big@boss.com virus update

If you search Google for big@boss.com, you’ll see that I’m #2 today. And the #1 site is in German.

It’s been a week and a half since I first wrote about the fact that I couldn’t find any information about the big@boss.com virus, and the blog comments keep streaming in. One of them even claims that big@boss.com is an MIT conspiracy!

Maybe if the anti-virus vendors stopped calling it the W32/Sobig@MM virus they’d move higher up in the Google search results.

70 thoughts on “big@boss.com virus update

  1. richard myers

    I have considered the possibility that, because a number of us in the online anti-war community are receiving huge numbers of viruses (two or three per day for me), there could be an intentional attempt to disrupt what we are trying to accomplish.

    There is also a good possibility that we have been receiving the big@boss.com virus (and many others) by chance– it seems pretty widespread.

    HOWEVER– since last evening two anti-war maillists on Yahoo have been under persistant spoofing attacks, with phony emails routed through Italy, fraudulently sent in the names of online activists, and crafted with text intended to cause dissension.

    Here are some of the header lines from one of those emails:

    Received: (EGP: mail-8_2_3_0); 24 Jan 2003 06:55:11 -0000

    Received: (qmail 34138 invoked from network); 24 Jan 2003 06:55:10 -0000

    Received: from unknown (66.218.66.216)

    by m9.grp.scd.yahoo.com with QMQP; 24 Jan 2003 06:55:10 -0000

    Received: from unknown (HELO randazzo.comune.randazzo.ct.it) (217.58.214.196)

    by mta1.grp.scd.yahoo.com with SMTP; 24 Jan 2003 06:55:01 -0000

    These attacks are real. They also seem crude, the strange header info is there for anyone to see.

    btw, i downloaded that entire message base from MIT. It is curious that the emails from big@boss.com in that Kerberos discussion group didn’t elicit any specific mention by others on the list, if they weren’t in fact already aware of what the emails were. I’m still undecided on MIT as the source, but i wish someone with C code experience could explore the possibility.

    best wishes,

    richard myers

    rtmyers@h2net.net

  2. Elly Richardson

    Have also been receiving these emails as has my boss and a couple of friends – why have non of the so called computer giants picked up on this yet?

    Slightly worrying and how can it be stopped?

  3. Weez

    I am an activist, I work from 2 computers & I’m with Richard Myers on this “Conspiracy” idea.

    The machine I have been using to write letters against a war in Iraq & Plan Colombia has been sent big@boss.com several times.

    The other computer has not recieved it once.

  4. Michael

    I’m at school in Wisconsin, I thought it was some schmuck doing a joke, but this email crap is starting to piss me off. How can I block this ??

  5. Charo

    I am not an official anti-war activist, and during the last 3 days I have received several big@boss.com messages… also.

    Do anyone of you know what supposely do this virus?

    thanks from Spain

  6. Daddyo

    Have also received messages from big@boss.com. Norton Antivirus Quarantines this virus for me. I am not an activist. I have 4 pc’s on a network. Only the one that corresponds with grassroots – about the pledge of alegience- is gettin messages from big@boss.com. I do use yahoo.com sometimes.

  7. Mark

    I am musician and got also the big@boss mail, although I am no activist! I must be lucky, that I didn’t open it as I didn’t know about the worm…

    but I was nosy, who is big@boss, so I found this forum! The adress must have been scanned from my homepage, because I don’t often use this mailadress….

  8. Bren

    TRACE OF BIG@BOSS.COM

    Return-Path:

    Received: from MIA ([142.177.212.63]) by tomts22-srv.bellnexxia.net

    (InterMail vM.5.01.04.19 201-253-122-122-119-20020516) with ESMTP

    id

    for ; Mon, 10 Feb 2003 10:10:26 -0500

    From:

    To:

    Subject: Re: Document

    Date: Mon, 10 Feb 2003 11:10:25 –0400

    Importance: Normal

    X-Mailer: Microsoft Outlook Express 6.00.2600.0000

    X-MSMail-Priority: Normal

    X-Priority: 3 (Normal)

    MIME-Version: 1.0

    Content-Type: multipart/mixed;

    boundary=”CSmtpMsgPart123X456_000_34094FBC”

    Message-Id:

  9. Dave

    I received messages from big@boss.com. Norton Antivirus Quarantined the virus. I am not an activist and of the three accounts I have on Shawmail only one received it. Any further information on this virus? It looks very intentional.

  10. HJH

    Just recieved this too. I seriously doubt it’s an anti-war thing. The only text contained in the data section of the executeable is:

    kernel32.dll

    user32.dll

    GetModuleHandleA

    MessageBoxA

    Not much to go on, and I’m a Linux guy anyway. But, the two DLLs probably provide whatever functions this program needs; the next line is a function name, one that allows this code to call any other function in any DLL; and the last creates a message box onscreen. The fact that there isn’t any text to display elsewhere suggests the executable has been compressed or encrypted.

    My message came from a telus.net IP address, one that didn’t have the standard email ports open. Best guess is that the exe contains it’s own mail server, and gets email addresses from the infected computer.

    Looked up the thing via Google, and I’m right on. This worm was released in early January. Update your virus scanners, and resist the urge for revenge since the person sending it probably has no idea he’s been infected.

    HJH

  11. XRayed Systems

    Greetings! The source could be also MIT initiated but the q-script analyzed by code breaker 7.4 points to an Italian multinational called Veritas S.g.A.: ip-route 199.2.212.1.6//o.ivs.it srvr http://www.infolink.outbound.spikes.it. (blocked)2user/padset. email slips right through most firewalls/attachment vb-script/huver command/disseminates worm/port scan/hybernate characteristics/multi remote url command/system key replication/ (file replaces existing-look for date to id) Good Luck!

  12. Carla

    We’ve been getting the big@boss.com worm for about a week. I don’t know much about it but its emergence co-incided with receiving mulitiple copies of all the emails that have come in – is this what the worm does? And does anyone know what can be done about it? Btw, we are involved with the anti-war campaign…

  13. mhb

    LLevo recibiendo desde hace dos meses estos mensajes del remitente big.boss, no se exactamente el motivo de que me manden tan reiteradamente este virus, sabr

  14. Teresa

    I have received the big@boss.com virus about 5 times on one of several of my e-mail accounts. I set up an account to use for a Car Show to be held soon and the day after I set up the account I received the virus, I scanned it but didn’t download the attachment. Now I delete a message from big@boss.com in my bulk mail box about once a week. I am not an anti-war activist so I think that theory is out. My grandmother also received a message from big@boss.com. I don’t know who is doing it, why they are persistent in sending it over and over, why they sent it to me or what it can do. I thought maybe it had something to do with the email account being new.

  15. Shay

    I get sent a virus from “big@boss.com” a number of times everyday to all my email addresses, today the tally is at 7 and only half way thru the day!!! I am anti-war, am on many anti-war mailing lists……..

  16. Jim Trapp

    You are sending my a virus…Please stop it…I do not want any mail from big@boss.com, I never requested it & I will call the FBI if you do not STOP…

    Jim

  17. Lis

    I am signed up with the pledge site and received big@boss.com today. I don’t think it is anti war unless someone else has signed me up — I signed the pledge petition last week. Hmmmmm . . .

  18. Still Alive & apologizing

    Hi again,

    I’m sorry my last message was a bit rude, wasn’t it ?

    It’s because :

    #1: i was pissed

    #2 : I hadn’t read all of this page, because of reason #1, and because i can’t read english so fluently (i’m french).

    So :

    – Kaspersky AV blocked & destroyed the file;

    – here are the full headers of the message:

    From mail@xxx.net Sun Mar 02 15:51:58 2003

    Received: from [62.147.120.44] (helo=BT-MZWK09PYVLLF) by mx.xx.xxx.net with esmtp

    (Exim 3.33 #1) id 18pUoD-0001bt-00 for xxx@xxx.org; Sun, 02 Mar 2003 15:51:22 +0100

    From:

    To:

    Subject: Re: Document

    Date: Mon, 30 Dec 2002 5:11:15 +0100

    Importance: Normal

    X-Mailer: Microsoft Outlook Express 6.00.2600.0000

    X-MSMail-Priority: Normal

    X-Priority: 3 (Normal)

    MIME-Version: 1.0

    Content-Type: multipart/mixed; boundary=”CSmtpMsgPart123X456_000_000584EE”

    Message-Id:

    The attached file was named “Document003”.

    I didn’t note the virus’ name, sorry…

    Good luck..

  19. Nero

    I got this e-mail first time last weeks sunday. My e-mail provider uses F-Secure Anti-virus and it cleaned the mail, before I even got it.

    It contained Sample.pif file which was infected with ‘W95/Sobig.A@mm’ worm/virus whatever.

    Today I got three new e-mails from “boss”.

    1. Document003.pif and ‘W95/Sobig.A@mm’

    2. Untitled1.pif and ‘W95/Sobig.A@mm’

    3. Movie_0074.mpeg.pif and ‘W32/Sobig.A@mm’

    And I have no idea why I got these mails.

  20. Citizen Kane

    Actually, the the big@boss.com email virus is not against anti-war persons. I think it is for all the other spineless, pathetic, pansy ass bed-wetters and overall waste of humanity who are against the US and the President for going to war with Saddam.

    We would all be better off without the French government interference as well!!!

  21. Nellie

    I am pissed off by all these e-mail from boss. Is there anything that can be done to eleminate this garbage????????/

  22. n3tph4t

    This is the latest header info for anyone interested:

    Return-Path:

    Delivered-To: crack-whores.net-webmaster@crack-whores.net

    Received: (qmail 97815 invoked from network); 15 Mar 2003 15:40:42 -0000

    Received: from unknown (HELO manage.24online) (202.153.36.13)

    by stealth-it-solutions.co.uk with SMTP; 15 Mar 2003 15:40:42 -0000

    Received: from SYS4 ([172.16.28.14])

    by manage.24online (8.9.3/8.9.3) with ESMTP id VAA19252

    for ; Sat, 15 Mar 2003 21:11:02 +0530

    From: big@boss.com

    Message-Id:

    To:

    Subject: Re: Movies

    Date: Sat, 15 Mar 2003 23:55:15 +0530

    Importance: Normal

    X-Mailer: Microsoft Outlook Express 6.00.2600.0000

    X-MSMail-Priority: Normal

    X-Priority: 3 (Normal)

    MIME-Version: 1.0

    Content-Type: multipart/mixed;

    boundary=”CSmtpMsgPart123X456_000_000436B3″

  23. jason

    I jhave being getting this email for about a month using win xp find it resides in the system restore you can acecess thgie by showing all files

    right click on system volume information i find i usually delete everything but the .

    txt file

    I gather this info is for win xp restore points

    I am currently getting from 1-5 emails a day

    have changed email address given to know one and still it finds me

    running a firewall to monitor any unusal trafic I gather this is a back door virus.

    its a waste of time blocking the email as it changes.

    need to find the one thing in commen with all its emails to apply a rule

    any help greatly appreciated

  24. slim (girl )

    ok who ever they r well if they do not stop i will punch there head off , and they will neaver have knee caps againe ok !!!!! ( not to be mean but grrrrrrr!!!!1

    love always ,

    slim

  25. Aaron

    Win32.Sobig

    Alias:

    WORM_Sobig.A (Trend),

    W32.Sobig.A@mm (Symantec),

    W32/Sobig.Worm,

    W32/Sobig@MM (McAfee)

    Category: Win32

    Type: Worm

    Last Modified: 2/9/2003

    Wild:

    Destructiveness:

    Pervasiveness:

    CHARACTERISTICS

    Win32.Sobig is a worm which spreads via e-mail using its own SMTP engine, and through shared drives.

    It arrives in a message with one of the following subjects:

    Re: Here is that sample

    Re: Document

    Re: Sample

    Re: Movies

    The attachment name may be one of the following:

    Sample.pif

    Untitled1.pif

    Document003.pif

    Movie_0074.mpeg.pif

    The only message body observed at this time contains simply:

    Attached file:

    The worm also spoofs the ‘From’ address. E-mail sent by the worm appear to be from the following address:

    “big@boss.com”

    When run, the worm copies itself to the following file name:

    %windows%\winmgm32.exe

    It also creates the following registry values so this copy is run when Windows starts:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\WindowsMGM=”%windows%\winmgm32.exe”

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\WindowsMGM=”%windows%\winmgm32.exe”

    Note: These registry values are only set if the keys already exist. For example, the second value might not be created on Windows 98 systems because the key

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

    does not usually exist.

    The worm appears to search files with the following extensions for e-mail addresses to send to:

    txt

    eml

    html

    htm

    dbx

    wab

    It also attempts to spread to remote Windows shares by copying itself to one of the following locations:

    Documents and Settings\All Users\Start Menu\Programs\Startup

    Windows\All Users\Start Menu\Programs\StartUp

    The worm tries to download a file from an account on http://www.geocities.com. This file in turn contains another URL which the worm downloads and then executes. This file is saved with the name “dwn.dat” in the Windows directory. At the time of writing, the file downloaded was a variant of the Win32.Zasil trojan.

    Analysis by Hamish O’Dea

    MINIMUM SIGNATURE/ENGINE INFORMATION Product/Engine Minimum Signature/ Engine Information * Virus Removal Instructions

    eTrust EZ Antivirus 5.4/2363 Update your Antivirus software with the latest signature files and scan all affected machines with the cure option activated.

    eTrust InoculateIT 6.0

    eTrust Antivirus 6.0 23.59.16 Update your Antivirus software with the latest signature files and scan all affected machines with the cure option activated.

    InoculateIT 4.x 41.16 Update your Antivirus software with the latest signature files and scan all affected machines with the cure option activated.

    Vet 10.4 10.4/2363 Update your Antivirus software with the latest signature files and scan all affected machines.

    Vet 10.5 10.5/4353 Update your Antivirus software with the latest signature files and scan all affected machines.

  26. nikhil vasudeva

    I recieved bigboss mail on my account twice and some other accounts too. the file extension and the email id makes it evident that its a virus.. so i deleted it then and there. this is a standard way of staying away from viruses, delete mails from unknown people sending unknown files.

  27. angel

    this guy is a prick I have been getting emails for the last couple of weeks and it gets annoying. Hope he gets what he deserves the bastard!!!!!!!!

  28. duncan

    This email is a carrier of the Klez virus. Still doesn’t explain where it comes from and why some many people are getting it from this boss.com domain, but that’s why it’s not showing up on Norton and other sites. It’s not a virus itself, it’s the Klez virus coming from that domain.

  29. Michael

    The instance of this that I had tonight was right in time with the start of the US attack on Iraq and traced to Korea near the DMZ as its source.

    Not sure who is doing this but here is the file data and trace info in a graphic file.

    Click on my name link to go to the graphic file

  30. poobaroo

    Ok now we have verified that we are all getting these emails, lets focus on finding out who, and how to stop this mess.

  31. clamydia

    I was sent the “virus” to a web based account. I downloaded the attatchment, which did not appear to be an executable. It had no DOS extention at all, and when I right clicked on it, Windows didn’t know what to open it with. I tried to look at it in WordPad, but it was all gibberish. I don’t know if it screwed up or what, or maybe it worked and now I’m infected. The name of the attatched file in this case was “UNKOWN PARAMETER VALUE.” The Dos name was Unknow~1. Again, there was NO file extention. What gives?

  32. Gerd Trampler

    Hello,

    I`ve got a meage from you at 2003/03/24 11:44 which contained a *.pif-file.

    Please can you tell me, what there is going on?

    I cannot remember having a contact with you.

    Best wishes

    Gerd Trampler

    Germany

  33. Raul Ibanez

    A clean up tool for this virus is located at:

    http://securityresponse.symantec.com/avcenter/venc/data/w32.sobig.a@mm.removal.tool.html

    And by the way, in spite of the rampant paranoia on this bulletin board, it is just an email worm virus – no one is attacking anti-war protestors. This thing is incredibly wide spread and because it disguises who it came from like the Klez virus, it is difficult to track down. You received the virus from someone who has your email address in their address book. If you are continually getting it, try contacting those you correspond with and have them check for it.

    -Raul

  34. Dee

    i was getting then in one e mail account blocked him now boss is sending them to another e mail account so i blocked him there 3/25/03 so u know it hasnt stop

  35. Reno

    I can assure all of you that this whole big@boss thing has nothing to do with the war whatsoever! I run a large amount of services on the internet such as web hosting, web design, marketing, etc.. and I have been getting the big@boss email for almost a year now, as have a large amount of my friends and family. Internet spam is so wide spread now that I don’t like to have any email addresses available on any of my pages. I usually just setup a submit form. One tip I will add for all of you, is to try and keep your email address private! Do not have your email address available to the public. I personally don’t even use my real email on froums and/or sites such as this one. if someone requests your email address, if at all possible try and keep it in this format (you at yoursite.com). The reason for this, is when you actually have the you@yoursite.com, it picks up on the @ symbol and releases your email address on the site which makes it vulnerable to such programs as “email harvesters”. (which comb the internet page by page, saving and logging all email addresses that it happens to come by.) So do your best to protect yourselves, and for now all you can really do is delete ALL big@boss.com emails, or anything of the such. You may also want to bookmark this page for any future updates or new information on this virus.

    On my behalf, I would like to thank the website operators for making this forum available, I’m sure it will help out a lot of people! Great job guys! 🙂

    Regards,

    James

  36. melissa

    I received a big@boss.com email today. I don’t know why or how, all I do on the web is chat on yahoo. well I do also subscribe to coupon sites and have recently signed up for a couple of free samples but other than that, nothing. I receive junk mail in my yahoo mailbox often but what caught me was the subject line which read “Re: Here is that sample” Only by chance did I scan it with antivirus. I guess Lucky for me.

  37. matt

    RE: Big@Boss.com

    I have been recieving this infected email for about 2 months now, on and off, as my mail is scanned on my mail server before its downloaded to my pc so i havent really suffered but can sympathise with those that have – last time i searched for ‘big@boss.com’ with google it came up with nothing, but it seems this ‘virus’ is now expanding over the internet quickly, maybe a mail to everyone in your address books to search for the Winmgm32.exe in the WINDOWS directory may help slow this fecker down!!!!

    If its hiding in the System Restore (WINDOWS XP) folder then no anti-virus program will be able to remove it without disabling System Restore first. (Right click My Computer > System Restore > Turn Off System Restore [checkbox] – Dont forget to turn it back on !!!!!

    The ‘author’ should be strapped to the next MOAB

    Laterz PPL

  38. Unrepresented American

    big@boss.com virus was sent to me at the March26-28 2003 period only once and I would like to know from all the people here who received the virus why we may be the ones getting it because this is the 1st virus sent to me and it has come at a period of time when i have been doing more research then i have ever done in regards to gov. scheming. ALSO: a curious thing is that in the same yahoo bulk folder that the virus was in was a separate email without any message in the body with a return email address…i entered the email into google and 1 page came out, it was a text list of network companies and the email address i entered into google was listed as a company in Mexico…a virus email and a separate email related to network security in the same bulk folder? Are network security firms working with virus makers so they get more business? nah, not in this flawless “democracy.” I think they are working with each…yes it’s fuct, but let’s investigate this matter further!

  39. Dave

    Greetings, I have received the big@boss virus today on three of my yahoo email accounts. They are completely un-related and I pretty much keep them separate, so I was supprised to see all accounts affected by it.

    It cannot be any targeting to anti-war prostesters as I have made no mention of the war.

    Nice blog btw.

    David

  40. Jan

    I received bugbear virus on my two e-mail accounts recently, in an e-mail forwarded, supposedly, by a friend, immediately after having been sent an anti-war e-mail with web site links to a petition (which I didn’t do – i’ve signed plenty hard copy). She had sent me that one. One got stopped by my work virus checker.

    I’ve now received an e-mail from big@boss on my work e-mail, stopped by the virus checker.The only links this e-mail address has with outside is via my own private address – I think the anti-war e-mail opened a few doors for this virus.

  41. xphotos

    To: big@boss.com

    Subject: Re: Re: Here is that sample

    From: 😉

    Date: Sat, 18 Jan 2003 16:14:21 -0800

    Cc: 😉

    Hi!

    Phuk you and attached files with two extensions…

    Movie_0074.mpeg.pif

    Besides, we didn’t ask you any sample, so you know where you should have kept it: up yours, but use also that medicine against diarrhoeas.

    Yours Sincerely,

    😉

    *****

    As you see, those fag virus creators must be trated as childs, as they need we even change their diapperss and love to suck our d… hehehe

  42. Xphotos told ya

    To: big@boss.com

    Subject: Re: Re: Here is that sample

    From: 😉

    Date: Sat, 18 Jan 2003 16:14:21 -0800

    Cc: 😉

    Hi!

    Phuk you and attached files with two extensions…

    Movie_0074.mpeg.pif

    Besides, we didn’t ask you any sample, so you know where you should have kept it: up yours, but use also that medicine against diarrhoeas.

    Yours Sincerely,

    😉

    *****

    As you see, those fag virus creators must be trated as childs, as they need we even change their diapperss and love to suck our d… hehehe

  43. Shilpa

    Hi, I’m from India & I just got this shitty Sobig virus an hour back. I was fool enough to try & download it, luckily my AV sw (AVG 6.0) screwed up Big Boss’s plans.

    I was totally prepared to send some hate-mail back, when I found ur blog on Google. Thanx a lot,Michael, for providing this forum. I had a good laugh reading some of the comments..

    Im surprised this thing’s been rampant for so long now, & it’s still alive & kicking. Can’t the ISPs & Web Servers put an end to such viruses, once they come to know of it?

    Neways, hope the pathetic creep responsible 4 this roasts in hell (along with George W Bush. V hate u Bush 4 what u’re doing to the innocent Iraqi people…)

    Big boss, I hope u get infected with SARS virus !!LOL, Shilpa.

  44. Ruaidhri

    Just got an e-mail from big@boss.com – the subject was “Here is that sample” and the attchment was “Movie_0074.mpeg.pif” it only said that “it is attached” will i keep getting these e-mails? and what damage can be done to my computer?

    Thanks

  45. Buttocks

    Sounds like this W***er, is upsetting a lot of people. Needs sorting out, I get several Emails from big@boss.com, but luckily Norton stops it.

    As many comments have suggested an evil and torturous death to the sender.lets hope it happens soon….

  46. K.O.

    A message to the BABOON sending out the shit from the big@ address: With several law enforcement agencies now notified, plus after pissing off several BIG 6’8″ “Guidos” here, you might as well seek refuge with Bin Laden, because we’re going to get you!

  47. loq

    Hi everyone and thanks for the forum.. first hit on Google!

    I’m from France, and I started getting big@boss.com messages a month ago.

    I believe this attack is just like others (see Al-Jazeera website), has no purpose but to piss people off, and no precise target. I’m very careful with giving this email address, but probably not enough..

    When you get 3 boss.com messages a day, you learn that deleting them is probably the only thing to do until that piece of shit wanabee hacktivist is stopped.

    By the way, thanks for letting France off with that bullshit, I don’t think that forum is appropriate for political discussions.

    Good luck on tracking the virus down and keep your eyes open 😉

    Regards

  48. Lindz

    i received 2 emails from big@boss.com and the first 1 deleted everything in my inbox in my email account. why are the big internet providers not passing out warning emails to all their customers? the thing is, the person who made it was probably some computer boffin who does nothing better with their life and decided that he/she would invent some virus…for a “laugh”! pratt!

  49. BritSwedeGuy

    I’ve been getting mails from big@boss.com for ages now – but only in my most active Yahoo account, suggesting it’s possibly coming from someone else’s address book. Yahoo’s AV picks it up anyway (as long as you have the sense to let it) and now it’s redirected to the Bulk folder anyway.

    Interesting that the very few retarded comments here are from pro-war types – pity them and their shrivelled genitalia.

  50. deb

    Can’t get rid of big@boss.com. Norton quarantined it, I deleted it. Next thing I know its the first thing at the door waiting again to get it, when I reopen mail. It prevents anything behind it from coming in, so I can’t get any messages. Any ideas?

  51. Nick

    big@boss problem, how do i stop it? have norton and that quarantines it but it is extremly annoying

  52. SpecterK

    Send an email to everyone in your address book including the following:

    A) Inform everyone that you’re receiving these emails.

    B) Ask anyone who is also receiving the emails to mail everyone in their address book this same email

    C) Suggest that everyone, regardless of whether they suspect they’re infected or not, run the fix util by symantec

    D) Remind people that keeping an address book in an email account is a dumb thing to do… if you can’t remember em, put them in a .txt file in a non-shared dir on your comp, and put a space on either side of the @ symbol

    E) Fix your address book problem in accordance with D), if you have one =)

    With cooperation from all, you may be able to find out who’s infected and spreading it, and possibly stop the emails – or at least reduce the volume

    =)

    Happy H4CK!N

    PS. I think this would be the time to mass bomb all the neophyte POS sites that post lamer progs and allow lil kids with no brains to make these sorts of cookie-cutter virii.. lol

  53. rC

    …i think this person has its own

    serve or something

    its virus is also received in asian countries

    too.

    would it be possible that everyone forward

    its attachment back to him/her…and hopefully

    create a “send back” attack…although it may

    not create any damage..but it will make his/her

    inbox full….onlyif everyone do it at the same time

    like a “code red” attack…

  54. rC

    …i think this person has its own

    serve or something

    its virus is also received in asian countries

    too.

    would it be possible that everyone forward

    its attachment back to him/her…and hopefully

    create a “send back” attack…although it may

    not create any damage..but it will make his/her

    inbox full….onlyif everyone do it at the same time

    like a “code red” attack…

  55. pa

    This guy is seriously damaged!

    This just has to stop. Not only do I recieve letters from “big@boss.com” containing viruses. I’m actually getting e-mails from regular e-mail adresses. I’m a guy who works alot over the internet. And people mail me all the time about work. Nowadays… since I started to get this “big@boss” thingy, I also recieve letters from addresses I know.

    With the exact same message “big@boss” sends out.

    exactly the same, just as if “big@boss” sends a letter from their e-mail.

    I dont know how many jobs I’ve been missing cause of this guy. i’m sad-

  56. sanatan_mohanty

    –India—

    i received it two days back..

    its suspicious format showed its identity.. I instantly deleted but found my friends are now getting mails from me with the same “UNKNOWN_PARAMETER_VALUE” attachment.

    How can my comp be infected until i download and run it in my comp.. or might be on LAN any comp is infected and taking info from my comp..

    its hell

    Sam

  57. rworley

    an ass kickin is in order for big@boss.com

    hwo the hell can i find out who sent the fucking shitover the net>

    where and who is the shit heads?

    anyone knows let me know

Comments are closed.