Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Computer Forums > Miscellaneous > Off Topic Discussion » SOBER Worm using FBI & CIA
Closed Thread
Old 11-23-2005, 12:26 PM   #1 (permalink)
 
Wizard Techie

Join Date: Feb 2005

Posts: 3,660

brady is on a distinguished road

Send a message via Yahoo to brady
Default SOBER Worm using FBI & CIA

Fake CIA, FBI E-Mails Power Sober Worm
Several new versions of the "Sober" e-mail worm have been mass-spammed to millions of e-mail boxes of the last 72 hours, posing as messages from the FBI and the CIA warning recipients that their Internet address has been implicated in illegal activity online.

The messages obviously were not sent by either agency, but any recipient who clicks on the attachment carried in the e-mail may indeed soon find their computers involved a variety of illegal activities at the hands of the virus authors. Both the CIA and the FBI have posted warnings about this latest worm on their Web sites.

FBI spokesperson Cathy Milhoan said the agency has been swamped with calls from people who received the e-mails because the message includes the actual phone number for the FBI headquarters in Washington. She said FBI operators have had their hands full routing calls and complaints to its Internet Crime Complaint Center in West Virginia, which received more than 4,000 complaints about the worm on Monday alone. The ICC typically receives 18,000 complaints each month.

Finnish anti-virus firm F-Secure calls the latest Sober outbreak the largest e-mail worm epidemic so far this year. UK-based e-mail security company MessageLabs said it has intercepted more than 2.7 million copies of Sober and its variants, noting that "the size of the attack indicates that this is a major offensive, certainly one of the largest in the last few months."

The criminals behind the Sober family of worms usually release several variants of the worm at once, each one altered slightly to evade detection by anti-virus software; security firms often take several hours to push out new virus definitions that their software uses to spot the worm.

The Sober worm uses its own e-mail engine to blast copies of itself out to all of the addresses found on an infected computer. Sober kills a long list of security applications that may be running, including anti-virus and firewall software, and prevents the victim from visiting a long list of security-related Web sites. Finally, it opens a backdoor on the infected machine, allowing attackers to upload whatever software they want.

As usual, be extremely cautious about clicking on links and opening e-mail attachments, even if they appear to come from someone you know. As Sober illustrates, you cannot always depend on scanning an attachment with anti-virus software to be sure it is safe to open. If you have any doubts about the integrity of an attachment or weren't expecting it, contact the person who sent it.
__________________
brady is offline  
Old 11-23-2005, 03:23 PM   #2 (permalink)
c0rr0sive's Avatar
 
Formerly charles_scott

Join Date: Feb 2005

Posts: 4,597

c0rr0sive will become famous soon enough

Default

Quote:
This email comes to you from the Virus Emergency Response Team at
Proland Software.

One more variant of W32/Sober Worm, named as W32/Sober.Y has been
discovered in the wild. The W32/Sober.Y Worm is rapidly spreading across
the internet. As in the case of the earlier W32/Sober Worm variants,
this variant also spreads through email. You may recall our previous alert,
which was run last week about the other variants of W32/Sober Worm.
Protector Plus users are advised to download the latest update.

We stress again to follow these general safe computing practices
to avoid similar virus/worm infections in the future.

a. Do not open any compressed file, unless it is scanned from
Protector Plus.
b. If the name of the attachment is associated with the subject
of the email, then it is possible that it is infected.
c. Do not fall prey for any attractive subject or attachment name,
which entices you to click on it.
d. Always scan your mailbox with latest version of Protector Plus.
e. Add the following latest virus information link to your browser's
favorites list to learn about new threats:

http://www.protectorplus.com/virusinfo/alerts.htm

About the W32/Sober.Y Worm:

W32/Sober.Y Worm spreads through email. This worm will infect
Windows systems. The subject and the content of the infected email
will be from a predefined list maintained by the worm like an email
sent by the FBI for visiting some illegal websites or some thing about
Registration or about your email account and password.

You can read more information about this worm at:

http://www.protectorplus.com/virusinfo/worms/sobery.htm

Also to know more, check this list of W32/Sober Worm variants
that appear in chronological order:

http://www.protectorplus.com/virusin...s/sobervar.htm

Instructions to remove the W32/Sober.Y worm from
your computer:

An emergency virus database update to detect and remove this worm is
available to the users of Protector Plus anti-virus software. To download
this update from our web site, right click on Protector Plus icon from the
system tray then select 'Update Virus Database now!' from the menu.

Others can download a 30 day, fully functional evaluation copy from:

http://www.protectorplus.com/download

The evaluation copy will detect and remove this worm and also all
other known viruses, trojans and worms.

You are welcome to use this information to help any one who might need or
benefit from it. If you have questions or issues in the usage of
Protector Plus, please write to support@protectorplus.com .

The reason this alert is being sent to you is because either you or someone
acting on your behalf, subscribed to the Virus Alert Mailing List
maintained by us.

If you do not wish to receive further alerts, please send a return mail to
unsub@pspl.com

__________________

http://www.diefer.de/i8kfan/index.html - Use this to controll Dell laptop fans.
c0rr0sive is offline  
Old 11-23-2005, 04:02 PM   #3 (permalink)
 
Wizard Techie

Join Date: Jun 2005

Posts: 3,346

Tyler1989

Default

I wonder what language it's written in?
__________________
<form action=\"http://www.srsyo.org/tfsearch.php\" method=\"get\">
<input type=\"text\" name=\"search\"> <input type=\"submit\" name=\"submit\" value=\"Search TF before you post!\"></form>
Vista Discussion | 64 Bit Discussion |Microsoft Homepage | Yo Linux | Paul Thurrott | Fire Fox | Thunder Bird | Image Shack | Photo Bucket | Put File | Anti-Spyware | MS Anti-Spyware | Trillian | Anti-Virus | On Line Virus Scan
Tyler1989 is offline  
Old 11-23-2005, 08:28 PM   #4 (permalink)
 
Monster Techie

Join Date: Feb 2005

Posts: 1,606

mikee is on a distinguished road

Default

OMG my dad got that email just an hour ago , I just told him to delete it because panda antivirus said it was infected. I thought it was kind of wierd because he hollered upstairs " Hey mike I got an email from the FBI" and I was like WTF!!!
__________________
My Rig

Intel core 2 duo E4300
2GB ram
120 gb HDD, 1.5TB HDD
LG DVD burner
BFG 8600 GTS OC'd
mikee is offline  
Old 11-24-2005, 09:23 PM   #5 (permalink)
 
Super Techie

Join Date: Jun 2005

Location: Spaceballs Mega-Maid

Posts: 412

RichM499 is on a distinguished road

Send a message via AIM to RichM499 Send a message via Yahoo to RichM499
Default

good thing your dad listens to you, if he had been anything like my family he would have completely ignored you (i guess having A+, CCNA, Network+ still doesnt mean crap)....

good example is when my mom asks me to help her with the computer and then tells me that she doesnt want to do what i tell her because "it wont fix it".. but thats off topic im just ranting

sounds like a serious worm=) thanks for the valuable information (although if i got a government email i wouldnt open it anyway)... actually... i dont open any email..... except from close friends or family members.......

... i have 8142 unread emails....

thank you Hotmail for giving me 500MB free storage=)
__________________
Athlon x2 5400+ 2.8ghz @ 3.3~ghz
Corsair XMS2 DDR2 800 @ DDR2 900
Sapphire Radeon 4850
WD 500g Sata2
Asus Xonar PCI-e
RichM499 is offline  
Old 11-24-2005, 09:42 PM   #6 (permalink)
 
Master Techie

Join Date: Apr 2004

Posts: 2,534

horndude is on a distinguished road

Default

Quote:
Originally posted by Tyler1989
I wonder what language it's written in?
visual basic compressed with UPX
horndude is offline  
 
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On