from autocat Date: Wed, 20 Aug 2003 10:57:10 -0500 From: Douglas Winship <[log in to unmask]> Reply-To: AUTOCAT <[log in to unmask]>, [log in to unmask] Subject: SoBig virus In case you haven't seen it or heard of it yet, worm/virus W32/Sobig.f@MM (and variants thereof) started appearing, massively, yesterday. I believe it has already been distributed on some other library lists. If you receive that e-mail, DELETE it immediately without opening it. The virus arrives as an e-mail attachment with a .pif or .scr extension. When run, it infects the host computer, then e-mails itself to harvested e-mail addresses from the victim's machine. In addition, the worm "spoofs" the "from: field", using one of the harvested e-mail addresses. Caution: An infected e-mail can come from addresses you recognize and may contain the following information: Subject: - Your details - Thank you! - Here are all the details - Re: Thank you! - Re: Details - Re: Re: My details - Re: Approved - Re: Your application - Re: Wicked screensaver - Re: That movie Attachment: - your_document.pif If you suspect your desktop has been infected with this virus, please contact either your local computer support office. Douglas Winship listowner AUTOCAT [log in to unmask] __________________________________________________________________ Mail submissions to [log in to unmask] For information about joining ARLIS/NA see: http://www.arlisna.org//membership.html Send administrative matters (file requests, subscription requests, etc) to [log in to unmask] ARLIS-L Archives and subscription maintenance: http://lsv.uky.edu/archives/arlis-l.html Questions may be addressed to list owner (Kerri Scannell) at: [log in to unmask]