moxnix
November 21st, 2004, 11:58 PM
I got this in an email from a-squared today:Warning! Worm.Win32.Sober.I!
The latest version of the Sober worm is spreading fast. As with it's predecessors, Sober.I spreads by email attachments. The email text suggests that it is an error message from the mailserver and the undelivery report is attached.
Current email clients like Outlook or Outlook Express are able to block harmful file extensions like EXE, COM or SCR, but Sober.I sometimes comes packed in a ZIP file to bypass outlook security. The ZIP file itself is not harmful, but the content inside (an executable file with variable file name) contains the worm and must not be opened!
A more detailed description of the worm can be found at the aČ Malware Database:
http://www.emsisoft.com/en/malware/?Worm.Win32.Sober.I
Sober.I can be detected and removed with aČ Free and aČ Personal with the latest signature updates. The latest versionaČ Personal background guard will block the worm if it is started. Please run the aČ Online-Update immediately and ensure that the new automatic update feature in aČ Personal is enabled.v
FYI
The latest version of the Sober worm is spreading fast. As with it's predecessors, Sober.I spreads by email attachments. The email text suggests that it is an error message from the mailserver and the undelivery report is attached.
Current email clients like Outlook or Outlook Express are able to block harmful file extensions like EXE, COM or SCR, but Sober.I sometimes comes packed in a ZIP file to bypass outlook security. The ZIP file itself is not harmful, but the content inside (an executable file with variable file name) contains the worm and must not be opened!
A more detailed description of the worm can be found at the aČ Malware Database:
http://www.emsisoft.com/en/malware/?Worm.Win32.Sober.I
Sober.I can be detected and removed with aČ Free and aČ Personal with the latest signature updates. The latest versionaČ Personal background guard will block the worm if it is started. Please run the aČ Online-Update immediately and ensure that the new automatic update feature in aČ Personal is enabled.v
FYI