Advertisement
Promo

Security threats Toolkit

A sobering thought for the festive season

Greg Sandoval CNET News.com

Published: 16 Nov 2005 09:40 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

There are at least three new variants of the Sober worm spreading across the Internet via email messages. The viruses are activated once a user clicks on an infected attachment.

The new variants of Sober, a worm that first appeared in 2003, are capable of disabling antivirus programs, according to a report from F-Secure.

Antivirus company Kaspersky Lab said on its Web site that large numbers of infected emails have been intercepted. This confirms, according to the company, that the epidemic was caused by spamming. Kaspersky identified the variants as Sober.u, Sober.v, and Sober.w.

Internet security officials in Germany warned Monday of a possible Sober attack. In recent months, Sober has been used in that country to spread right-wing propaganda.

Last month, a variant of the Sober worm was spread as an attachment that claimed to be an old class photo sent by a schoolmate.

Sober can hijack a Windows-based computer and force it to send spam e-mails. The continuous e-mailing can lead to overloaded servers and reduced network performance.

Security firms cautioned computer users to be careful when opening attachments. Infected messages may have a random subject line or none at all, Kapersky said.

But the attachments can be recognized by their names: Exceltab-packed_List.exe, Liste.zip and Reg-List-Dat_Packer2.exe., reg_text.zip Word-Text.zip, Word-Text_packedList.exe and Word-Text_packedList.zip.

The virus creators appeared to taunt security experts with a message left in the code which reads: "Use your debuggers, it's fun."

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
76 out of 137 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters