Version: 2008
  • On GameSpot: So-called 'Halo killer' gets 23 to life

May 6, 2005 4:11 PM PDT

Sober worm makes a comeback

  • 10 comments
The Sober.P worm is still spreading fast and made up almost 5 percent of all e-mail traffic on Friday morning, according to a U.K. antivirus company.

Sophos said that the worm accounts for around 77 percent of all virus activity it is seeing. The company said the Sober variant is still spreading, even though large corporations appear to have patched the vulnerabilities that the virus uses to propagate.

"It's lingering around like a nasty smell and spreading in big numbers," said Graham Cluley, senior technology consultant at Sophos. "It's still at the same level in that it's 4.65 percent of all e-mail out there. We can't be sure how many people it's infecting, but we think most big business will be protected."

Worm alert
Sober.P prevention and cure
Learn more about the bilingual worm from CNET.com.

Sophos reported earlier this week that Sober.P appears to turn off Symantec's antivirus protection and the Microsoft Windows XP firewall, probably as a way of preparing computers to distribute spam and to spread itself wider.

"That's probably why it has become widespread so quickly," Cluley said. "(Virus writers) used spam technology to send it out. Now it's just perpetuating."

Sober.P--which security companies have variously tagged as Sober.N, Sober.O or Sober.S--travels as an attachment in e-mails written in English and German. One of the most widely reported e-mails contains an alluring message stating that the recipient has won free tickets to the 2006 World Cup in Germany, but many other types have also been spotted. Once opened, the virus sends itself to e-mail addresses harvested from the infected machine.

Dan Ilett of ZDNet UK reported from London.

See more CNET content tagged:
Sober worm, Sophos Plc., Graham Cluley, security company, worm

Add a Comment (Log in or register) (10 Comments)
  • prev
  • 1
  • next
Virus,Worms,Exploits, Complete Reporting
by May 8, 2005 8:20 AM PDT
The MAC and Linux community would appreciate it greatly if you would go that extra step in reporting these things to the world by including the phrase
"These are ONLY affecting Microsoft PC's" !!!!
"Linux and Mac PC's are not affected"

Thanks....
Reply to this comment
So true.
by aabcdefghij987654321 May 8, 2005 8:49 AM PDT
This is NOT an email virus. This is a Windows/Outlook virus. The media people need to harp on this LOUDLY. Microsoft's feet need to be held to the fire everytime this occurs or things won't change.
Give it a rest
by catchall May 8, 2005 9:06 AM PDT
What the press needs to SHOUT is that with an up to date anti-virus program, even Windows PC's are no longer affected. This could have been squashed in a day. Then they need to point people to free or low cost antivirus ( http://www.grisoft.com )(hint hint wink wink) .
Lets face facts. If the affected users switched to the Mac, virus writers would target the Mac, and easily score. A fool who can't be bothered and is willing to double click anything comming into the inbox on a PC is just as easy a target on anything else.
View reply
As I sat there
by May 8, 2005 10:29 AM PDT
As I sat there, Symantec's alert pop-up window appeared, alerting me to a fast-spreading problem. I installed the fix & kept on working, using Outlook & Outlook Express.

BFD - there's a fallacy circulating, that if someone is using M$ products, that probably ARE porous, they have security issues. All it takes, is properly security software & hardware & the right settings (no automatic downloads & no automatic running) and things are Hunky Dory.

Sure, M$ have some buggy code - but RULE # 1 - ALL SOFTWARE HAS BUGS. Apple just released a bunch of fixes - apparently not security related, but bugs none the less. There are also issues with Tiger, where it doesn't interact correctly with existing software & where the vendors are having to fix their own software, to deal with Tiger.

So, providing people don't rely on security software that comes with an OS & install & set it up correctly, it IS possible to use buggy applications, like Outlook.
View all 2 replies
(10 Comments)
  • prev
  • 1
  • next

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Dow Jones Industrials (0.17%) 17.46 10,023.42
S&P 500 (0.25%) 2.67 1,069.30
NASDAQ (0.34%) 7.12 2,112.44
CNET TECH (0.20%) 3.03 1,538.38
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right