New Sober variant spreading
IDG News Service - SAN FRANCISCO -- A new version of the Sober e-mail worm started spreading in Europe last week, according to antivirus software vendors, which have given the worm a midlevel threat rating.
By the end of the workday in Europe, the worm had spread to North America and was propagating there as well, said Marius van Oers, an Amsterdam-based antivirus research engineer at McAfee Inc.
The Sober variant is referred to as Sober.j by McAfee and as Sober.i and by F-Secure Corp. and Kaspersky Labs Ltd. This variant is the latest version of a worm that first appeared in October last year.
The new worm sends itself as an attachment to German and English e-mail messages. Infected messages have various subjects and body texts. The worm isn't activated until the recipient opens the attachment.
Once opened, a fake error message is displayed and the worm creates two files in the Windows directory. Like its predecessors, Sober.i spreads by skimming e-mail addresses from victims' computers, then mailing copies of itself to those addresses.
The two files make it harder to manually remove the worm from an infected system, Van Oers said. Both files are loaded in the system's memory, and when one is deleted the other will re-create it, he said. Antivirus software is able to remove the worm, he said.
In spreading, Sober.i adapts its message for German-speaking audiences, inserting a German-language version of its pitch message into e-mail addresses belonging to German domains, such as those ending in .de for Germany, .ch for Switzerland and .at for Austria, F-Secure of Helsinki said in an advisory.
"It appears that the virus originated in Germany," McAfee's Van Oers said.
Sober.i appears to do no damage to users' systems other than replicating itself. The worm does try to download software from a remote location, but that feature didn't work when tested by McAfee, Van Oers said. The worm doesn't install any keystroke loggers or back doors into the user's system.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Reducing the Cost and Complexity of Web Vulnerability Management
- Hackers and cybercriminals are constantly refining their attacks and targets; which means you need agile tools to stay ahead of them.
Download this... - Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will... All Malware and Vulnerabilities White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Malware and Vulnerabilities Webcasts