
Security experts said Tuesday that the worm, dubbed Sober.M, reports e-mail addresses of victims back to its anonymous author--a technique known as harvesting. Spammers typically buy these fresh addresses to add to their lists of e-mail recipients.
The e-mail containing the worm is written in bad English with the subject line: "I've got your e-mail on my account."
"It looks like the virus writer is deliberately using broken English to (convince) people the e-mail is not a virus," Graham Cluley, senior technology consultant at antivirus company Sophos, said in a statement.
Sophos said that the new Sober variant was the fifth most reported virus over the last 24 hours, closely followed by versions of Zafi and Netsky. It's thought that all the major antivirus companies are now offering protection against the worm, so users should update their virus protection.
Sober.M is a mass e-mailing virus that spreads as a .zip file attachment and affects systems running Microsoft Windows. The e-mail containing the worm sends itself in German or English language. The English version of the e-mail is below.
Subject line: I've_got your E-mail on my_account!
Message text:
Hello,
First, Very Sorry for my bad English.
Someone is sending your private e-mails on my address.
It's probably an e-mail provider error!
At time, I've got over 10 mails on my account, but the recipient are you.
I have copied all the mail text in the windows text-editor for you & zipped then.
Make sure, that this mails don't come in my mail-box again.
bye
Attached file: your_text.zip
I just keep getting mail from MY Email address but from a different provider....ie I am let say Vaquero@Yahoo.com and I get mail from Vaquero@hotmail.com...well as it turns out there is and attachment which is a virus.....I have never opened it, but I have forwarded it to my work email address and boy did it send off bells and whistles.....anyway thats how I check for viruses....the IT guy wanted to know who sent me the virus and I said "I did, I didnt know what it was so I sent it here figuring if it was evil you guy would figure it out".
But since my IQ exceeds that of a flying squirrel, I delete these, without opening the attachments.
If everyone would do the same the problem would go away.
I've have yet to see an spam email, virus, or any other nefarious item from the internet that was NOT in anything but broken english.
Protect yourselves!
And you're still gainfully employed?
Maybe someone can help me with a quick question.
I just installed new anti-virus software (McFee VirusScan Enterprise 8.0.0). Is there any way to tell if it's working okay on my computer? Is there any way to make sure it's turned "on"?
Are you asking someone to mail you a virus to test it? I'm sorry but I laughed at that image.
That's wasn't what I had in mind. I was hoping there'd be a web page I could visit to test my computer or something -- maybe they have a benign or "dead" virus they could send me as a test.
There used to be a "test virus," but I can't remember the name. It was a line of text typed (looked like gibberish) but wasn't active, and was saved in a .txt file. The scanner would pick up on the text and alert the user.
It's called Eicars
Thanks - I hate getting old.
We don't figure out viruses at my company. We don't have time to play patty-cake like you play with your IT staff. We just delete the message and let the executive figure out why he didn't receive it.
On those rare occasions when the executive finally does chase us down and asks us why he didn't get a particular message, we shrug our shoulders or we tell the executive that the sender has a virus and we blocked all mail coming from him and tell the executive to tell the sender to clean up his computer otherwise his mail won't ever get through and go back to helping the pretty girl.
At least with her, there's a chance for a pay-off. When you help an executive, all you get is more stupid questions and idiotic behavior.
Yes. Would you like for me to send you a copy of the worm described in this article? I've gotten a few today, and am perfectly willing to share. Since this virus only works against people who use windows, it was kinda wasted on me.
I got email today from NAVMSE with subject line: Norton AntiVirus detected and quarantined a virus in a message you sent. The body of email said following: "Recipient of the infected attachment: SBS, First Storage Group\Mailbox Store (SBS), Patty Pierce/Inbox
Subject of the message: [spamcatcher] report
One or more attachments were quarantined.
Attachment secrets_attachment.doc.exe was Quarantined for the following reasons:
Virus W32.Netsky.C@mm was found."
DO YOU THINK THIS IS LEGIT? I can't find virus anywhere. Thanks
Done. Microsoft platforms and tools are never used for e-mail around here.
Ummm.... yeah.
Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.