ALERT:Reteras Redux: The Worm Returns

All of us accessing this forum are using a computer, if you've got a problem, have or need information, then post here.


Reply
 
LinkBack Thread Tools Display Modes
Old 08-09-2003   #1
net1
Guest
 
Posts: n/a
ALERT:Reteras Redux: The Worm Returns

Type: Worm
Aliases: W32.Sobig.F@mm, WORM_SOBIG.F, I-Worm.Sobig.f, W32/Sobig.F-mm
Vulnerable Operating Systems: Windows 95/98/ME/NT/2000/XP.
How It Infects: Through infected email attachments or shared network folders.

What It Does:
- Scours files on your hard drive for email addresses, then sends infected email to the addresses it finds.
- Spoofs (mimics) the From: email address to make people think the message is from you or someone they might know. The email address will either be one found on your computer or admin@internet.com.
- Modifies your computer's registry so that it loads itself whenever Windows starts.
- Places infected files onto your computer.
- Infects networked computers through their shared folders.
- Attempts to contact a list of web servers and access an address where it can download files to your computer, files such as spyware, trojans, or newer versions of itself.
- Reportedly, Win32.HLLM.Reteras may use your computer as a relay server for spam.
- Stops its mass mailing on September 10, 2003, although the computer is still infected and needs to have the worm removed completely. If this worm follows its previous versions, it is expected to make some changes to the subject lines or attachment names, and change the registry and file entries it makes. We will continue to update Stop-Sign to remove this worm.

The email subject line may include any of the following:
Re: Approved
Re: Details
Re: Re: My details
Re: Thank you!
Re: That movie
Re: Your application
Re: Wicked screensaver
Thank you!
Your details

The body of the email message is either "See the attached file for details" or "Please see the attached file for details."

The email attachment is randomly selected from:
your_document.pif
document_all.pif
thank_you.pif
your_details.pif
details.pif
document_9446.pif
application.pif
wicked_scr.scr
movie0045.pif

Files with the following file extensions are searched for email addresses used to propagate the worm:
.dbx
.eml
.hlp
.htm
.html
.mht
.wab
.txt
  Reply With Quote
Reply

Bookmarks

Tags
alertreteras, redux, returns, worm


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Worm poses as Saddam death pics net1 Computer Discussion 0 03-02-2005 07:27 PM
Attack of the talking worm net1 Computer Discussion 0 14-09-2004 07:47 PM
New worm steals user data net1 Computer Discussion 0 03-11-2003 07:02 PM
Romanian Student Arrested for New Blaster Worm net1 Daily Satellite and Broadcast industry News 0 04-09-2003 09:35 PM
Worm could be clearing path for DDoS attack net1 Computer Discussion 0 10-03-2003 09:18 PM






All times are GMT +1. The time now is 08:04 AM.


All views and information expressed in users' communications and profiles represent the opinions of the users concerned and do not represent the views of Satellites.co.uk. All images and news content are believed to be in the public domain, except where otherwise stated. Forum software by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.

Content Relevant URLs by vBSEO 3.3.1