TulipTools Internet Business Owners and Online Sellers Community

Full Version: New 'Sober' virus circulating
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Quote:There are at least three new variants of the Sober worm spreading across the Internet via e-mail messages. The viruses are activated once a user clicks on an infected attachment.

The new variants of Sober, a worm that first appeared in 2003, are capable of disabling antivirus programs...

...the attachments can be recognized by their names: Exceltab-packed_List.exe, Liste.zip and Reg-List-Dat_Packer2.exe., reg_text.zip Word-Text.zip, Word-Text_packedList.exe and Word-Text_packedList.zip.

full article: http://news.com.com/New+Sober+virus+circ...g=nefd.top
Quote: The pesky Sober worm is to blame for disrupting e-mail traffic between Comcast account holders and users of Microsoft-based e-mail, Redmond said on Friday.

A variant of Sober known as Win32/Sober.Z@mm is pummeling servers at Hotmail and MSN with "unusually high mail load," causing delays in e-mail delivery to Hotmail and MSN customers, said Brooke Richardson, MSN's lead product manager. Richardson also indicated that Internet service providers besides Comcast may be having problems directing e-mail to Hotmail and MSN servers.


full article: http://news.com.com/Sober+worm+stalls+MS...80987.html
More Sober Worm news:  the virus maker has reportedly programmed a new attack by the worm to occur on January 5th:

Quote:Security outfit iDefense is reporting that the next Sober worm attack will take place on 5 January - the 87th anniversary of the founding of the Nazi party.

The information has been gleaned from breaking encrypted code in the latest version of Sober which dominated the November anti-virus ratings. According to iDefense, "the November 22 variant is designed to download an unknown payload of code on January 5, 2006".

full article: http://www.theregister.co.uk/2005/12/08/sober_attack/

In a related development, anti-virus makers have reportedly cracked the code the Sober Worm uses to communicate with its author:

Quote:Anti-virus firms have cracked an algorithm that was being used by the Sober worm to 'communicate' with its author.

The latest variant of the Sober worm caused havoc in November by duping users into executing it by masking as an e-mails from the FBI and CIA. Anti-virus companies were aware that the worm somehow 'knew' how to update itself via the Web. The worm's author programmed this functionality in order to control infected machines and, if required, change their behaviour.

On Thursday, Finnish anti-virus firm F-Secure revealed that it had cracked the algorithm used by the worm and could now calculate the exact URLs the worm would check on a particular day.

full article: http://zdnet.com.au/news/security/soa/So...908,00.htm

related topic: E-mail Scammers Pose as FBI, CIA: try to trick users into installing Sober Worm http://community.tuliptools.com/index.ph...448.0.html
A reminder that the Sober Worm is programmed to attack again today. The attack is reportedly scheduled for Midnight GMT tonight (4 pm PST, 7 pm EST).

I wazsh trygin to read aobut the shober virsu, butt ia don't tingk i'll have to worry aoubt it. :hollandsmiley: Love7 :hkpumpkin:

Where's the freakin' dink thing????