Author Topic: Mass Mailing Worm  (Read 5526 times)

0 Members and 1 Guest are viewing this topic.

Willy Mammoth

  • Offline Gold Turtle Award
  • *
  • Turtle Points: 0
  • Male Posts: 4,252
  • Member since Nov '04
    • View Profile
Mass Mailing Worm
« on: May 02, 2005, 05:32:19 PM »
:scared: There is a new Mass Mailing Worm out and somebody on this forum is infected. I /we have been getting emails with Zip attachments that are bogus. If you get these do not open them, the Zip attachment is the worm. Please check here for more information and check your system for this.

 http://securityresponse.symantec.com/avcenter/venc/data/w32.sober.o@mm.html
Thanks for practicing safe computering,
Mark
:usa: American by birth, redneck by choice. 

Making Of http://board.marlincrawler.com/index.php?topic=6472.0  
 
Sightings Of  http://board.marlincrawler.com/index.php?topic=10805.0

FATB0Y

  • Offline The 2.5K Group
  • ****
  • Turtle Points: 0
  • Male Posts: 2,803
  • Member since Nov '04
    • View Profile
    • fatboy on my space.com
Re: Mass Mailing Worm
« Reply #1 on: May 02, 2005, 05:38:12 PM »
Thanks for practicing safe computering,
Mark
I wear a rubber when online :rofl2:

Willy Mammoth [OP]

  • Offline Gold Turtle Award
  • *
  • Turtle Points: 0
  • Male Posts: 4,252
  • Member since Nov '04
    • View Profile
Re: Mass Mailing Worm
« Reply #2 on: May 02, 2005, 05:43:22 PM »
Me to it's easier to clean up after :gap:


But really I got an email error from Postmaster@pirate4x4.com, service@marlincrawler.com and a few others which leads me to believe it is someone on this site that is infected.
« Last Edit: May 02, 2005, 05:52:47 PM by Willy Mammoth »
:usa: American by birth, redneck by choice. 

Making Of http://board.marlincrawler.com/index.php?topic=6472.0  
 
Sightings Of  http://board.marlincrawler.com/index.php?topic=10805.0

Lady Di

  • Goddess of Mud
  • Rock Ninja
  • Offline Rock Master
  • *
  • Turtle Points: 0
  • Female Posts: 299
  • Member since Nov '04
    • View Profile
Re: Mass Mailing Worm
« Reply #3 on: May 02, 2005, 05:53:08 PM »
and I got the same ones but have never been on pirate4x4.com or at least if I have I have never posted there, and I don't email anyone from there that isn't on Marlin, so it's got to be someone that has both my and Mark's address as well as pirate and marlin, as well as quite a few others such as these in my screen capture. All the attachments are zip files:
Life is like a bowl of beer flavored chocolate covered dog turds.. it makes no sense. :pokinit:

Where is the Mammoth?

How the Mammoth came to be

Number Two :pokinit:

RUGER

  • Offline The 1K Club
  • *
  • Turtle Points: 17495
  • Male Posts: 1,022
  • Member since May '02
  • I love Marlin Crawler!
    • View Profile
    • Buy me a beer
Re: Mass Mailing Worm
« Reply #4 on: May 02, 2005, 05:59:27 PM »
Me to it's easier to clean up after :gap:


But realy I got a email error from Postmaster@pirate4x4.com, service@marlincrawler.com and a few others which leads me to belive it is someone on this site that is infected.

could be me :_oops: ...my roomie got something like that last night too. didn't say who it was from...i'll ask him when he gets back from working on his engineering project.

i checked my pirate4x4 email(its in my profile) and i got 9 emails that are titled virus found and email was blocked. they are all in my inbox...i wasnt planning on opening them anyway(they all have todays date on them).
my other email addys dont have anything like that.

how do you get these worm thingys...what do they doo. i didnt send any emails to you.

happy trails
rich *ruger*  :usa:  :turtle:
« Last Edit: May 02, 2005, 06:05:28 PM by RUGER »
:usa: GOD BLESS AMERICA :usa:

"the hag" 83 toy with 5" all-pro lift, marlin crawler dual case #1011 and marlin hy-steer, 35s, 5.29's, exo cage, yada, yada, yada. she's back in black.

97 F250
84 Grand Waggy
77 Scout II SS
96 Explorer Sport
20 F150

USN SEABEE 2008-2012 :usa:
run with THE PACK 4wdc of los osos
NRA life member

Willy Mammoth [OP]

  • Offline Gold Turtle Award
  • *
  • Turtle Points: 0
  • Male Posts: 4,252
  • Member since Nov '04
    • View Profile
Re: Mass Mailing Worm
« Reply #5 on: May 02, 2005, 06:06:04 PM »
I talked to my web provider service tech and he said it is sent in an email. It was just found today. Go to the link above and read up on it. I just downloaded the latest version of Norton Internet Security.
:usa: American by birth, redneck by choice. 

Making Of http://board.marlincrawler.com/index.php?topic=6472.0  
 
Sightings Of  http://board.marlincrawler.com/index.php?topic=10805.0

Lady Di

  • Goddess of Mud
  • Rock Ninja
  • Offline Rock Master
  • *
  • Turtle Points: 0
  • Female Posts: 299
  • Member since Nov '04
    • View Profile
Re: Mass Mailing Worm
« Reply #6 on: May 02, 2005, 06:10:06 PM »
it's a crazy world out here. Not a good idea to surf unprotected for sure. Who the emails are from won't tell you anything as these worms take the addresses from the address books and use random names from there for the TO: box as well. So just because it says it's from so&so doesn't mean anything.
All you have to do is have the email addresses in your address book. Did you have either mine or marks? Did any of those other email addresses look familiar?

Is your roomie on marlin or pirate?
« Last Edit: May 03, 2005, 06:04:35 PM by MrsWillyMammoth »
Life is like a bowl of beer flavored chocolate covered dog turds.. it makes no sense. :pokinit:

Where is the Mammoth?

How the Mammoth came to be

Number Two :pokinit:

FATB0Y

  • Offline The 2.5K Group
  • ****
  • Turtle Points: 0
  • Male Posts: 2,803
  • Member since Nov '04
    • View Profile
    • fatboy on my space.com
Re: Mass Mailing Worm
« Reply #7 on: May 02, 2005, 06:11:40 PM »
I have Earthlink and they scan my e-mail B-4 I even get it in my mailbox.

RUGER

  • Offline The 1K Club
  • *
  • Turtle Points: 17495
  • Male Posts: 1,022
  • Member since May '02
  • I love Marlin Crawler!
    • View Profile
    • Buy me a beer
Re: Mass Mailing Worm
« Reply #8 on: May 02, 2005, 06:14:37 PM »
i read some of the link you posted...i dont really understand computer lingo.
so could it be me er not. there are lots here that frequent both pirate and marlin.

happy trails
rich *ruger* :usa:  :turtle:
:usa: GOD BLESS AMERICA :usa:

"the hag" 83 toy with 5" all-pro lift, marlin crawler dual case #1011 and marlin hy-steer, 35s, 5.29's, exo cage, yada, yada, yada. she's back in black.

97 F250
84 Grand Waggy
77 Scout II SS
96 Explorer Sport
20 F150

USN SEABEE 2008-2012 :usa:
run with THE PACK 4wdc of los osos
NRA life member

Lady Di

  • Goddess of Mud
  • Rock Ninja
  • Offline Rock Master
  • *
  • Turtle Points: 0
  • Female Posts: 299
  • Member since Nov '04
    • View Profile
Re: Mass Mailing Worm
« Reply #9 on: May 02, 2005, 06:16:38 PM »
could be me :_oops: ...my roomie got something like that last night too. didn't say who it was from...i'll ask him when he gets back from working on his engineering project.

i checked my pirate4x4 email(its in my profile) and i got 9 emails that are titled virus found and email was blocked. they are all in my inbox...i wasnt planning on opening them anyway(they all have todays date on them).
my other email addys dont have anything like that.

how do you get these worm thingys...what do they doo. i didnt send any emails to you.

happy trails
rich *ruger*  :usa:  :turtle:

From the link above:

W32.Sober.O@mm is a mass-mailing worm that sends itself as an email attachment to addresses gathered from the compromised computer. It uses its own SMTP engine to spread. The email may be in either English or German.

English:

Subject:
One of the following:


Re:Your Password
Re:Registration Confirmation
Re:Your email was blocked
Re:mailing error
Re: [blank]

Message:
One of the following:


ok ok ok,,,,, here is it


Account and Password Information are attached!
Visit: http:/ /www.[random domain]


This is an automatically generated E-Mail Delivery Status Notification.
Mail-Header, Mail-Body and Error Description are attached

Appends one of the following randomly to the bottom of the message:


Attachment-Scanner: Status OK
AntiVirus: No Virus found
Server-AntiVirus: No Virus (Clean)
http:/ / www.[random domain]

Attachment:
One of the following:


our_secret.zip
mail_info.zip
error-mail_info.zip
account_info.zip
account_info-text.zip

Note: The attachment will be a zip file containing a copy of the worm. The file name within the zip file will be Winzipped-Text_Data.txt[many spaces].pif or Winzipped-Text_Data.txt[many spaces].exe.


Life is like a bowl of beer flavored chocolate covered dog turds.. it makes no sense. :pokinit:

Where is the Mammoth?

How the Mammoth came to be

Number Two :pokinit:

FATB0Y

  • Offline The 2.5K Group
  • ****
  • Turtle Points: 0
  • Male Posts: 2,803
  • Member since Nov '04
    • View Profile
    • fatboy on my space.com
Re: Mass Mailing Worm
« Reply #10 on: May 02, 2005, 06:18:15 PM »
 :beerchug: 
« Last Edit: May 04, 2005, 12:29:00 AM by 03HDFATBOY »

Willy Mammoth [OP]

  • Offline Gold Turtle Award
  • *
  • Turtle Points: 0
  • Male Posts: 4,252
  • Member since Nov '04
    • View Profile
Re: Mass Mailing Worm
« Reply #11 on: May 02, 2005, 06:21:22 PM »
Don't mean to scare anyone, but it could be anybody. It could also be many here. These things tend to get around. Best thing you could do is get a good security program like Norton Internet Security and just don't open any email unless you know where it came from. Know your senders and how they address you and watch out for attachments that don't look rite.
:usa: American by birth, redneck by choice. 

Making Of http://board.marlincrawler.com/index.php?topic=6472.0  
 
Sightings Of  http://board.marlincrawler.com/index.php?topic=10805.0

FATB0Y

  • Offline The 2.5K Group
  • ****
  • Turtle Points: 0
  • Male Posts: 2,803
  • Member since Nov '04
    • View Profile
    • fatboy on my space.com
Re: Mass Mailing Worm
« Reply #12 on: May 02, 2005, 06:24:02 PM »
Mrs W. I'll ditch the Pic. If it Makes You happy. :beerchug:
« Last Edit: May 04, 2005, 12:31:14 AM by 03HDFATBOY »

RUGER

  • Offline The 1K Club
  • *
  • Turtle Points: 17495
  • Male Posts: 1,022
  • Member since May '02
  • I love Marlin Crawler!
    • View Profile
    • Buy me a beer
Re: Mass Mailing Worm
« Reply #13 on: May 02, 2005, 06:29:52 PM »
thanks mrs willy...that helped a buntch.

i dont think my roomies on here. hes got 90 mustang(basicly stock) and is on various engineering projects. the super mileage car, and a little on the baja. we really dont talk alot...we're getting better but we will only be living together fer another 3 weeks(dorms). its kinda sad hes opening up with such little time left.

happy trails
rich *ruger* :usa:  :turtle:
:usa: GOD BLESS AMERICA :usa:

"the hag" 83 toy with 5" all-pro lift, marlin crawler dual case #1011 and marlin hy-steer, 35s, 5.29's, exo cage, yada, yada, yada. she's back in black.

97 F250
84 Grand Waggy
77 Scout II SS
96 Explorer Sport
20 F150

USN SEABEE 2008-2012 :usa:
run with THE PACK 4wdc of los osos
NRA life member

FATB0Y

  • Offline The 2.5K Group
  • ****
  • Turtle Points: 0
  • Male Posts: 2,803
  • Member since Nov '04
    • View Profile
    • fatboy on my space.com
Re: Mass Mailing Worm
« Reply #14 on: May 02, 2005, 06:36:38 PM »
but seriously, I do appreciate the removal of the picture.
U R :welcome: :beerchug:

Lady Di

  • Goddess of Mud
  • Rock Ninja
  • Offline Rock Master
  • *
  • Turtle Points: 0
  • Female Posts: 299
  • Member since Nov '04
    • View Profile
Life is like a bowl of beer flavored chocolate covered dog turds.. it makes no sense. :pokinit:

Where is the Mammoth?

How the Mammoth came to be

Number Two :pokinit:

Willy Mammoth [OP]

  • Offline Gold Turtle Award
  • *
  • Turtle Points: 0
  • Male Posts: 4,252
  • Member since Nov '04
    • View Profile
Re: Mass Mailing Worm
« Reply #16 on: May 02, 2005, 06:41:32 PM »
:offtopic:  Do we need to start a bashing other members page? Get your own thread. Like Mike has said before http://board.marlincrawler.com/index.php?topic=10636.new#new
:usa: American by birth, redneck by choice. 

Making Of http://board.marlincrawler.com/index.php?topic=6472.0  
 
Sightings Of  http://board.marlincrawler.com/index.php?topic=10805.0

Lady Di

  • Goddess of Mud
  • Rock Ninja
  • Offline Rock Master
  • *
  • Turtle Points: 0
  • Female Posts: 299
  • Member since Nov '04
    • View Profile
Re: Mass Mailing Worm
« Reply #17 on: May 02, 2005, 06:48:48 PM »
But we already shook hands and made up, but you are right. My bad.  :slap:

Anyway, back ON TOPIC:

One easy way to find out if you are infected is to check in your registry.

From your Start bar, click on RUN... and type in REGEDIT.

This will bring up your registry editor.

DO NOT MUCK WITH ANYTHING HERE UNLESS YOU KNOW WHAT YOU'RE DOING!

Just look for these files by navigating the folders to this:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

in the Run folder look for:

" WinStart" = "%Windir%\Connection Wizard\Status\services.exe"

and in:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

look for:

"_WinStart" = "%Windir%\Connection Wizard\Status\services.exe"

these cause the virus to autorun when you start your computer.
Life is like a bowl of beer flavored chocolate covered dog turds.. it makes no sense. :pokinit:

Where is the Mammoth?

How the Mammoth came to be

Number Two :pokinit:

Rocksurfer

  • Momentum Man
  • Offline Gold Turtle Award
  • *
  • Turtle Points: 730
  • Male Posts: 13,860
  • Member since Jul '04
  • Lego Enforcement
    • View Profile
    • Spinnin4s 4x4 Club
Re: Mass Mailing Worm
« Reply #18 on: May 02, 2005, 06:53:23 PM »
I have AVG anti-virus, ad-aware and STINGER to keep the creepy crawlies out of my computer. My daughter used to have Norton and she continually had virus's sneekin' in some how.  I went to her house and installed AVG and it found something like 150 virus's, 70 Trojan horse's and something that AVG detected but could not remove, probably a worm. I had the same experience with Norton and is why I got AVG and AVG found about 70 or so virus's that Norton didn't.  As to the worm my STINGER  will deal with that silly little parasite.
The Ghost-Rider/Ghost Runner

No matter how far you fall, the ground will always catch you

BLACKDOG

  • 3.0 Killer
  • Offline Gold Turtle Award
  • *
  • Turtle Points: 718
  • Male Posts: 7,644
  • Member since Aug '04
  • I used to fit
    • View Profile
Re: Mass Mailing Worm
« Reply #19 on: May 03, 2005, 11:50:12 AM »
I have recieved worms from someone on this forum a while ago, and you odnt have to be emailing buddies.  I had never emailed him when they started popping up.  I spoke to him on PM about it, and he had no idea it was happening.  I havent gotten anyfor a while, every once in a while I still get one.
:usa: Its better to die on your feet than live on your knees :usa:

"Freedom is never more than one generation away from extinction. We didn't pass it to our children in the bloodstream. It must be fought for, protected, and handed on for them to do the same, or one day we will spend our sunset years telling our children and our children's children what it was once like in the United States where men were free. "

"I don't believe in a government that protects us from ourselves."
              -Ronald Reagan

Don't take life too seriously, it isn't permanent

brainlessfool

  • It's not my problem if you can't hear the voices too.
  • Offline Gold Turtle Award
  • *
  • Turtle Points: 2730
  • Male Posts: 4,207
  • Member since Jun '02
  • drive fast or the devil may get ya
    • View Profile
    • Buy me a cigar
Re: Mass Mailing Worm
« Reply #20 on: May 03, 2005, 01:09:35 PM »
I had a couple of "e-mail eorres" on my e-mail yesterday.  I don't have Mr. willes e-mail ads. so I don't know what to think.  :headscratch:  :dunno:
A good day working, that's just sick :reg:

WHITE_TRASH

  • Offline Gold Turtle Award
  • *
  • Turtle Points: 679
  • Posts: 6,277
  • Member since Feb '03
  • Don't blame me, I didn't vote for this crap.
    • View Profile
Re: Mass Mailing Worm
« Reply #21 on: May 03, 2005, 02:06:39 PM »
Ive been getting a grip of crap junk mail lately.  All of it is 73k so its all the same crap.  I havent opened anything as of yet nor do I plan on it.  In the past few days Ive gotten 31 junk e-mails, usually I only get 2 or 3 tops per week.  So Id bet its the worm eh?
Full hydro, 186:1 with an auto and 44's what could go wrong??

Lady Di

  • Goddess of Mud
  • Rock Ninja
  • Offline Rock Master
  • *
  • Turtle Points: 0
  • Female Posts: 299
  • Member since Nov '04
    • View Profile
Re: Mass Mailing Worm
« Reply #22 on: May 03, 2005, 06:12:00 PM »
I have recieved worms from someone on this forum a while ago, and you odnt have to be emailing buddies. I had never emailed him when they started popping up. I spoke to him on PM about it, and he had no idea it was happening. I havent gotten anyfor a while, every once in a while I still get one.
who the email says the email is from is not necessarily where it came from.

Typically what they do is take any random name out of the sucker, erm, I mean victims address book and put that as the FROM name, so you don't know where it is coming from.

As far as having our addresses, if whoever opened the zip file (btw - good rule of thumb, never open an attachment unless you are sure of where it came from, especially a ZIP or EXE file, but worms can be imbedded in HTML emails too) in the first place had the address of someone else who then opened it, thereby sending it to everyone in their address book, and then went to someone that had our address, that could have all morphed and been included to look like it was coming from an entirely different source.

This isn't particularly harmful but will implant itself in your registry so it autoruns everytime you start you computer and mails itself out again. THe most that this one does it clog up the bandwidth and crash websites.

Most of the Antivirus sites, Symantec, McAfee, AVG, Panda, probably even Windows will have removal tools for this.
Life is like a bowl of beer flavored chocolate covered dog turds.. it makes no sense. :pokinit:

Where is the Mammoth?

How the Mammoth came to be

Number Two :pokinit:

UNBREAKABLE

  • Offline The 2K Group
  • ***
  • Turtle Points: 372
  • Male Posts: 2,028
  • Member since Aug '04
  • Yeah, I guess you could say I'm a RockStar
    • View Profile
Re: Mass Mailing Worm
« Reply #23 on: May 03, 2005, 06:16:10 PM »
That's how I roll

Lady Di

  • Goddess of Mud
  • Rock Ninja
  • Offline Rock Master
  • *
  • Turtle Points: 0
  • Female Posts: 299
  • Member since Nov '04
    • View Profile
Re: Mass Mailing Worm
« Reply #24 on: May 03, 2005, 06:22:03 PM »
and for the geeks that crawl among us:

http://mvps.org/winhelp2002/hosts.htm
Life is like a bowl of beer flavored chocolate covered dog turds.. it makes no sense. :pokinit:

Where is the Mammoth?

How the Mammoth came to be

Number Two :pokinit:

FATB0Y

  • Offline The 2.5K Group
  • ****
  • Turtle Points: 0
  • Male Posts: 2,803
  • Member since Nov '04
    • View Profile
    • fatboy on my space.com
Re: Mass Mailing Worm
« Reply #25 on: May 04, 2005, 12:34:40 AM »
 :haha:
who the email says the email is from is not necessarily where it came from.

Typically what they do is take any random name out of the sucker, erm, I mean victims address book and put that as the FROM name, so you don't know where it is coming from.
:funny: :rofl: now I gotta go pee :toiletwait:

 
 
 
 
 

Related Topics

0 Replies
1232 Views
Last post Aug 26, 2003, 02:41:59 PM
by snorklehead
0 Replies
1202 Views
Last post Dec 04, 2004, 07:53:30 PM
by gizmo
5 Replies
1792 Views
Last post Apr 01, 2005, 11:07:35 AM
by toyoder
13 Replies
5546 Views
Last post Dec 22, 2005, 07:04:45 PM
by kneedownnate
2 Replies
1408 Views
Last post Feb 11, 2011, 09:34:10 AM
by BoG-ToY