Welcome our webmaster and SEO forum
Please enjoy the forum, contribute what you can, and wind up the Moderators!
Closed Thread
Results 1 to 3 of 3

Thread: Computer Worm Poses as E-Mail From FBI, CIA

  1. #1
    ovi Guest

    Default Computer Worm Poses as E-Mail From FBI, CIA

    It's being called the worst computer worm of the year -- a fast-spreading Internet threat that looks like an official e-mail from the CIA or FBI but can leave your computer wide open to intruders.

    The bogus e-mail claims the government has discovered you visiting "illegal" Web sites and asks you to open an attachment to answer some official questions. If you do, your computer gets infected with malware that can disable security and firewall programs and blast out similar e-mails to contacts in your address book. It can also keep you from getting to computer security Web sites that might help fix the problem, and it may open your Windows computer to intruders who can steal your personal data.

    The worm -- named "Sober X" -- has spread so far so fast that the CIA and the FBI put prominent warnings on their Web sites making clear that they did not send out the e-mail and urging people to not open the attachment.

    Across the Atlantic Ocean, Austria's equivalent to the FBI is investigating a flurry of similar bogus e-mails sent in its name to people in Austria, Germany and Switzerland, the Associated Press reported.

    "This particular virus is a mass-mailer worm and is the largest one we have seen this year," said Alfred A. Huger, senior director of engineering at Symantec Corp., which sells Norton AntiVirus software. "It's as bad as it gets. With this particular type of virus on your system, there is a high probability that your personal information will be stolen."

    Craig Schmugar, a virus-research manager at McAfee Inc.'s Avert Labs, said his company, which also makes anti-virus software, had logged more than 73,000 consumer computers reporting detection since the worm was discovered Monday.

    British e-mail security company MessageLabs Ltd. said it has intercepted more than 2.7 million copies of Sober and its variants, noting that "the size of the attack indicates that this is a major offensive, certainly one of the largest in the last few months."

    Still, the Sober worm was listed as only a "medium-risk" worm by security companies, which noted that it was not as widespread as others in recent years, notably MyDoom, which hit computer systems early last year.

    Sober is known to affect only those computers running the Windows operating system. It appears that Apple and Linux computer users were not affected.

    The e-mail informs the recipient that the user's "IP-address" has accessed more than 30 illegal Web sites and that the attachment contains a list of questions that need to be answered. The e-mail also includes an authentic phone number for the FBI or CIA.

    And that has kept government switchboard operators busy.

    FBI operators have been routing calls and complaints to its Internet Crime Complaint Center in West Virginia, which received more than 4,000 complaints about the worm on Monday. The ICC typically receives 18,000 complaints each month, said FBI spokeswoman Cathy Milhoan.

    The FBI is investigating the source of the attack, which closely resembles an e-mail worm that surfaced in February, Milhoan said, though she declined to comment on the progress of that investigation.

    Source: washingtonpost.com

  2. #2
    dmscs is offline Junior Member dmscs is on a distinguished road
    Join Date
    Nov 2005
    Posts
    29

    Default Dont Panic

    It's more an anoying thing really!


    Sober.AH Worm Aliases: W32.Sober.X@mm, Email-Worm.Win32.Sober.y, W32/Sober-Z, W32/Sober.AG.worm, Email-Worm.Win32.Sober.Y

    Technical Name W32/Sober.AH.worm

    It ends several processes belonging to some security tools, among others and displays a fake error when it is run. It spreads via email in a message written in English or German.

    Sober.AH is a worm that ends several processes belonging to some security tools, among others.

    Sober.AH spreads via email, in a message written in English or German that contains an attached file with ZIP format.

    The email message will be written in German only if the mail domain extension is one of the following: de (Germany), ch (Switzerland), at (Austria) or li (Liechtenstein).

    Removal

    # Delete the entries that Sober.AH has created in the Windows Registry:

    HKEY_CURRENT_USER Software Microsoft Windows CurrentVersion Run
    _Windows = %windir% WinSecurity services.exe

    HKEY_LOCAL_MACHINE Software Microsoft Windows CurrentVersion Run
    [blank space]Windows = %windir% WinSecurity services.exe
    where %windir% is the Windows directory.

    # Restart the computer and get on with your life

  3. #3
    ovi Guest

    Default :))

    For me is not a problem, I know to take care and to clean my system. The problem is with the beginners. A beginner as a first thing you know what do? PANIC
    As a second thing start to made a lots of calls to friends, etc.

    Ovi

Closed Thread

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

     

Similar Threads

  1. Robot future poses hard questions
    By gkd_uk in forum General Webmaster Talk
    Replies: 0
    Last Post: 04-24-2007, 07:03 PM
  2. Beware of world cup worm
    By temi in forum General Webmaster Talk
    Replies: 0
    Last Post: 06-22-2006, 07:21 AM
  3. Malicious worm that talks back
    By clau in forum Computer and Software Forum
    Replies: 0
    Last Post: 12-13-2005, 10:38 AM
  4. Win32.Worm.Mexer.E
    By ovi in forum Computer and Software Forum
    Replies: 0
    Last Post: 09-26-2004, 06:18 PM
  5. New worm - Win32.Mydoom.U@mm
    By ovi in forum Computer and Software Forum
    Replies: 0
    Last Post: 09-05-2004, 01:26 PM

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts

Search Engine Friendly URLs by vBSEO 3.6.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124