Print

Print


from autocat
Date: Wed, 20 Aug 2003 10:57:10 -0500
From: Douglas Winship <[log in to unmask]>
Reply-To: AUTOCAT <[log in to unmask]>, [log in to unmask]
Subject: SoBig virus

In case you haven't seen it or heard of it yet, worm/virus W32/Sobig.f@MM
(and variants thereof) started appearing, massively, yesterday.  I believe
it has already been distributed on some other library lists.

If you receive that e-mail, DELETE it immediately without opening it.
The virus arrives as an e-mail attachment with a .pif or .scr extension.
When run, it infects the host computer, then e-mails itself to harvested
e-mail addresses from the victim's machine. In addition, the worm "spoofs"
the "from: field", using one of the harvested e-mail addresses.

Caution:  An infected e-mail can come from addresses you recognize and may
contain the following information:

Subject:
- Your details
- Thank you!
- Here are all the details
- Re: Thank you!
- Re: Details
- Re: Re: My details
- Re: Approved
- Re: Your application
- Re: Wicked screensaver
- Re: That movie

Attachment:
- your_document.pif


If you suspect your desktop has been infected with this virus, please
contact either your local computer support office.

Douglas Winship
listowner AUTOCAT
[log in to unmask]

__________________________________________________________________
Mail submissions to [log in to unmask]
For information about joining ARLIS/NA see:
        http://www.arlisna.org//membership.html
Send administrative matters (file requests, subscription requests, etc)
        to [log in to unmask]
ARLIS-L Archives and subscription maintenance:
       http://lsv.uky.edu/archives/arlis-l.html
Questions may be addressed to list owner (Kerri Scannell) at: [log in to unmask]