New Sober Worm Surfaces

By Ed Oswald | Published January 31, 2005, 12:50 PM

Antivirus company McAfee has upgraded the W32/Sober.k@MM to a "medium-risk worm" after receiving more than 50 reports of the virus to its AVERT (Anti-virus and Vulnerability Emergency Response Team) team since Sunday evening.

According to McAfee, the virus is a "mass mailing threat that contains its own SMTP engine to construct outgoing messages, which are written in German or English. It harvests addresses from local files and then uses the harvested addresses to send itself. This produces a message with a spoofed 'From' address."

The worm arrives as a zip file attached to an e-mail and has many of the same functionalities as its W32/Sober.j@MM predecessor. The attachment that comes with the worm is named "EMAIL_TEXT.ZIP" or "TEXT.ZIP," and has the file "MAIL_TEXT-INFO.TXT," followed by many spaces, then the extension .PIF within the zip file itself.

McAfee is directing users to its Web site for more information and the cure for Sober.k. The company also advised customers to update their antivirus definition files as soon as possible to combat the new variant.

The new Sober worm follows new variants of the Bagle worm surfacing last week, which McAfee also lists as "medium risk."

Sober.k can be removed using the latest release of McAfee's AVERT Stinger application.

Comments

View comments by with a score of at least

don't get me wrong, I'm sure many many people were infected with sober varients at one time, I've seen the numbers. I just find it odd that NOT ONCE have I encountered ANY sober variants, and heck I do this stuff for a living. Is sober spreading in other countries and not in the US, or what?

Score: 0

|

A real beta process at work: Mozilla fires up Firefox 3.6 Beta 2

In the clearest sign yet that public input really does help the development process, a flurry of bug detections provoked Mozilla to release Beta 2 of the next Firefox.

Snow Leopard and Windows 7 still can't crack the netbook problem

Apple has killed Atom support in OS X 10.6.2 and Windows 7 Starter Edition is stripped of "basic" functionality.

Microsoft's Top 3 advances in Exchange Server 2010

The latest round of changes launched today will impact how admins deliver services to e-mail recipients, and how much companies will pay along the way.

Firefox turns five: Thanks for giving us a choice

Carmi Levy | Wide Angle Zoom: No longer the phoenix rising from the ashes, Mozilla has carried on more than just Netscape's legacy.

The Samsung Intrepid: A nice phone, if you can accept Windows Mobile

Samsung appears to have built solid enough hardware, but it's the software that seems uncomfortable and unintuitive.

Kindle for PC opens in beta, underwhelms

Amazon has opened the beta of Kindle for PC, a companion to the Kindle, but little else.

European ministers approve watered-down 'neutral net' language

The latest provision in the EU's telecoms regulatory framework would let businesses cancel individuals' Internet access, if they go to court first.

It's the US vs. the EU over Oracle+Sun and the meaning of 'open source'

Now that the EU is a virtual country, the US Justice Dept. is taking a stand in favor of its view -- and against the EC's -- that MySQL will survive under Oracle.

Qualcomm: $1.3 billion Samsung licensing deal unrelated to fair trade violations

Samsung has come to a 15-year licensing deal with Qualcomm over 3G and 4G wireless technology.

Nokia's 'limited number' of recalled chargers exceeds 14 million

Today, the Finnish phone maker has begun a recall of mobile phone chargers that are a shock hazard.

Ubuntu 9.10 upgraders report frustration

For those Wine aficionados out there, beware of the remote possibility that your Linux system could be infected by Windows-seeking malware.