Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » W32.Sober.O@mm/Sober.P
Search Topic:
Uniqs:
10718
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
SymLCSV1.exe »
« Generic Host Process for Win32  
page: 1 · 2 · 3 · 4 · 5
AuthorAll Replies


GKJUG

@algx.net
 reply to kpatz
Re: W32.Sober.O@mm/Sober.P

Recieved 6 more under a variety of Subject titles overnight.

- Registration confirmation

- Your email was blocked

- FWD: Your password

- Your password

All are in the 73 - 74kb range.


timcuth
Braves Fan
Premium
join:2000-09-18
Pelham, AL
clubs:
reply to kpatz
I got two, last night. Avast! caught them and I hit the recommended Delete button. I assume I am okay.

Tim


Deajl

@algx.net
reply to kpatz
Latest Subject title.

- Mailing error


wadonoel
Premium
join:2004-11-16
New York, NY
Mine came from register@cigna.com, sent through an Italian dynamic address. It's quite rare that I receive viruses on that account so it really must be wide spread.


Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX
·AT&T U-Verse


1 edit
reply to Chizep
said by Chizep See Profile:

Getting hit with it here at my job right now.

Forutnately none of the users have been stupid enough open the zip and execute the contents.
I haven't seen any copies at work yet, though there was
an unspecified warning about a new email virus sent by IT
and for all users to delete attachments from unknown
senders. I was not sure which it was until I had read
about the latest Sober variants.

None of my other email accounts have gotten hit yet.
--
"Kayura or Badamon, whichever you are, you should know that I will never give up this battle. By the will of the Ancient, I shall succeed!" - Shuten (Anubis) from the Ronin Warriors.
To RIAA/MPAA - You can sue but you can't catch everyone!


bskuared
It's Hip To Be Square
Premium
join:2001-12-02
San Clemente, CA
·Cox HSI


1 edit
reply to kpatz
I'm getting over 100 a day of a variety of these. Zone Alarm or AVG Free Cleans them all but still a major pain in the mailbox
--
2b or not 2b


--


none of this really matters



skj
Welcome to the far side of reality
Premium,Mod
join:2002-04-04
Atlanta, GA
reply to kpatz
I have gotten about 50 of them since yesterday.

compuwizz

join:2001-03-05
Blacksburg, VA
reply to kpatz
Looks like my school is having fun with it

»antivirus.vt.edu/

notice the heading at the top, it hit a listserv

Sending mail and webmail is flakey at best right now.

kpatz
MY HEAD A SPLODE
Premium
join:2003-06-13
Manchester, NH

said by compuwizz See Profile:

notice the heading at the top, it hit a listserv
And why does the listserv not have (a) a virus scanner, (b) attachment blocking, or (c) a moderator to screen messages posted to the list?
--
SMTP: Spam and Malware Transfer Protocol. Also used on rare occasion to transmit e-mail messages.


Shriyash
Sungazer
Premium
join:2005-02-23
PuNe, InDiA


2 edits
reply to kpatz
Click for full size
over the last 2 days, i have recieved several copies of this virus in my Yahoo bulk mail folder.
they are typically 72kb to 73kb in size, they all have attachments , with names like "mail_info.zip" or "error_info.zip".

{gives me the jitters just looking at it!}:D


Shriyash
Sungazer
Premium
join:2005-02-23
PuNe, InDiA


1 edit
reply to kpatz
Click for full size
Click for full size
just a couple of snaps for anyone curious

compuwizz

join:2001-03-05
Blacksburg, VA

reply to kpatz
Just to clear things up. We do have virus scanning on our e-mails. One of my professors said last year that they process about 2 million messages per day. I beleive it was when MyDoom or another virus hit campus, before the definitions were even created, there were 10 million e-mails in a 4 hour period. It literally brought the servers to a standstill and they were down for at least 3 days while they processed the backlog of mail. The campus really took a hit, so much that we do these days relies on e-mails whether it be pdf quizes or announcements.

QS

join:2001-12-02
North Vancouver, BC
reply to kpatz
I feel so left out, I have honestly never been hit by an email worm before. And I mean never. Kinda wish i would at least get one, so my AV can stretch it's legs =P


Jiminez

@net.mx
reply to compuwizz
Our campus has greater than 12,000 e-mail infecting of new Sober series, with no successful infect of computers.

NOD32 is stopping him since Monday, now by name, but as the unknown virus before update.


Shriyash
Sungazer
Premium
join:2005-02-23
PuNe, InDiA

reply to kpatz
Spread of Sober E-Mail Worm Variant Slowing
As always, PC users urged to update their antivirus software.

»www.pcworld.com/news/article/0,a···2,00.asp


awsdqwe2

@chello.nl
reply to boognish
[img/] »www.game-legion.com/W32.Sober.O@mm.JPG [img]


Tim dob

@chello.nl
reply to kpatz
Hi.
I need help the virus deled your Symantec
it deled your update Fil but how do i fix this must i Re-Istall or ..
who knows this help me plz !


kpatz
MY HEAD A SPLODE
Premium
join:2003-06-13
Manchester, NH

Tim dob, you should get the removal tool from here: »securityresponse.symantec.com/av···ool.html

You'll have to reinstall LiveUpdate afterward, since Sober.O deletes it.

Well, I had my first hit this morning. The subject on my sample is "Your email was blocked" and the attachment was named mail_info.zip.
--
SMTP: Spam and Malware Transfer Protocol. Also used on rare occasion to transmit e-mail messages.


amysheehan
Premium,VIP,MVM
join:1999-12-21
Huntington Beach, CA
·RoadRunner Cable

reply to Tim dob
To reinstall Live Update see:

How to download and install the newest version of LiveUpdate [from Symantec support]
»service1.symantec.com/SUPPORT/sh···osv_lvl=



boognish
Premium
join:2001-09-26
Baton Rouge, LA
clubs:

reply to kpatz
We are still getting hammered by this last night and this morning. Most of them look like one of these.
Registration Confirmation The attachment "account_info-text.zip" was marked for Deletion f
*or the following reasons:
Virus W32.Sober.O@mm was found in Winzipped-Text_Data.txt .pif.

Subject of the message: FwD: mailing error The attachment "mail_info.zip" was marked for
*Deletion for the following reasons:
Virus W32.Sober.O@mm was found in Winzipped-Text_Data.txt .pif.

Subject of the message: mailing error The attachment "error-mail_info.zip" was marked for
* Deletion for the following reasons:
Virus W32.Sober.O@mm was found in Winzipped-Text_Data.txt .pif.

The attachment "our_secret.zip" was marked for Deletion for the following reasons:
Virus W32.Sober.O@mm was found in Winzipped-Text_Data.txt .pif.

(*) WARNING 3 long line(s) split
Forums » Up and Running » Security » SecuritySymLCSV1.exe »
« Generic Host Process for Win32  
page: 1 · 2 · 3 · 4 · 5


Sunday, 29-Nov 02:47:29 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [122] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [80] TiVo Sees Record Customer Losses
· [73] Weekend Open Thread
· [70] Verizon CEO: Hulu Will Be Dead Soon
· [69] In-Flight Internet Headed For Bumpy Landing?
· [62] Thanksgiving Open Thread
· [40] EFF Wages War On Fine Print
Most people now reading
· [ PVP] 3.2 DK PvP D/W Spec... [World of Warcraft]
· ToC 4th boss - Preliminary Strategy for Twin Valkyr [World of Warcraft]
· Using AirMax to provide triple play services? [Wireless Service Providers]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· [Newsgroups] Newzleech down? [Filesharing Software]
· Windows 7 boot manager editing questions [Microsoft Help]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· how to use the 2nd line with phone hooked to the 1st line? [VOIP Tech Chat]
· [ Classes] Druid tanking: rotation and glyphs [World of Warcraft]
· [Future9] Future9 status [VOIP Tech Chat]