Advertisement
Promo

Security threats Toolkit

Sober worm still swamping email systems

Dan Ilet ZDNet.co.uk

Published: 06 May 2005 13:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Sober.P worm is still spreading fast and now makes up 4.65 percent of all emails, according to the latest results from a UK antivirus company on Friday morning.

Sophos said that the worm currently accounts for around 77 percent of all virus activity the company is seeing and is still spreading even though big businesses appear to have patched the vulnerabilities the virus exploits to propagate.

"It's lingering around like a nasty smell and spreading in big numbers," said Graham Cluley, senior technology consultant for Sophos. "It's still at the same level, in that it's 4.65 percent of all email out there. We can't be sure how many people it's infecting, but we think most big business will be protected."

Sophos reported earlier this week that Sober.P appears to turn off Symantec's antivirus protection and the Windows XP firewall, probably as a way of preparing computers to distribute spam and to spread itself wider. "That's probably why it has become widespread so quickly," Cluley said. "[Virus writers] used spam technology to send it out. Now it's just perpetuating."

Sober.P — which security companies have variously tagged as Sober.N, Sober.O or Sober.S — travels as an attachment in emails written in English and German. One of the most widely reported emails contains an alluring message stating that the recipient has won free tickets to the 2006 World Cup in Germany, but many other types have also been spotted. Once opened, the virus sends itself to email addresses harvested from the infected machine.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
83 out of 146 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters