Jump to content
  • GUESTS

    If You  want access  to member only forums on FM, You will need to Sign-in or  Sign-Up now .

    This box will disappear once you are signed in as a member.

Some sort of Virus going around?


Uncle Grump

Recommended Posts

Hi all

Lately I am getting a ton of emails which
have a 1 liner message which says "see the
attached file for details", and has an attachment which is 1K in size.

The subject line varys - its been:

Re: Wicked screen saver
Re: Your Application
Re: Details
Re: That movie
Your Details
and other stuff as well....

The real intersting part is that one of the
latest ones to come in was supposedly from
Rick here at FM!

I been deleting these critters. Any one else been getting them or know more details?

UG

Link to comment
Share on other sites


WORM_SOBIG.F




Overview Technical Details Statistics





QUICK LINKS Solution

--------------------------------------------------------------------------------

Virus type: Worm

Destructive: No

Aliases: Win32.HLLM.Reteras, W32.Sobig.F@mm, W32/Sobig.f@MM, Sobig.F, Win32.Sobig.F, W32/Sobig-F, I-Worm.Sobig.f

Pattern file needed: 617

Scan engine needed: 6.100

Overall risk rating: Medium

--------------------------------------------------------------------------------

Reported infections: Medium

Damage Potential: High

Distribution Potential: High

--------------------------------------------------------------------------------

Description:

TrendLabs has received several infection reports of this mass-mailing worm from Norway and Spain. As of 12:19 PM GMT, Trend Micro has declared a Medium Risk alert to control the spread of this malware.

This worm propagates by mass-mailing copies of itself using its own Simple Mail Transfer Protocol (SMTP) engine. It collects email addresses from files with the following extensions:


DBX
HLP
MHT
WAB
HTML
HTM
TXT
EML
It sends out email messages with the following details:

Subject: <any of the following:>
Re: Thank you!
Thank you!
Re: Details
Re: Re: My details
Re: Approved
Re: Your application
Re: Wicked screensaver
Re: That movie

Message body: <any of the following:>
See the attached file for details.
Please see the attached file for details.

Attachment: <any of the following:>
your_document.pif
document_all.pif
thank_you.pif
your_details.pif
details.pif
document_9446.pif
application.pif
wicked_scr.scr
movie0045.pif

It may spoof the FROM field using email addresses found on the infected machine so that its email messages appear to originate from one source but was actually sent from another.

This worm deactivates its propagation routine on September 10, 2003.

This worm runs on Windows 95, 98, ME, NT, 2000, and XP.

Solution:

AUTOMATIC REMOVAL INSTRUCTIONS

To automatically remove this malware from your system, please use the Trend Micro System Cleaner.

MANUAL REMOVAL INSTRUCTIONS

Identifying the Malware Program

To remove this malware, first identify the malware program.

Scan your system with your Trend Micro antivirus product.
NOTE all files detected as WORM_SOBIG.F.
Trend Micro customers need to download the latest pattern file before scanning their system. Other Internet users may use Housecall, Trend Micro’s free online virus scanner.

Terminating the Malware Program

This procedure terminates the running malware process from memory. You will need the name(s) of the file(s) detected earlier.

Open Windows Task Manager.
On Windows 95/98/ME systems, press
CTRL+ALT+DELETE
On Windows NT/2000/XP systems, press
CTRL+SHIFT+ESC, then click the Processes tab.
In the list of running programs*, locate the malware file or files detected earlier.
Select one of the detected files, then press either the End Task or the End Process button, depending on the version of Windows on your system.
Do the same for all detected malware files in the list of running processes.
To check if the malware process has been terminated, close Task Manager, and then open it again.
Close Task Manager.
*NOTE: On systems running Windows 95/98/ME, Task Manager may not show certain processes. You may use a third party process viewer to terminate the malware process. Otherwise, continue with the next procedure, noting additional instructions.

Removing Autostart Entries from the Registry

Removing autostart entries from the registry prevents the malware from executing during startup.

To remove the malware autostart entries:

Open Registry Editor. To do this, click Start>Run, type Regedit, then press Enter.
In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>
CurrentVersion>Run
In the right panel, locate and delete the entry or entries:
TrayX = "%Windows%\winppr32.exe /sinc"
(Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)
In the left panel, double-click the following:
HKEY_CURRENT_USER>Software>Microsoft>Windows>
CurrentVersion>Run
In the right panel, locate and delete the entry or entries:
TrayX = "%Windows%\winppr32.exe /sinc"
Close Registry Editor.
NOTE: If you were not able to terminate the malware process from memory as described in the previous procedure, restart your system.
Deleting Dropped File

Right-click Start then click Search… or Find… depending on your version of Windows.
In the Named input box, type:
WINSTT32.DAT
In the Look In drop-down list, select the drive which contains Windows, then press Enter.
Once located, select the file then hit Delete.
Running Trend Micro Antivirus

Scan your system with Trend Micro antivirus and delete all files detected as WORM_SOBIG.F. To do this, Trend Micro customers must download the latest pattern file and scan their system. Other Internet users can use HouseCall, Trend Micro’s free online virus scanner.

For product specific solutions, please refer to Solution 16031 of Trend Micro's Knowledge Base.

Trend Micro offers best-of-breed antivirus and content-security solutions for your



[This message has been edited by danny berg (edited 09-10-2003).]

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.


  • Your Responses - Share & Have Fun :)

    • mulefarm
      With the early ice out, how is the curlyleaf pondweed doing?
    • LakeofthewoodsMN
      On the south end...   The big basin, otherwise known as Big Traverse Bay, is ice free.  Zippel Bay and Four Mile Bay are ice free as well.  Everything is shaping up nicely for the MN Fishing Opener on May 11th. With the walleye / sauger season currently closed, most anglers are targeting sturgeon and pike.  Some sturgeon anglers are fishing at the mouth of the Rainy River, but most sturgeon are targeted in Four Mile Bay or the Rainy River.  Hence, pike are the targeted species on the south shore and various bays currently.   Pike fishing this time of year is a unique opportunity, as LOW is border water with Canada, the pike season is open year round. The limit is 3 pike per day with one being able to be more than 40 inches. All fish 30 - 40 inches must be released. Back bays hold pike as they go through the various stages of the spawn.  Deadbait under a bobber, spinners, spoons and shallow diving crankbaits are all viable options.   Four Mile Bay, Bostic Bay and Zippel Bay are all small water and boats of various sizes work well. On the Rainy River...  Great news this week as we learned sturgeon will not be placed on the endangered species list by the U.S. Fish and Wildlife Service.     The organization had to make a decision by June 30 and listing sturgeon could have ended sturgeon fishing.  Thankfully, after looking at the many success stories across the nation, including LOW and the Rainy River, sturgeon fishing and successful sturgeon management continues.   A good week sturgeon fishing on the Rainy River.  Speaking to some sturgeon aficionados, fishing will actually get even better as water temps rise.     Four Mile Bay at the mouth of the Rainy River near the Wheeler's Point Boat Ramp is still producing good numbers of fish, as are various holes along the 42 miles of navigable Rainy River from the mouth to Birchdale.   The sturgeon season continues through May 15th and resumes again July 1st.   Oct 1 - April 23, Catch and Release April 24 - May 7, Harvest Season May 8 - May 15, Catch and Release May 16 - June 30, Sturgeon Fishing Closed July 1 - Sep 30, Harvest Season If you fish during the sturgeon harvest season and you want to keep a sturgeon, you must purchase a sturgeon tag for $5 prior to fishing.    One sturgeon per calendar year (45 - 50" inclusive, or over 75"). Most sturgeon anglers are either a glob of crawlers or a combo of crawlers and frozen emerald shiners on a sturgeon rig, which is an 18" leader with a 4/0 circle hook combined with a no roll sinker.  Local bait shops have all of the gear and bait. Up at the NW Angle...  A few spots with rotten ice, but as a rule, most of the Angle is showing off open water.  In these parts, most are looking ahead to the MN Fishing Opener.  Based on late ice fishing success, it should be a good one.  
    • leech~~
      Nice fish. I moved to the Sartell area last summer and just thought it was windy like this everyday up here? 🤭
    • Rick G
      Crazy windy again today.... This is has been the norm this spring. Between the wind and the cold fronts, fishing has been more challenging for me than most years.  Panfish have been moving in and out of the shallows quite a bit. One day they are up in the slop, the next they are out relating to cabbage or the newly sprouting lilly pads.  Today eye guy and I found them in 4-5 ft of water, hanging close to any tree branches that happened to be laying in the water.  Bigger fish were liking a 1/32 head and a Bobby Garland baby shad.   Highlight of the day way this healthy 15incher
    • monstermoose78
    • monstermoose78
      As I typed that here came a hen.  IMG_7032.mov   IMG_7032.mov
    • monstermoose78
      So far this morning nothing but non turkeys. 
    • monstermoose78
      Well yesterday I got a little excited and let a turkey get to close and I hit the blind!!
    • smurfy
      good......you?? living the dream..in my basement playing internet thug right now!!!!!! 🤣 working on getting the boat ready.......bought a new cheatmaster locator for the boat so working on that.   waiting for warmer weather to start my garden!!!
    • monstermoose78
      How is everyone doing? Holy moly it’s chilly this morning I stayed in bed and will hunt later today when it warms up.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use and Privacy Policy. We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.