What you are probably seeing is the following:
W32.Sobig.F@mm is a mass-mailing, network-aware worm that sends itself to all the email addresses that it finds in the files with the following extensions:
ââ¬Â¢ .dbx
ââ¬Â¢ .eml
ââ¬Â¢ .hlp
ââ¬Â¢ .htm
ââ¬Â¢ .html
ââ¬Â¢ .mht
ââ¬Â¢ .wab
ââ¬Â¢ .txt
Email Routine Details
The email message has the following characteristics:
From:
[email protected]
Subject:
ââ¬Â¢ Re: Details
ââ¬Â¢ Re: Approved
ââ¬Â¢ Re: Re: My details
ââ¬Â¢ Re: Thank you!
ââ¬Â¢ Re: That movie
ââ¬Â¢ Re: Wicked screensaver
ââ¬Â¢ Re: Your application
ââ¬Â¢ Thank you!
ââ¬Â¢ Your details
Body:
ââ¬Â¢ See the attached file for details
ââ¬Â¢ Please see the attached file for details.
Attachment:
ââ¬Â¢ application.zip (contains application.pif)
ââ¬Â¢ details.zip (contains details.pif)
ââ¬Â¢ document_9446.zip (contains document_9446.pif)
ââ¬Â¢ document_all.zip (contains document_all.pif)
ââ¬Â¢ movie0045.zip (contains movie0045.pif)
ââ¬Â¢ thank_you.zip (contains thank_you.pif)
ââ¬Â¢ your_details.zip (contains your_details.pif)
ââ¬Â¢ your_document.zip (contains your_document.pif)
ââ¬Â¢ wicked_scr.zip (contains wicked_scr.scr)
NOTE: The worm deactivates on September 10, 2003. The last day on which the worm will spread is September 9, 2003.