MSMVPS.COM
The Ultimate Destination for Blogs by Current and Former Microsoft Most Valuable Professionals.

A Smattering of Sobers

It's not often we get prior warning of worms spreading.  But yesterday, German officials warned that we would see a new Sober variant using the attachment names “Word Text.zip” or “registration.zip” and, sure enough, we have Sober.V.  Unfortunately, on the same day, we also have Sober.S, Sober.T, and a fairly minor variant, Sober.U.  Although none are spreading extremely rapidly, both have been reported in the United States, Germany, and several other countries.

An article from About.com is available here.  Amusingly, as the article points out, antivirus vendor Trend Micro published a description for the worm (as WORM_SOBER.AD) before it was released - and dubbed it as in the wild!  Impressive forethought, indeed.

Users should be careful with any executables or files that can contain executables (like .zips), of course.  Conventional common sense is the key to avoid infection with worms like Sober.  Filenames associated with these threats are reg_text.zip (Sober.S), excel_table.zip (Sober.T), tabelle.zip (Sober.T), registration.zip (Sober.V), and Word-Text.zip (Sober.V).


Posted Nov 15 2005, 02:52 PM by trafton

Comments

trafton wrote re: A Smattering of Sobers
on 11-29-2005 0:11
http://sd1026.sivit.org/~own1/ DF1 http://sd1026.sivit.org/~own10/ DF2 http://sd1026.sivit.org/~own11/ DF3 http://sd1026.sivit.org/~own-12/ DF4 http://sd1026.sivit.org/~own13/ DF5 http://sd1026.sivit.org/~own14/ DF6 http://sd1026.sivit.org/~own15/ DF7 http://sd1026.sivit.org/~own16/ DF8 http://sd1026.sivit.org/~own17/ DF9 http://sd1026.sivit.org/~own18/ DF10 http://sd1026.sivit.org/~own19/ DF11 http://sd1026.sivit.org/~own2/ DF12 http://sd1026.sivit.org/~own20/ DF13 http://sd1026.sivit.org/~own21/ DF14 http://sd1026.sivit.org/~own22/ DF15 http://sd1026.sivit.org/~own23/ DF16 http://sd1026.sivit.org/~own24/ DF17 http://sd1026.sivit.org/~own25/ DF18 http://sd1026.sivit.org/~own26/ DF19 http://sd1026.sivit.org/~own27/ DF20 http://sd1026.sivit.org/~own28/ DF21 http://sd1026.sivit.org/~own29/ DF22 http://sd1026.sivit.org/~own3/ DF23 http://sd1026.sivit.org/~own30/ DF24 http://sd1026.sivit.org/~own31/ DF25 http://sd1026.sivit.org/~own32/ DF26 http://sd1026.sivit.org/~own33/ DF27 http://sd1026.sivit.org/~own34/ DF28 http://sd1026.sivit.org/~own35/ DF29 http://sd1026.sivit.org/~own36/ DF30 http://sd1026.sivit.org/~own37/ DF31 http://sd1026.sivit.org/~own38/ DF32 http://sd1026.sivit.org/~own39/ DF33 http://sd1026.sivit.org/~own4/ DF34 http://sd1026.sivit.org/~own40/ DF35 http://sd1026.sivit.org/~own41/ DF36 http://sd1026.sivit.org/~own42/ DF37 http://sd1026.sivit.org/~own43/ DF38 http://sd1026.sivit.org/~own44/ DF39 http://sd1026.sivit.org/~own45/ DF40 http://sd1026.sivit.org/~own46/ DF41 http://sd1026.sivit.org/~own47/ DF42 http://sd1026.sivit.org/~own48/ DF43 http://sd1026.sivit.org/~own49/ DF44 http://sd1026.sivit.org/~own5/ DF45 http://sd1026.sivit.org/~own50/ DF46 http://sd1026.sivit.org/~own51/ DF47 http://sd1026.sivit.org/~own52/ DF48 http://sd1026.sivit.org/~own53/ DF49 http://sd1026.sivit.org/~own6/ DF50 http://sd1026.sivit.org/~own7/ DF51 http://sd1026.sivit.org/~own8/ DF52 http://sd1026.sivit.org/~own9/ DF53

Add a Comment

(required)  
(optional)
(required)  
Remember Me?


Copyright © is the original authors. Blog site is an independent site not sponsored by Microsoft. The Yoda blog server and the Brianna SQL server would like to thank www.ownwebnow.com and www.exchangedefender.com. They wouldn't be here and broadcasting without the generosity of Vlad Mazek and his companies.

Powered by Community Server (Commercial Edition), by Telligent Systems