ALERT:Reteras Redux: The Worm ReturnsAll of us accessing this forum are using a computer, if you've got a problem, have or need information, then post here. | |
![]() |
| | LinkBack | Thread Tools | Display Modes |
![]() | ![]() |
| |||||||
ALERT:Reteras Redux: The Worm ReturnsAll of us accessing this forum are using a computer, if you've got a problem, have or need information, then post here. | |
![]() |
| | LinkBack | Thread Tools | Display Modes |
| | #1 | ||
| Guest
Posts: n/a
|
Type: Worm Aliases: W32.Sobig.F@mm, WORM_SOBIG.F, I-Worm.Sobig.f, W32/Sobig.F-mm Vulnerable Operating Systems: Windows 95/98/ME/NT/2000/XP. How It Infects: Through infected email attachments or shared network folders. What It Does: - Scours files on your hard drive for email addresses, then sends infected email to the addresses it finds. - Spoofs (mimics) the From: email address to make people think the message is from you or someone they might know. The email address will either be one found on your computer or admin@internet.com. - Modifies your computer's registry so that it loads itself whenever Windows starts. - Places infected files onto your computer. - Infects networked computers through their shared folders. - Attempts to contact a list of web servers and access an address where it can download files to your computer, files such as spyware, trojans, or newer versions of itself. - Reportedly, Win32.HLLM.Reteras may use your computer as a relay server for spam. - Stops its mass mailing on September 10, 2003, although the computer is still infected and needs to have the worm removed completely. If this worm follows its previous versions, it is expected to make some changes to the subject lines or attachment names, and change the registry and file entries it makes. We will continue to update Stop-Sign to remove this worm. The email subject line may include any of the following: Re: Approved Re: Details Re: Re: My details Re: Thank you! Re: That movie Re: Your application Re: Wicked screensaver Thank you! Your details The body of the email message is either "See the attached file for details" or "Please see the attached file for details." The email attachment is randomly selected from: your_document.pif document_all.pif thank_you.pif your_details.pif details.pif document_9446.pif application.pif wicked_scr.scr movie0045.pif Files with the following file extensions are searched for email addresses used to propagate the worm: .dbx .eml .hlp .htm .html .mht .wab .txt | ||
|
![]() |
| Bookmarks |
| Tags |
| alertreteras, redux, returns, worm |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Worm poses as Saddam death pics | net1 | Computer Discussion | 0 | 03-02-2005 07:27 PM |
| Attack of the talking worm | net1 | Computer Discussion | 0 | 14-09-2004 07:47 PM |
| New worm steals user data | net1 | Computer Discussion | 0 | 03-11-2003 07:02 PM |
| Romanian Student Arrested for New Blaster Worm | net1 | Daily Satellite and Broadcast industry News | 0 | 04-09-2003 09:35 PM |
| Worm could be clearing path for DDoS attack | net1 | Computer Discussion | 0 | 10-03-2003 09:18 PM |