E-mail this

  • Home

  • Search
  • Send Comments
  • What's New
  • Hottest 25
      Legends

  • Odd News
  • Glossary
  • FAQ

  • Autos
  • Business
  • Cokelore
  • College
  • Computers

  • Crime
  • Critter Country
  • Disney
  • Embarrassments
  • Food

  • Glurge Gallery
  • History
  • Holidays
  • Horrors
  • Humor

  • Inboxer Rebellion
  • Language
  • Legal
  • Lost Legends
  • Love

  • Luck
  • Media Matters
  • Medical
  • Military
  • Movies

  • Music
  • Old Wives' Tales
  • Photo Gallery
  • Politics
  • Pregnancy

  • Quotes
  • Racial Rumors
  • Radio & TV
  • Religion
  • Risqué Business

  • Science
  • September 11
  • Sports
  • Titanic
  • Toxin du jour

  • Travel
  • Weddings

  • Message Archive
 
Home --> Computers --> Virus Hoaxes & Realities --> Sobig.F

Sobig.F

Virus name:   Sobig.F

Status:   Real.

Origins:   Sobig.F is the latest variant of yet another mass-mailing worm which exploits a vulnerability in the Microsoft Outlook e-mail client on Windows 95, 98, ME, NT, 2000, and XP platforms to replicate itself by mailing out messages with forged return addresses. The payload is contained in attachments to messages bearing one of the following subject lines:
  • My Details
  • Your Details
  • Thank you!
  • That movie
  • Approved
  • Application
  • Wicked screensaver
  • Re: My Details
  • Re: Your Details
  • Re: Thank you!
  • Re: That movie
  • Re: Details
  • Re: Approved
  • Re: Your application
  • Re: Wicked screensaver
The file name of the infected attachment will match one of the following:
  • wicked_scr.scr
  • movie0045.pif
  • your_document.pif
  • document_all.pif
  • thank_you.pif
  • your_details.pif
  • details.pif
  • document_9446.pif
  • application.pif
Trend Micro provides a system cleaner on its web site which will remove Sobig.F.

Additional Information:
    WORM_SOBIG.F WORM_SOBIG.F
(Trend Micro)
Last updated:   29 January 2008

Urban Legends Reference Pages © 1995-2014 by Barbara and David P. Mikkelson.
This material may not be reproduced without permission.
snopes and the snopes.com logo are registered service marks of snopes.com.