New Sober Worm Surfaces

By Ed Oswald | Published January 31, 2005, 12:50 PM

Antivirus company McAfee has upgraded the W32/Sober.k@MM to a "medium-risk worm" after receiving more than 50 reports of the virus to its AVERT (Anti-virus and Vulnerability Emergency Response Team) team since Sunday evening.

According to McAfee, the virus is a "mass mailing threat that contains its own SMTP engine to construct outgoing messages, which are written in German or English. It harvests addresses from local files and then uses the harvested addresses to send itself. This produces a message with a spoofed 'From' address."

The worm arrives as a zip file attached to an e-mail and has many of the same functionalities as its W32/Sober.j@MM predecessor. The attachment that comes with the worm is named "EMAIL_TEXT.ZIP" or "TEXT.ZIP," and has the file "MAIL_TEXT-INFO.TXT," followed by many spaces, then the extension .PIF within the zip file itself.

McAfee is directing users to its Web site for more information and the cure for Sober.k. The company also advised customers to update their antivirus definition files as soon as possible to combat the new variant.

The new Sober worm follows new variants of the Bagle worm surfacing last week, which McAfee also lists as "medium risk."

Sober.k can be removed using the latest release of McAfee's AVERT Stinger application.

Comments

View comments by with a score of at least

don't get me wrong, I'm sure many many people were infected with sober varients at one time, I've seen the numbers. I just find it odd that NOT ONCE have I encountered ANY sober variants, and heck I do this stuff for a living. Is sober spreading in other countries and not in the US, or what?

Score: 0

|

Latest Firefox 3.6 beta fixes 133 bugs, promises faster page load times

A once-sluggish beta testing process has kicked into overdrive, with astonishing success at finding serious bugs. Will Mozilla be able to fix all the others in time?

Apple invokes DMCA, claims Psystar is 'trafficking in circumvention devices'

In trying to close the book on possibly the last attempt at a Mac clone, Apple cites from its own landmark case...but may actually be misinterpreting it.

The fallacy of Facebook privacy

Carmi Levy | Wide Angle Zoom: If an insurance company learns something interesting about its client through the Internet, is that snooping?

Microsoft 'worked with Apple' for Silverlight on iPhone, says Goldfarb

By not making such a big deal out of trying to stream video to the iPhone, Microsoft got a big deal out of it, revealed the Silverlight product manager.

Confirmed: Office 2010 to ship in June

Two weeks after Microsoft had been expected to draw a clearer roadmap for its principal applications suite, it's finally ready to commit to the end of H1.

New EU antitrust commissioner will oversee Microsoft, Oracle+Sun, Intel issues

As one of Europe's most prominent politicians shifts positions in January, her replacement remains a question mark over technology's biggest issues.

Without its own 'iTablet' yet, is Apple missing the boat?

Steve Jobs is on record as dissing "single-purpose" devices like e-readers. But given their recent popularity, was that a mistake?

Not-so-mobile battery life: Time to force the issue

Carmi Levy | Wide Angle Zoom: If power efficiency is important when you buy a car or even a motorcycle, why shouldn't it matter for a smartphone?

Clicker.com cuts through the Web video chaos

In a world where homemade video and Hollywood movies travel the same pipeline, it's good to have a real search engine to cut through the clutter.

Microsoft's Ray Ozzie: 'Nobody's going to be 100% open'

The mobile apps ecosystems of the world may converge over time, led by apps being ported over across platforms, according to the Chief Software Architect.

A case study in improving software: What Office 2010 can learn from Notion 3

A music composition product gambles with a complete overhaul, in an effort to make headway against two well-known competitors in a tough market.