PDA

Click to See Complete Forum and Search --> : Sober worm to cause a few hangovers


SwordFish_13
November 19th, 2004, 06:22 PM
Hi,

The Worm is back form it's sleep and about to cause a few hangovers ....................Labelled as either variant 'I' or 'J' the worm has been spreading rapidly since first thing this morning.


The newest variant in the Sober family of Windows viruses resurrects itself if some of the parts it leaves on infected machines are not deleted.

The virus also tries to trick people into opening infected attachments by claiming that the message has been passed as clean by anti-virus scanners.

POPULAR SOBER-I SUBJECT LINES
Details
Registration Confirmation
Your mail password
invalid mail
Mail delivery_failed
Re: Delivery_failure_notice
Re: illegal signs in your mail
Your Password

Source (http://news.bbc.co.uk/2/hi/technology/4026541.stm)


Threat Advisory: McAfee AVERT Raises Risk Assessment to Medium on New W32/Sober.j@MM Virus (http://biz.yahoo.com/prnews/041119/sff027_1.html)

Virus Profile: W32/Sober.j@MM (http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=130130)

--Good Luck--

moonstar550
May 19th, 2005, 08:54 PM
I was looking for info on this virus, my Isp just warned me about it, they are having problems with it. Thanks

halv
May 19th, 2005, 09:39 PM
Your ISP is having problesm with this ? it is over 5 months old. You need to switch ISPs now if they have insecure machines that are being hit by this old virus.

BTW... if a post has a flashing date by the poster's name, then the thread is considered old.

Welcome to AO!

~Halv

nihil
May 19th, 2005, 09:58 PM
Hi halv

It looks like a new variant:

http://news.com.com/Sober+worm+makes+a+comeback/2100-7349_3-5698411.html
:)

Und3ertak3r
May 19th, 2005, 11:59 PM
AKA - Sober.O (symantec)

details from: http://securityresponse.symantec.com/avcenter/venc/data/w32.sober.o@mm.html

one of several info pages you can find helpful when looking for virus information: http://securityresponse.symantec.com/

Sober.Q (Sophos)

Details from: http://www.sophos.com/virusinfo/analyses/trojsoberq.html


Cheers