MORE SPAM

In this forum you can discuss anything from sports, news, or what ever is on your mind.

Moderator: SMLCHNG

Post Reply
Gulfbreeze
On a Salty Piece of Land
Posts: 12387
Joined: January 16, 2005 11:38 am
Number of Concerts: 8
Location: Gulf Coast of Florida
Contact:

MORE SPAM

Post by Gulfbreeze »

:evil: :evil: :evil:

All of the sudden I'm starting to get crap through my roadrunner account...and I never use this email addy for anything but personal emails.

The latest was from cia.gov so it peaked my interest. I go to BN, Drudge, Hotsheet, and the countless # of links underscoreShark3 sends us to and thought, hmm, somethings not quite right...

Bottom line...don't open any attachments unless it's from someone you know...I never opened it but a quick search on Snopes came up with...

Dear Sir/Madam,

we have logged your IP-address on more than 30 illegal Websites.

Important:
Please answer our questions!
The list of questions are attached.


Yours faithfully,
Steven Allison

++++ Central Intelligence Agency -CIA-
++++ Office of Public Affairs
++++ Washington, D.C. 20505

++++ phone: (703) 482-0623
++++ 7:00 a.m. to 5:00 p.m., US Eastern time


Like the earlier Sober.C mass-mailing worm which hit in 2003, this latest version (Sober.X) employs phony warning messages supposedly sent by law enforcement agencies which claim to be tracking illegal Internet activity. In this case, the messages purport to come from a "Steve Allison," an investigator with either the FBI or the CIA, and state that the recipient has visited "more than 30 illegal Websites," presenting him with a "list of questions" he must answer. The whole thing is, of course, a fiction inteded to lure the reader into opening the attached .ZIP file so that the worm can spread to his PC.
Image
Moonie
User banned 30 days
Posts: 3906
Joined: June 21, 2003 10:19 am
Number of Concerts: 0
Location: ....Coastal Georgia....
Contact:

Post by Moonie »

I've gotten 12 to 15 of these in various forms the past couple of days... ..not only don't open the attachment..delete all of it...quickly!

the following was emailed to me..

AVG has protected me so far..and has also listed the worms and viruses it has caught in all of these emails...


Sent: Monday, November 21, 2005 7:20 PM
Subject: Trend Micro Medium Risk Virus Alert - WORM_SOBER.AG


Dear Trend Micro customer,

As of November 21, 2005 2:20 PM Pacific Standard Time (PST, GMT -8:00),
TrendLabs has declared a Medium Risk Virus Alert to control the spread of
WORM_SOBER.AG. TrendLabs has received several infection reports indicating
that this malware is spreading in the USA, Belgium, Canada, Brazil, and New
Zealand.

This memory-resident worm propagates by attaching a copy of itself to an
email message, which it sends to target recipients using its own Simple Mail
Transfer Protocol (SMTP) engine. Since it's email propagation does not
require any user intervention, the user is often unaware that this worm is
sending out email messages.

The email it sends out has the following details:

From: {Email address generated by this worm}

Subject: (any of the following)
. hi,_ive_a_new_mail_address
. Mail delivery failed
. Registration Confirmation
. smtp mail failed
. Spam: Registration Confirmation
. Your Password
. Your IP was logged
. Paris_Hilton_&_Nicole_Richie
. You visit illegal websites

Message body: (any of the following)
hey its me, my old address dont work at time. i dont know why?!
in the last days ive got some mails. i' think thaz your mails but im not
sure!
plz read and check ...
cyaaaaaaa

---

This is an automatically generated Delivery Status Notification.

SMTP_Error []
I'm afraid I wasn't able to deliver your message.
This is a permanent error; I've given up. Sorry it didn't work out.
The full mail-text and header is attached

---

Account and Password Information are attached!
***** Go to: http://www.{random}.com
***** Email: {random}.com

---

Dear Sir/Madam,

we have logged your IP-address on more than 30 illegal Websites.
Important:
Please answer our questions!
The list of questions are attached.

Yours faithfully,
Steven Allison

*** Federal Bureau of Investigation -FBI-
*** 935 Pennsylvania Avenue, NW, Room 3220
*** Washington, DC 20535
*** phone: (202) 324-3000

---

Account and Password Information are attached! ---

The Simple Life:
View Paris Hilton & Nicole Richie video clips , pictures & more ;)
Download is free until Jan, 2006!
Please use our Download manager.


Attachment: (any of the following)
. mailtext.zip
. mail.zip
. reg_pass.zip
. mail.zip
. reg_pass-data.zip
. question_list.zip
. list.zip
. downloadm
. mail_body.zip


The attached .ZIP file contains the copy of this worm using the following
file name:
File-packed_dataInfo.exe

When executed, it displays a fake error message box in order to trick a user
into thinking that the file did not properly execute.

This worm searches the process list of the affected system for mrt.exe, the
Microsoft Windows Malicious Software Removal Tool process. If found, it
terminates the said process thus making the system more vulnerable to
malicious attacks.


TrendLabs will be releasing the following EPS deliverables:

TMCM Outbreak Prevention Policy (Beta) - 187 (Released)
Official Pattern Release - 2.957.00 (ETA: 1.5 hrs)
Damage Cleanup Template - 678 (Being created)
Network Virus Wall - 10232 (Being created)


For more information on WORM_SOBER.AG, you can visit our Web site at:
http://www.trendmicro.com/vinfo/virusen ... M_SOBER.AG
Last edited by Moonie on November 22, 2005 9:48 am, edited 2 times in total.
Image



When it goes from full to crescent...I move in and out of tune...Everlasting Moon.... Image
land_shark3
Here We Are
Posts: 9804
Joined: April 6, 2004 4:03 pm
Number of Concerts: 0
Location: Halfway here or halfway gone?

Post by land_shark3 »

I saw an article on the news about this last night. Personally, I think they should hang virus creators by their toenails and skin them alive. :evil: :evil: :evil:

I've run all my virus programs and spyware removal tools and came up with nothing. In addition to the e-mails from cia.gov and fbi.gov, I've been getting them from factories I work for "ive new e-mail address".
It's your world, I'm just living in it! :pirate:
sunseeker
Woman going crazy on Caroline street
Posts: 22136
Joined: April 18, 2002 8:00 pm
Favorite Buffett Song: That's what living is to me
Number of Concerts: 50
Favorite Boat Drink: Mostly water these days
Location: North Carolina

Post by sunseeker »

i got all of those today!!! deleted them all....
There's this one particular harbor.....
Moonie
User banned 30 days
Posts: 3906
Joined: June 21, 2003 10:19 am
Number of Concerts: 0
Location: ....Coastal Georgia....
Contact:

Post by Moonie »

I unintentionally (or stupidly) let the moab (sp?) worm into my computer this past summer and took me six hrs. and numerous spy programs and virus scans to eliminate it...

and these worms work fast, too...
Image



When it goes from full to crescent...I move in and out of tune...Everlasting Moon.... Image
shakerofsalt
At the Bama Breeze
Posts: 4895
Joined: March 9, 2004 9:08 pm

Post by shakerofsalt »

ummmmm, How do I get rid of this worm? I think I just got it. I'm almost positive that I didn't open the zip file, but my computer turned off and rebooted when I closed that email. HELP!!!!
ToplessRideFL
Changing Channels
Posts: 17798
Joined: January 9, 2005 9:34 am
Number of Concerts: 0
Location: Phlocking with BN'rs in Tampa Bay!
Contact:

Re: MORE SPAM

Post by ToplessRideFL »

Gulfbreeze wrote::evil: :evil: :evil:

All of the sudden I'm starting to get crap through my roadrunner account...
Me too... the last few months or so.....
MOST VALUABLE PLAYER OF BN FEUD VII
land_shark3
Here We Are
Posts: 9804
Joined: April 6, 2004 4:03 pm
Number of Concerts: 0
Location: Halfway here or halfway gone?

Re: MORE SPAM

Post by land_shark3 »

Gulfbreeze wrote::evil: :evil: :evil:

All of the sudden I'm starting to get crap through my roadrunner account...and I never use this email addy for anything but personal emails.

The latest was from cia.gov so it peaked my interest. I go to BN, Drudge, Hotsheet, and the countless # of links underscoreShark3 sends us to and thought, hmm, somethings not quite right...
:oops: Hoping it was none of my links :oops:
It's your world, I'm just living in it! :pirate:
shakerofsalt
At the Bama Breeze
Posts: 4895
Joined: March 9, 2004 9:08 pm

Re: MORE SPAM

Post by shakerofsalt »

ToplessRideFL wrote:
Gulfbreeze wrote::evil: :evil: :evil:

All of the sudden I'm starting to get crap through my roadrunner account...
Me too... the last few months or so.....
the last 2 weeks for me....at least 10 a day.................and now I must have accidentally opened one! :evil: to roadrunner
land_shark3
Here We Are
Posts: 9804
Joined: April 6, 2004 4:03 pm
Number of Concerts: 0
Location: Halfway here or halfway gone?

Post by land_shark3 »

shakerofsalt wrote:
ToplessRideFL wrote:
Gulfbreeze wrote:All of the sudden I'm starting to get crap through my roadrunner account...
Me too... the last few months or so.....
the last 2 weeks for me....at least 10 a day.................and now I must have accidentally opened one! :evil: to roadrunner
Hmmm, mine just started yesterday. Granted I received about 20+ before I had my e-mail filter set up to block them.
It's your world, I'm just living in it! :pirate:
Moonie
User banned 30 days
Posts: 3906
Joined: June 21, 2003 10:19 am
Number of Concerts: 0
Location: ....Coastal Georgia....
Contact:

Re: MORE SPAM

Post by Moonie »

land_shark3 wrote:
Gulfbreeze wrote::evil: :evil: :evil:

All of the sudden I'm starting to get crap through my roadrunner account...and I never use this email addy for anything but personal emails.

The latest was from cia.gov so it peaked my interest. I go to BN, Drudge, Hotsheet, and the countless # of links underscoreShark3 sends us to and thought, hmm, somethings not quite right...
:oops: Hoping it was none of my links :oops:
AVG scans all of my email and this is where the worm is getting in..(I think) it removes the attachment or won't let me open it..
Image



When it goes from full to crescent...I move in and out of tune...Everlasting Moon.... Image
shakerofsalt
At the Bama Breeze
Posts: 4895
Joined: March 9, 2004 9:08 pm

Re: MORE SPAM

Post by shakerofsalt »

Moonie wrote:
land_shark3 wrote:
Gulfbreeze wrote::evil: :evil: :evil:

All of the sudden I'm starting to get crap through my roadrunner account...and I never use this email addy for anything but personal emails.

The latest was from cia.gov so it peaked my interest. I go to BN, Drudge, Hotsheet, and the countless # of links underscoreShark3 sends us to and thought, hmm, somethings not quite right...
:oops: Hoping it was none of my links :oops:
AVG scans all of my email and this is where the worm is getting in..(I think) it removes the attachment or won't let me open it..
What is AVG and where do I get it?? Will it take care of this worm if it is currently on my computer??
Gulfbreeze
On a Salty Piece of Land
Posts: 12387
Joined: January 16, 2005 11:38 am
Number of Concerts: 8
Location: Gulf Coast of Florida
Contact:

Re: MORE SPAM

Post by Gulfbreeze »

shakerofsalt wrote:
Moonie wrote:
land_shark3 wrote:
Gulfbreeze wrote::evil: :evil: :evil:

All of the sudden I'm starting to get crap through my roadrunner account...and I never use this email addy for anything but personal emails.

The latest was from cia.gov so it peaked my interest. I go to BN, Drudge, Hotsheet, and the countless # of links underscoreShark3 sends us to and thought, hmm, somethings not quite right...
:oops: Hoping it was none of my links :oops:
AVG scans all of my email and this is where the worm is getting in..(I think) it removes the attachment or won't let me open it..
What is AVG and where do I get it?? Will it take care of this worm if it is currently on my computer??
Try this...assuming you are running a MS OS...

http://www.microsoft.com/security/malwa ... fault.mspx
Image
RinglingRingling
Last Man Standing
Posts: 53938
Joined: May 30, 2004 3:12 pm
Favorite Buffett Song: Glory Days
Number of Concerts: 0
Favorite Boat Drink: Landshark, and Margaritaville products...
Location: Where payphones all are ringing

Post by RinglingRingling »

Gulfbreeze
On a Salty Piece of Land
Posts: 12387
Joined: January 16, 2005 11:38 am
Number of Concerts: 8
Location: Gulf Coast of Florida
Contact:

Re: MORE SPAM

Post by Gulfbreeze »

land_shark3 wrote:
Gulfbreeze wrote::evil: :evil: :evil:

All of the sudden I'm starting to get crap through my roadrunner account...and I never use this email addy for anything but personal emails.

The latest was from cia.gov so it peaked my interest. I go to BN, Drudge, Hotsheet, and the countless # of links underscoreShark3 sends us to and thought, hmm, somethings not quite right...
:oops: Hoping it was none of my links :oops:
Naaa...underscoreSharky's off the hook... :D
Image
Moonie
User banned 30 days
Posts: 3906
Joined: June 21, 2003 10:19 am
Number of Concerts: 0
Location: ....Coastal Georgia....
Contact:

Re: MORE SPAM

Post by Moonie »

shakerofsalt wrote:
Moonie wrote:
land_shark3 wrote:
Gulfbreeze wrote::evil: :evil: :evil:

All of the sudden I'm starting to get crap through my roadrunner account...and I never use this email addy for anything but personal emails.

The latest was from cia.gov so it peaked my interest. I go to BN, Drudge, Hotsheet, and the countless # of links underscoreShark3 sends us to and thought, hmm, somethings not quite right...
:oops: Hoping it was none of my links :oops:
AVG scans all of my email and this is where the worm is getting in..(I think) it removes the attachment or won't let me open it..
What is AVG and where do I get it?? Will it take care of this worm if it is currently on my computer??
AVG is my virus protection and it's free...does better than anything I've ever puchased..

You might try this..you'll have to read it...this is what I used this summer to get rid of the worm I'd d/l..


http://www.trendmicro.com/vinfo/virusen ... G&VSect=Sn

.
Image



When it goes from full to crescent...I move in and out of tune...Everlasting Moon.... Image
Sam
Inactive User
Posts: 3993
Joined: February 5, 2002 7:00 pm
Number of Concerts: 0
Location: Somewhere between a Rock and a Hard Place

Post by Sam »

AVG is a free for home use antiviral. I like it better than Norton's or Mcafee. It picked up stuff they have let through.
Whatever you do get an antiviral and KEEP IT UPDATED
You can get it here : http://www.grisoft.com/doc/40/lng/us/tpl/tpl01

Note I also use go to Trend Micro online and run their HOUSECALL that will scan your computer while you are online, as a surety check.

So far my computer system has stayed clean. AVG works and works GREAT.

NEVER OPEN ANY SUSPICIOUS EMAIL OR AN ATTACHJMENT FROM ANYONE YOU DO NOT KNOW!!!
If someone YOU KNOW sends you an attachment VERIFY it with them BEFORE you open it. It may not actually be from them. OR their puter may have caught a nasty and don't know it.

When in doubt of any email In Outlook or Outlook Express highlight the suspicious email and RIGHT click on the email and then RIGHT click Properties. Then LEFT CLICK on DETAILS then LEFT click on properties.
This will give you the full header information. This tells you where the email came from. NOTE it is possible to spoof the address. The last address at the bottom is where the e-mail originated. You can get the IP# from there and then run an IP trace and find out the server where the e-mail originated.
(The techies and uber geeks out there may have other ways of doing this and yes it is possiple to spoof or mask IP#s.)

The place we were getting the worm from yesterday was from east Tenn.

I also highly reccommend a good firewall. There are numerous FREE FOR HOME USE ones out there such as Zone Alarm.

While I am at it I allso reccommend numerous antispyware Two top ones that are FREE Adaware from Lavasoft and Spybot. Also Microsoft currently has an antispyware in Beta that seems to work great that is currently FREE.

There are many numerous other Free programs for home use that you may want to consider.
You can look over the following site as it has a list of them and others.
http://www.freebyte.com/antivirus/#scanners
Best of luck!!!
Last edited by Sam on November 22, 2005 7:49 pm, edited 1 time in total.
Roll with the punches, play all of your hunches...come what may...
Image POW-MIA, YOU ARE NOT FORGOTTEN!!!
SUPPORT OPERATION JUST CAUSE!!!
http://www.ojc.org/
Lundah
Half-baked cookies in the oven
Posts: 719
Joined: November 16, 2003 11:35 am
Number of Concerts: 0
Location: Chicago, IL
Contact:

Post by Lundah »

I use a great little program called MailWasher to filter out all the junk in my email. I have it set up so that I at least see the offending email before it's junked, and I also have it set up to be able to "bounce" Spam back to the sender (the real sender from the headers, not the bogus address in the From: line). Catches about 99% of the spam I get.
Image
Post Reply