Author
|
Topic: virus: how many e-mails has the Sobig.F. worm released? (Read 965 times) |
|
Walter Watts
Archon
Gender:
Posts: 1571 Reputation: 8.61 Rate Walter Watts
Just when I thought I was out-they pull me back in
|
|
virus: how many e-mails has the Sobig.F. worm released?
« on: 2003-09-11 07:29:26 » |
|
Q. Approximately how many e-mails has the Sobig.F. worm (released in August) generated?
A. The Sobig.F. worm has generated at least 100 million e-mails. Seventy-two hours after the attack, the worm manufactured one in every 17 e-mails.
--
Walter Watts Tulsa Network Solutions, Inc.
"Reminding you to help control the human population. Have your sexual partner spayed or neutered."
--- To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>
|
Walter Watts Tulsa Network Solutions, Inc.
No one gets to see the Wizard! Not nobody! Not no how!
|
|
|
Blunderov
Archon
Gender:
Posts: 3160 Reputation: 8.63 Rate Blunderov
"We think in generalities, we live in details"
|
|
RE: virus: how many e-mails has the Sobig.F. worm released?
« Reply #1 on: 2003-09-11 13:32:57 » |
|
I've been getting about 3-4 per day lately. The majority claim to emanate from US Military addresses.
Best Regards Blunderov
> -----Original Message----- > From: owner-virus@lucifer.com [mailto:owner-virus@lucifer.com] On Behalf > Of Walter Watts > Sent: 11 September 2003 1329 > To: undisclosed-recipients: > Subject: virus: how many e-mails has the Sobig.F. worm released? > > Q. Approximately how many e-mails has the Sobig.F. worm (released in > August) generated? > > A. The Sobig.F. worm has generated at least 100 million e-mails. > Seventy-two hours after the attack, the worm manufactured one in every > 17 e-mails. > > > > -- > > Walter Watts > Tulsa Network Solutions, Inc. > > "Reminding you to help control the human population. Have your sexual > partner spayed or neutered." > > > --- > To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi- > bin/virus-l>
--- To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>
|
|
|
|
DrSebby
Archon
Gender:
Posts: 456 Reputation: 8.07 Rate DrSebby
...Oh, you smell of lambs!
|
|
Re: virus: how many e-mails has the Sobig.F. worm released?
« Reply #2 on: 2003-09-11 16:19:04 » |
|
...what exactly does the Sobig virus do? i did a virus scan a day ago or so...came up with a few copies of some harmless spyware, which i cleaned...and now today, i woke up to find the bootup screen on my computer, but with a long number with dashes in between at the bottom...like a serial # of sorts. anyways, i dont give it much thought and assume my computer crashed during the night somehow. i reboot it...and nothing! the fan goes on,....and it therefore sounds like it's running...but no form of actual life can be detected from the processor! the monitor displays nothing...in fact it doesnt even turn on from it's self-imposed standby mode...which happens when nothing is coming from the processor of course. any ideas?
DrSebby. "Courage...and shuffle the cards".
----Original Message Follows---- From: Walter Watts <wlwatts@cox.net> Reply-To: virus@lucifer.com Subject: virus: how many e-mails has the Sobig.F. worm released? Date: Thu, 11 Sep 2003 06:29:26 -0500
Q. Approximately how many e-mails has the Sobig.F. worm (released in August) generated?
A. The Sobig.F. worm has generated at least 100 million e-mails. Seventy-two hours after the attack, the worm manufactured one in every 17 e-mails.
--
Walter Watts Tulsa Network Solutions, Inc.
"Reminding you to help control the human population. Have your sexual partner spayed or neutered."
--- To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>
_________________________________________________________________ Add photos to your e-mail with MSN 8. Get 2 months FREE*. http://join.msn.com/?page=features/featuredemail
--- To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>
|
"courage and shuffle the cards..."
|
|
|
rhinoceros
Archon
Gender:
Posts: 1318 Reputation: 8.06 Rate rhinoceros
My point is ...
|
|
Re:virus: how many e-mails has the Sobig.F. worm released?
« Reply #3 on: 2003-09-11 17:27:21 » |
|
[DrSebby] ...what exactly does the Sobig virus do? i did a virus scan a day ago or so...came up with a few copies of some harmless spyware, which i cleaned...and now today, i woke up to find the bootup screen on my computer, but with a long number with dashes in between at the bottom...like a serial # of sorts. anyways, i dont give it much thought and assume my computer crashed during the night somehow. i reboot it...and nothing! the fan goes on,....and it therefore sounds like it's running...but no form of actual life can be detected from the processor! the monitor displays nothing...in fact it doesnt even turn on from it's self-imposed standby mode...which happens when nothing is coming from the processor of course. any ideas?
[rhinoceros] Sobig had no damaging payload until the last time I checked. Just spreading itself around and clogging the networks. Probably some other shit happened...
You'll have to narrow it down. Does the BIOS screen come up when you hit Del (or whatever is the proper key for your machine) at startup? Can you hear hard disk activity (or see the hard disk LED blinking, if there is one)? Can the machine start with a bootable diskette or CD? Can you see if the processor fan is working?
If it cannot even start with a boot diskette, you will probably have to take it to a repair shop...
|
|
|
|
Kalkor
Magister
Gender:
Posts: 109 Reputation: 6.78 Rate Kalkor
Kneading the swollen donkey...
|
|
RE: virus: how many e-mails has the Sobig.F. worm released?
« Reply #4 on: 2003-09-11 17:30:28 » |
|
[Blunderov] I've been getting about 3-4 per day lately. The majority claim to emanate from US Military addresses.
[Kalkor] I suspect that you're getting a majority of them from US Military addresses because the military servers are more likely to be configured to assume that what's in the "FROM" field in an email's header is actually where the message came from, and not the "X-SENDER" field like most email servers do. Since the messages sent by Sobig.F do not include any X-information such as the X-SENDER, a lot of email servers will just drop them as they don't actually have an origin at that point. However, it takes an act of congress to change the way the military does things, and for now they go primarily on what is listed in the "FROM" field... which is intentionally generated by Sobig.F based on whatever the virus finds on the infected HDD... this is where YOUR email address comes into the picture.
Anyone know for certain? This is all merely speculation on my part based on my limited understanding of Sobig.F, and a few years' experience running mail servers... If I'm wrong, speak up! hehehhehe
Kalkor
--- To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>
|
|
|
|
Kalkor
Magister
Gender:
Posts: 109 Reputation: 6.78 Rate Kalkor
Kneading the swollen donkey...
|
|
RE: virus: how many e-mails has the Sobig.F. worm released?
« Reply #5 on: 2003-09-11 17:36:29 » |
|
[DrSebby] ...what exactly does the Sobig virus do? i did a virus scan a day ago or so...came up with a few copies of some harmless spyware, which i cleaned...and now today, i woke up to find the bootup screen on my computer, but with a long number with dashes in between at the bottom...like a serial # of sorts. anyways, i dont give it much thought and assume my computer crashed during the night somehow. i reboot it...and nothing! the fan goes on,....and it therefore sounds like it's running...but no form of actual life can be detected from the processor! the monitor displays nothing...in fact it doesnt even turn on from it's self-imposed standby mode...which happens when nothing is coming from the processor of course. any ideas?
[Kalkor] I don't think Sobig.F is destructive in that way. The long number with dashes you described sounds almost like a BIOS version number? If you say it showed up during the bootup screen... Above that, was there a place where it had tested ram or autodetected any of your IDE devices? Maybe even an energy star logo in the upper right?
When you reboot, do you get spinup from the HDD? Does the floppy light come on? You say the fans start up but the monitor doesn't come on... display card problems? Do you hear any beeps? If you put a floppy in the drive and turn it on, does it try to read the floppy? Might need some more troubleshooting, but any of those symptoms should help narrow it down a bit ;-}
Good luck dood!
Kalkor
--- To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>
|
|
|
|
DrSebby
Archon
Gender:
Posts: 456 Reputation: 8.07 Rate DrSebby
...Oh, you smell of lambs!
|
|
RE: virus: how many e-mails has the Sobig.F. worm released?
« Reply #6 on: 2003-09-11 18:51:16 » |
|
DrSebby. "Courage...and shuffle the cards".
[Kalkor] I don't think Sobig.F is destructive in that way. The long number with dashes you described sounds almost like a BIOS version number? If you say it showed up during the bootup screen... Above that, was there a place where it had tested ram or autodetected any of your IDE devices? Maybe even an energy star logo in the upper right?
Sebby: yes, thats the screen im talking about. "enter DELete to enter setup" and all the rest. i came to my computer and that was showing up...along with the mysterious hyphenated # at the bottom looking something like: 0084-4325-6884-1340-00-234 or something like that.
[Kalkor] When you reboot, do you get spinup from the HDD? Does the floppy light come on? You say the fans start up but the monitor doesn't come on... display card problems? Do you hear any beeps? If you put a floppy in the drive and turn it on, does it try to read the floppy?
Sebby: well, it seems i can hear the HD spin-up when i turn it on...and it does try to read the cd drive....with continued spin(something it is supposed to do). the floppy light however does not go on...whether i put a disk in it or not. no beeps or sound...which is a bad thing i would assume. there is no sign that behind the darkened screen, anything is happening at all. i sort of thought i might have accidentally cooked the processor, but why would that happen at night? the coolest time of day? and why would i have seen that initial setup screen sitting there before i tried to reboot it? would something still be visible onscreen of a computer whose processor was fried??? thank you very much for your assistance in this dear Kalkor.
Sebastian.
--- To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>
_________________________________________________________________ STOP MORE SPAM with the new MSN 8 and get 2 months FREE* http://join.msn.com/?page=features/junkmail
--- To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>
|
"courage and shuffle the cards..."
|
|
|
rhinoceros
Archon
Gender:
Posts: 1318 Reputation: 8.06 Rate rhinoceros
My point is ...
|
|
Re:virus: how many e-mails has the Sobig.F. worm released?
« Reply #7 on: 2003-09-11 22:01:05 » |
|
[Sebby] yes, thats the screen im talking about. "enter DELete to enter setup" and all the rest.
<snip>
[Sebby] well, it seems i can hear the HD spin-up when i turn it on...and it does try to read the cd drive....with continued spin(something it is supposed to do). the floppy light however does not go on...whether i put a disk in it or not. no beeps or sound...which is a bad thing i would assume. there is no sign that behind the darkened screen, anything is happening at all. i sort of thought i might have accidentally cooked the processor, but why would that happen at night? the coolest time of day? and why would i have seen that initial setup screen sitting there before i tried to reboot it? would something still be visible onscreen of a computer whose processor was fried??? thank you very much for your assistance in this dear Kalkor.
[rhinoceros] The processor is not fried. It seems to be working and trying to run all the startup procedures (trying to find a bootable disk or CD). It just happened that the computer rebooted after a problem occured. Does it get into the BIOS setup when you hit Del?
If it does, the problem is probably with your hard disk. The best case is if the disk is intact but the BIOS does not recognize it any more. You can try to fix that by getting into the BIOS setup by pressing Del and telling it to identify the disk (if it is an LBA disk) or specifically giving it the disk parameters from the manual (if it is not).
The second best case is if the computer can see the disk, but the disk is not bootable any more because a system file was deleted or damaged. In this case, you'll have to boot from a CD (or a floppy disk -- it depends on your current BIOS setup settings) and then make the hard disk bootable again or even reinstal your OS.
The worst case is if the hard disk actually crashed...
|
|
|
|
DrSebby
Archon
Gender:
Posts: 456 Reputation: 8.07 Rate DrSebby
...Oh, you smell of lambs!
|
|
Re:virus: how many e-mails has the Sobig.F. worm released?
« Reply #8 on: 2003-09-11 23:59:32 » |
|
...wouldnt i at least see the blue screen of death if one of these situations were the case? example; i turn the monitor on after the computer...it goes 'green light' and then after a few seconds (presumably waiting for some sort of output or signal from mr. computer) it just switches over to the "orange light of waiting" for evermore. it really seems as if nothing is coming out of the computer whatsoever. i put a bootable cd in and still nothing. also, there isnt even a boot-up "BEEP" that the machine makes...no sounds whatsoever...from the speakers or from the internal computer tower speaker(the one that makes the beeps). i've tried looking for a suicide note in and around the printer, but still nothing. this is looking bad. real bad. =( a despondant sebby awaits your reply.
DrSebby. "Courage...and shuffle the cards".
----Original Message Follows---- From: "rhinoceros" <rhinoceros@freemail.gr> Reply-To: virus@lucifer.com To: virus@lucifer.com Subject: Re:virus: how many e-mails has the Sobig.F. worm released? Date: Thu, 11 Sep 2003 20:01:05 -0600
[Sebby] yes, thats the screen im talking about. "enter DELete to enter setup" and all the rest.
<snip>
[Sebby] well, it seems i can hear the HD spin-up when i turn it on...and it does try to read the cd drive....with continued spin(something it is supposed to do). the floppy light however does not go on...whether i put a disk in it or not. no beeps or sound...which is a bad thing i would assume. there is no sign that behind the darkened screen, anything is happening at all. i sort of thought i might have accidentally cooked the processor, but why would that happen at night? the coolest time of day? and why would i have seen that initial setup screen sitting there before i tried to reboot it? would something still be visible onscreen of a computer whose processor was fried??? thank you very much for your assistance in this dear Kalkor.
[rhinoceros] The processor is not fried. It seems to be working and trying to run all the startup procedures (trying to find a bootable disk or CD). It just happened that the computer rebooted after a problem occured. Does it get into the BIOS setup when you hit Del?
If it does, the problem is probably with your hard disk. The best case is if the disk is intact but the BIOS does not recognize it any more. You can try to fix that by getting into the BIOS setup by pressing Del and telling it to identify the disk (if it is an LBA disk) or specifically giving it the disk parameters from the manual (if it is not).
The second best case is if the computer can see the disk, but the disk is not bootable any more because a system file was deleted or damaged. In this case, you'll have to boot from a CD (or a floppy disk -- it depends on your current BIOS setup settings) and then make the hard disk bootable again or even reinstal your OS.
The worst case is if the hard disk actually crashed...
---- This message was posted by rhinoceros to the Virus 2003 board on Church of Virus BBS. <http://virus.lucifer.com/bbs/index.php?board=54;action=display;threadid=29251> --- To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>
_________________________________________________________________ The new MSN 8: advanced junk mail protection and 2 months FREE* http://join.msn.com/?page=features/junkmail
--- To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>
|
"courage and shuffle the cards..."
|
|
|
Kalkor
Magister
Gender:
Posts: 109 Reputation: 6.78 Rate Kalkor
Kneading the swollen donkey...
|
|
RE: virus: how many e-mails has the Sobig.F. worm released?
« Reply #9 on: 2003-09-12 00:08:36 » |
|
[Sebby] ...wouldnt i at least see the blue screen of death if one of these situations were the case? example; i turn the monitor on after the computer...it goes 'green light' and then after a few seconds (presumably waiting for some sort of output or signal from mr. computer) it just switches over to the "orange light of waiting" for evermore. it really seems as if nothing is coming out of the computer whatsoever. i put a bootable cd in and still nothing. also, there isnt even a boot-up "BEEP" that the machine makes...no sounds whatsoever...from the speakers or from the internal computer tower speaker(the one that makes the beeps). i've tried looking for a suicide note in and around the printer, but still nothing. this is looking bad. real bad. =( a despondant sebby awaits your reply.
[Kalkor] No beeps? No BIOS. Sorry. You're gonna have to start swapping out components I'm afraid, unless you can at least get the monitor to come out of rest and display the initial BIOS self-test bits...
--- To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>
|
|
|
|
DrSebby
Archon
Gender:
Posts: 456 Reputation: 8.07 Rate DrSebby
...Oh, you smell of lambs!
|
|
RE: virus: how many e-mails has the Sobig.F. worm released?
« Reply #10 on: 2003-09-12 01:09:46 » |
|
...yeah thats what im sort of figuring. but what do you suppose it means...the fact that i saw that initial setup screen with the weird serial number-like thing at the bottom.... and then i restart the computer and NOTHING! at least i had a screen there until i restarted. i wish i had hit delete and entered the bios to poke around.
DrSebby. "Courage...and shuffle the cards".
----Original Message Follows---- From: "Kalkor" <kalkor@kalkor.com> Reply-To: virus@lucifer.com To: <virus@lucifer.com> Subject: RE: virus: how many e-mails has the Sobig.F. worm released? Date: Thu, 11 Sep 2003 21:08:36 -0700
[Sebby] ...wouldnt i at least see the blue screen of death if one of these situations were the case? example; i turn the monitor on after the computer...it goes 'green light' and then after a few seconds (presumably waiting for some sort of output or signal from mr. computer) it just switches over to the "orange light of waiting" for evermore. it really seems as if nothing is coming out of the computer whatsoever. i put a bootable cd in and still nothing. also, there isnt even a boot-up "BEEP" that the machine makes...no sounds whatsoever...from the speakers or from the internal computer tower speaker(the one that makes the beeps). i've tried looking for a suicide note in and around the printer, but still nothing. this is looking bad. real bad. =( a despondant sebby awaits your reply.
[Kalkor] No beeps? No BIOS. Sorry. You're gonna have to start swapping out components I'm afraid, unless you can at least get the monitor to come out of rest and display the initial BIOS self-test bits...
--- To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>
_________________________________________________________________ MSN 8 helps eliminate e-mail viruses. Get 2 months FREE*. http://join.msn.com/?page=features/virus
--- To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>
|
"courage and shuffle the cards..."
|
|
|
Kalkor
Magister
Gender:
Posts: 109 Reputation: 6.78 Rate Kalkor
Kneading the swollen donkey...
|
|
RE: virus: how many e-mails has the Sobig.F. worm released?
« Reply #11 on: 2003-09-12 01:30:23 » |
|
[Sebby] ...wouldnt i at least see the blue screen of death if one of these situations were the case? example; i turn the monitor on after the computer...it goes 'green light' and then after a few seconds (presumably waiting for some sort of output or signal from mr. computer) it just switches over to the "orange light of waiting" for evermore. it really seems as if nothing is coming out of the computer whatsoever. i put a bootable cd in and still nothing. also, there isnt even a boot-up "BEEP" that the machine makes...no sounds whatsoever...from the speakers or from the internal computer tower speaker(the one that makes the beeps). i've tried looking for a suicide note in and around the printer, but still nothing. this is looking bad. real bad. =( a despondant sebby awaits your reply.
[Kalkor] No beeps? No BIOS. Sorry. You're gonna have to start swapping out components I'm afraid, unless you can at least get the monitor to come out of rest and display the initial BIOS self-test bits...
[Sebby2] ...yeah thats what im sort of figuring. but what do you suppose it means...the fact that i saw that initial setup screen with the weird serial number-like thing at the bottom.... and then i restart the computer and NOTHING! at least i had a screen there until i restarted. i wish i had hit delete and entered the bios to poke around.
[Kalkor2] BSOD is part of Windoze... you hadn't even gotten there yet, so I would not expect the BSOD. As you say, it seemed the computer was frozen at the BIOS screen... you probably wouldn't have even been able to get into BIOS setup, as the computer didn't seem to want to get past the "counting its marbles" phase, pre-OS load.
Sounds like the BIOS had a hickup and stopped right at that point, never to be able to reach that point again. I'd start with some removal of, say, video card, and boot, see if you get the beeps (motherboard error codes). If not, try removing all IDE devices, and do the same thing (boot, listen for beep codes). If nothing, I'd guess you're SOL on the mobo. Wish I had a different answer for you. If anyone else has troubleshooting steps to suggest, speak up!
Kalkor
--- To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>
|
|
|
|
Pedro
Adept
Gender:
Posts: 46 Reputation: 7.10 Rate Pedro
|
|
Re:virus: how many e-mails has the Sobig.F. worm released?
« Reply #12 on: 2003-09-12 23:13:02 » |
|
I think the most amount I got in one day was about 54. I still get them constantly. They just keep on rolling in. But they have been slowly down, I must admit that much. Now they have cut down to only a few a day, which is good.
|
Website | Profile
|
|
|
DrSebby
Archon
Gender:
Posts: 456 Reputation: 8.07 Rate DrSebby
...Oh, you smell of lambs!
|
|
RE: virus: how many e-mails has the Sobig.F. worm released?
« Reply #13 on: 2003-09-13 22:28:58 » |
|
....ok, i opened up my computer after having chatted with the people that sold it to me...they suggested that the three beeps sounded like a vid. card problem....but i cant be sure. so far i have pulled out the vid card...put it back in, unplugged it etc....i still seem to get the three beeps on startup. so i must ask, without actually replacing something, how do i test for confirmation of error? i pulled the supposed vid card evil-doer, and i still get the error beeps. any ideas what it might be instead?
DrSebby. "Courage...and shuffle the cards".
----Original Message Follows---- From: "Kalkor" <kalkor@kalkor.com> Reply-To: virus@lucifer.com To: <virus@lucifer.com> Subject: RE: virus: how many e-mails has the Sobig.F. worm released? Date: Thu, 11 Sep 2003 22:30:23 -0700
[Sebby] ...wouldnt i at least see the blue screen of death if one of these situations were the case? example; i turn the monitor on after the computer...it goes 'green light' and then after a few seconds (presumably waiting for some sort of output or signal from mr. computer) it just switches over to the "orange light of waiting" for evermore. it really seems as if nothing is coming out of the computer whatsoever. i put a bootable cd in and still nothing. also, there isnt even a boot-up "BEEP" that the machine makes...no sounds whatsoever...from the speakers or from the internal computer tower speaker(the one that makes the beeps). i've tried looking for a suicide note in and around the printer, but still nothing. this is looking bad. real bad. =( a despondant sebby awaits your reply.
[Kalkor] No beeps? No BIOS. Sorry. You're gonna have to start swapping out components I'm afraid, unless you can at least get the monitor to come out of rest and display the initial BIOS self-test bits...
[Sebby2] ...yeah thats what im sort of figuring. but what do you suppose it means...the fact that i saw that initial setup screen with the weird serial number-like thing at the bottom.... and then i restart the computer and NOTHING! at least i had a screen there until i restarted. i wish i had hit delete and entered the bios to poke around.
[Kalkor2] BSOD is part of Windoze... you hadn't even gotten there yet, so I would not expect the BSOD. As you say, it seemed the computer was frozen at the BIOS screen... you probably wouldn't have even been able to get into BIOS setup, as the computer didn't seem to want to get past the "counting its marbles" phase, pre-OS load.
Sounds like the BIOS had a hickup and stopped right at that point, never to be able to reach that point again. I'd start with some removal of, say, video card, and boot, see if you get the beeps (motherboard error codes). If not, try removing all IDE devices, and do the same thing (boot, listen for beep codes). If nothing, I'd guess you're SOL on the mobo. Wish I had a different answer for you. If anyone else has troubleshooting steps to suggest, speak up!
Kalkor
--- To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>
_________________________________________________________________ The new MSN 8: smart spam protection and 2 months FREE* http://join.msn.com/?page=features/junkmail
--- To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>
|
"courage and shuffle the cards..."
|
|
|
|