Forum Moderators: phranque

Message Too Old, No Replies

30 virus attacks in 2 hours! - W32.Sobig.F@mm

After the blaster another one mass mailing virus!

         

lasko

4:15 pm on Aug 19, 2003 (gmt 0)

10+ Year Member



The virus W32.Sobig.F@mm has been really really quite recently howver symantec have just upgraded it to nearly the same level as the blaster.

For some reason in the last two hours I have received 30 attacks all of which where stopped by Norton with no problems.

The virus is sending it self to any email address found on html, htm, txt files and more on the internet.

So now I am taking all my addresses of all my high ranking web sites and using php to protect my email accounts.

Has anyone else seen a sudden increase of attacks from this virus?

What a week its turning out to be :(

Herenvardo

2:42 pm on Sep 2, 2003 (gmt 0)

10+ Year Member



lasko:
I only had to do a format on my hard drive three or four times since I get it (four years ago).
Even so, I understand that not everybody has time to make manual cleanings and checks of the system. I'm very fortunated! :):):)
But I was suggesting the manual cleaning only to home users.
Of course a server or any workstation needs an anti-virus! But it is safer the manual checking. Slower, but safer.
And the safest would be to use all the anti-virus available and, after passing all checks, manually inspect each file. Of course, nobody does so. There is a balance between speed and security: I don't need great speed, so I can get the great security of manual check.
I also want to make a complaint about the currently available antivirus: they are too weak programs, only able to compare the files with the virus paterns from a list. If somebody makes a simple virus to harm a concret system, no antivirus will stop it, cause until that moment the virus did not exist and it does not appear in any virus list. From here I suggest to Panda Software, McAfee, MS, Symantec and all other companies to improve their protection algos.
My manual check would detect that hom-made virusses... ;P

Greetings,
Herenvardö

GlynMusica

3:13 pm on Sep 4, 2003 (gmt 0)

10+ Year Member



"Herenvardö said...
I don't now how can you get so troubled!
I do not use any antivirus and my systems are always clean. I send mailings to many people and sometimes (2-3 times a year) somebody tells me that my mail had a virus.
Once I tried to install Panda and I was not able to boot my computer again: i had to format the hard drive and re-install Windows again.
So I will never use an antivirus. "

Well I'd hazzard a guess that your system was so full of trojans/viruses that the PANDA had to take out your whole system.

That's why it never re-started.

;)

futureX

4:28 pm on Sep 4, 2003 (gmt 0)

10+ Year Member



meh, i always format my hdd every few month, when the system starts getting a little slow and/or theres something there that takes too much work to fix. I just back everything up on my other HDD.

Herenvardo

4:42 pm on Sep 4, 2003 (gmt 0)

10+ Year Member



GlynMusica:
I don't need antivirus. When I installed panda for the first time, it made a whole test on my system and did not detect any virus. It asked me to restart my PC, I selected something like "Restart now" and it never started again. I started windows in safe mode, uninstalled panda and... wow! the system worked again.
The second time, it was very simillar, but I was not able to boot in safe mode, so i had to re-install windows.
I received a Sticky mail giving me the url of a free antivirus, i tried it and the result is similar: only takes problems!
I understand that servers need antivirus software. The server I work at also uses Panda. But no AV software has worked ever on my home PC. I begin to believe that this programs hate my PC. When I do my next format, I'll try it again, but I don't hope it will work.
Even so, I believe in my manual checks. I manually check everything that is suspicious and I have never had problems with virus. I don't need antivirus.

Greetings,
Herenvardö

GlynMusica

9:48 am on Sep 5, 2003 (gmt 0)

10+ Year Member



In that case....ignorance is bliss.

lasko

11:15 am on Sep 5, 2003 (gmt 0)

10+ Year Member



Herenvardo

Let me get this straight you download a free anti virus program from the Internet and you find it messes up your system.

What about the paid versions have you ever given them a real chance, I have not had one single problem since I installed Norton Anti Virus 2000, plus I keep it updated every few days not just once a week.

Of course you have to pay for these services and to be honest for the amount of time that is saved not having to Format my pc and knowing that I am protected its well worth it not just for me but also to do my bit against the spread of viruses.

Even though you format your pc. When you are infected by a mass emailing worm you will have given out a load of email addresses stored in your email programs or even documents on your pc.

Viruses only spread quickly due to amount of Internet users without basic Virus Prevention Software.

Herenvardo

3:29 pm on Sep 8, 2003 (gmt 0)

10+ Year Member



Hi!
My PC is actually nude: my main partition has been completely removed and re-made. I also re-wrote the MBR and the partition table by installing and uninstalling some LiNUX boot managers. So, my PC is theorically clean. I shall install the Win98 system that came with the PC when I purchased it and, immediately, an antivirus.
Currently, my hard disk is clean. Boot diskette and Windows CDs have been always write-protected, so the must be clean. So, once I re-install all the system again, it will be clean. Then I'll do my manual checks before the AV does its own. I bet you that it won't never find a virus that has skipped my checks.
Then we shall see who is the best: antivirus or me! :P
I will post again when the battle is won ;)

Greetings,
Herenvardö, the one who doesn't need antivirus ;)

chrisandsarah

9:16 am on Sep 10, 2003 (gmt 0)

10+ Year Member



so long sobig..
Yipeee!
It seems to have stopped! Thank god. My email can now breathe again..
Are they still expecting a next wave attack?

lasko

9:36 am on Sep 10, 2003 (gmt 0)

10+ Year Member



Yes when Sobig.G comes out!

This one is not finished yet every new strain seems to be stronger!

Today was the last day of the virus emailing it self, infected pc's will still have problems but things should go very quite now :)

for a while anyway!

Herenvardo

2:40 pm on Sep 10, 2003 (gmt 0)

10+ Year Member



wow!
I have said that I don't need antivirus, but this is better: viruses do not attack me!
Perhaps I'm very lucky, but I have not suffered ANY attack from sobig in any of the email accounts I manage (neither personal nor work addresses).

I have discovered that my luck is better than all of your antivirus programs toghether. :P:P:P :):):)

Greetings,
Herenvardo, the Lucky One

lasko

2:50 pm on Sep 10, 2003 (gmt 0)

10+ Year Member



Congratulations on your luck

hope it doesn't run out!

DaveN

3:10 pm on Sep 11, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



keep them coming and collect all the email addresses.

Dave

Net_Wizard

5:10 pm on Sep 13, 2003 (gmt 0)



Yup, spammers have a field day...I'm getting 3x more spam compared before this.

Kukenan

6:47 pm on Sep 13, 2003 (gmt 0)

10+ Year Member



Just change the addresses.

I had to do it!

coconutz

7:41 am on Oct 1, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Anyone else seeing a resurgence? We've received almost 300 infected messages in the last couple of hours.

SuzyUK

7:46 am on Oct 1, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I had a spate at the weekend but it's SWEN this time..

Am I right in thinking, (just before I try advising someone else) that it's better to use ANY other email client than MS, e.g. would Netcapes mail client be better? or is Eudora(free) better than that. I might pay for Eudora, but friends wont ;)

Suzy

Sinner_G

7:48 am on Oct 1, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



it's better to use ANY other email client than MS

Correct. :)

lasko

7:51 am on Oct 1, 2003 (gmt 0)

10+ Year Member



Eudora doen't make much of difference with me, however now my hosting company has set up a facility that DEFANG attachments that request.

For example:

exe,
scr,
pif files I have instructed to delete as I never need these sent to me, I also get a message saying one was deleted. So far its been great really taking the pressure off the NAV and normal emails with doc,pdf,JPG or GIF attachements are getting through like they should.

The only other solution would do everything using web based email but that can be a little slow sometimes.

I use Eudora, great program.

This 198 message thread spans 7 pages: 198