New Sober Worm Surfaces

By Ed Oswald | Published January 31, 2005, 12:50 PM

Antivirus company McAfee has upgraded the W32/Sober.k@MM to a "medium-risk worm" after receiving more than 50 reports of the virus to its AVERT (Anti-virus and Vulnerability Emergency Response Team) team since Sunday evening.

According to McAfee, the virus is a "mass mailing threat that contains its own SMTP engine to construct outgoing messages, which are written in German or English. It harvests addresses from local files and then uses the harvested addresses to send itself. This produces a message with a spoofed 'From' address."

The worm arrives as a zip file attached to an e-mail and has many of the same functionalities as its W32/Sober.j@MM predecessor. The attachment that comes with the worm is named "EMAIL_TEXT.ZIP" or "TEXT.ZIP," and has the file "MAIL_TEXT-INFO.TXT," followed by many spaces, then the extension .PIF within the zip file itself.

McAfee is directing users to its Web site for more information and the cure for Sober.k. The company also advised customers to update their antivirus definition files as soon as possible to combat the new variant.

The new Sober worm follows new variants of the Bagle worm surfacing last week, which McAfee also lists as "medium risk."

Sober.k can be removed using the latest release of McAfee's AVERT Stinger application.

Comments

View comments by with a score of at least

don't get me wrong, I'm sure many many people were infected with sober varients at one time, I've seen the numbers. I just find it odd that NOT ONCE have I encountered ANY sober variants, and heck I do this stuff for a living. Is sober spreading in other countries and not in the US, or what?

Score: 0

|

Exchange Server 2010 goes live, will extend rights-managed e-mail to browsers

A new feature will give companies a way to prevent users from manipulating e-mail content they receive based on what the messages contain.

Google Chrome 4: Yes, it's fast, but is it usable?

As Betanews readers have responded to our stories about Chrome's JavaScript superiority...Does that mean we'd actually use this browser? Well...

Video: Netflix on PlayStation 3

Netflix has come to the PlayStation 3 via Blu-ray and BD-Live.

Early build of Moblin 2.1 improves connectivity, but not device support

The Linux Foundation's Atom-centric OS yesterday received a major overhaul with the project release of Moblin 2.1 for netbooks and nettops.

Microsoft's Top 3 advances in Exchange Server 2010

The latest round of changes launched today will impact how admins deliver services to e-mail recipients, and how much companies will pay along the way.

Qualcomm: $1.3 billion Samsung licensing deal unrelated to fair trade violations

Samsung has come to a 15-year licensing deal with Qualcomm over 3G and 4G wireless technology.

Firefox turns five: Thanks for giving us a choice

Carmi Levy | Wide Angle Zoom: No longer the phoenix rising from the ashes, Mozilla has carried on more than just Netscape's legacy.

Nokia's 'limited number' of recalled chargers exceeds 14 million

Today, the Finnish phone maker has begun a recall of mobile phone chargers that are a shock hazard.

Ubuntu 9.10 upgraders report frustration

For those Wine aficionados out there, beware of the remote possibility that your Linux system could be infected by Windows-seeking malware.

Supreme Court considers patentability of abstract methods today

Can software that executes a formula for a business process qualify for federal patents? An appeals court already said no, and inventors are making their case.

Thanks, iPhone: Google buys mobile advertiser AdMob for $750 million

AdMob came to thrive thanks to the iPhone's popularity, now Google has bought it.