Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Worm.Win32.Sober.L Alert!(Save your Computer Data)
Emmissoft | Wed. March 9 2005 | a-squared

Posted on 03/09/2005 6:19:11 AM PST by OPS4

Important information about current security risks.

Worm.Win32.Sober.L Alert!

A new variant of the Sober worm is spreading fast. As it's predecessors, Sober.L spreads as an email attachment in emails which are sent to all email addresses found on the victim's harddisk. Even if the executable file is packed in a .ZIP file, many users open the file and activate the worm this way. For novice users it's hard to see that it is a worm generated email because the email subject is "your password + accountnumber !". The email body text is the following:

hi,

i've got an admin mail with a Password and Account info! but the mail recipient are you! it's probably an esmtp error, i think. i've copied the full mail text in the Windows text-editor & zipped. ok, cya...

More details about Sober.L can be found at the a-squared malware database: http://www.emsisoft.com/en/malware/?Worm.Win32.Sober.L Ops4 God Bless America!


TOPICS: Business/Economy; News/Current Events; Technical
KEYWORDS: computervirusalert; exploit; getamac; internetexploiter; lookoutexpress; lowqualitycrap; patch; securityflaw; trojan; virus; windows; worm
Navigation: use the links below to view more comments.
first 1-2021-35 next last
OPs4 I hope you pass this on and help others save data. Ops4 God BLess America!
1 posted on 03/09/2005 6:19:12 AM PST by OPS4
[ Post Reply | Private Reply | View Replies]

To: OPS4

More details about Sober.L can be found at the a-squared malware database:
http://www.emsisoft.com/en/malware/?Worm.Win32.Sober.L

I am trying to give yhou an active link.
OPS4 it usually does. Maybe someone else can post active if this does not work.


2 posted on 03/09/2005 6:22:04 AM PST by OPS4 (worth repeating)
[ Post Reply | Private Reply | To 1 | View Replies]

To: OPS4

More details about Sober.L can be found at the a-squared malware database:
http://www.emsisoft.com/en/malware/?Worm.Win32.Sober.L

I am trying to give yhou an active link.
OPS4 it usually does. Maybe someone else can post active if this does not work.


3 posted on 03/09/2005 6:22:10 AM PST by OPS4 (worth repeating)
[ Post Reply | Private Reply | To 1 | View Replies]

To: OPS4

More details about Sober.L can be found at the a-squared malware database:
http://www.emsisoft.com/en/malware/?Worm.Win32.Sober.L

I am trying to give yhou an active link.
OPS4 it usually does. Maybe someone else can post active if this does not work.


4 posted on 03/09/2005 6:22:14 AM PST by OPS4 (worth repeating)
[ Post Reply | Private Reply | To 1 | View Replies]

To: OPS4
OPS4 (worth repeating)

We get the idea already.

5 posted on 03/09/2005 6:24:04 AM PST by martin_fierro (< |:)~)
[ Post Reply | Private Reply | To 4 | View Replies]

To: martin_fierro

Sorry my computer locked up and it appeared I was not posting.Ops4


6 posted on 03/09/2005 6:25:09 AM PST by OPS4 (worth repeating)
[ Post Reply | Private Reply | To 5 | View Replies]

To: martin_fierro

Maybe this virus hits the POST button multiple times.


7 posted on 03/09/2005 6:29:46 AM PST by Izzy Dunne (Hello, I'm a TAGLINE virus. Please help me spread by copying me into YOUR tag line.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Izzy Dunne

Maybe you dont appreciate people trying to prevent virus and malware problems for fellow freepers.
Ops4 God Bless America!


8 posted on 03/09/2005 6:31:30 AM PST by OPS4 (worth repeating)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Izzy Dunne; OPS4
Maybe this virus hits the POST button multiple times.

And locks up your computer?

9 posted on 03/09/2005 6:32:31 AM PST by FreePaul
[ Post Reply | Private Reply | To 7 | View Replies]

To: FreePaul

There's a good removal tool (from Symantec) here

http://www.sarc.com/avcenter/venc/data/w32.sober.removal.tool.html


10 posted on 03/09/2005 6:36:30 AM PST by Conservative_since_63 ( -- Things ain't like they used to be... And they never were.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: OPS4

Nobody needs to directly load emails onto their computer. You may easily sidestep email viruses, Trojans and malware hiding in photos. Just use web mail. Pick up all your emails from your ISP directly. Most ISP's run better anti-virus programs than you can purchase anyway. Also, I use PC-Cillin which automatically notifies me of the need to download updates. Please take care out there. The web world is dangerous.


11 posted on 03/09/2005 6:36:59 AM PST by ex-Texan (Mathew 7:1 through 6)
[ Post Reply | Private Reply | To 1 | View Replies]

To: OPS4
Never ever open an email attachment from someone you don't know. 'Nuff said.

(Denny Crane: "Sometimes you can only look for answers from God and failing that... and Fox News".)
12 posted on 03/09/2005 6:40:16 AM PST by goldstategop (In Memory Of A Dearly Beloved Friend Who Lives On In My Heart Forever)
[ Post Reply | Private Reply | To 1 | View Replies]

To: OPS4

Are you logged in?


13 posted on 03/09/2005 6:40:20 AM PST by Arkie2
[ Post Reply | Private Reply | To 6 | View Replies]

To: ex-Texan

Yep, Ive never had a problem with viruses myself for exactly the reasons you state.


14 posted on 03/09/2005 6:40:27 AM PST by cripplecreek (I'm apathetic but really don't care.)
[ Post Reply | Private Reply | To 11 | View Replies]

To: goldstategop
Never ever open an email attachment from someone you don't know. 'Nuff said

Modern viruses fake the "FROM" line in your mail client, you may have to look at the headers to determine the actual sender.

15 posted on 03/09/2005 6:42:15 AM PST by ko_kyi
[ Post Reply | Private Reply | To 12 | View Replies]

To: goldstategop
Never ever open an email attachment from someone you don't know. 'Nuff said.

...or link. Apparent webpage links in emails can also actually mangle your system registry and do other nasty things.

16 posted on 03/09/2005 6:44:22 AM PST by Ichneumon
[ Post Reply | Private Reply | To 12 | View Replies]

To: goldstategop
...Sober.L spreads as an email attachment in emails which are sent to all email addresses found on the victim's harddisk.

Opening e-mails from only those you know is no protection. As with many of these plagues an e-mail "from a friend" can bring the problem to you.

17 posted on 03/09/2005 6:47:47 AM PST by FreePaul
[ Post Reply | Private Reply | To 12 | View Replies]

To: OPS4; Ramius; Corin Stormhands; ecurbh; g'nad; RMDupree
A new variant of the Sober worm is spreading fast.

Sounds like if I just stay drunk, I'll be OK.

18 posted on 03/09/2005 6:50:21 AM PST by HairOfTheDog (It is no bad thing to celebrate a simple life!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: goldstategop
Never ever open an email attachment from someone you don't know. 'Nuff said.

By their very nature, viruses may very well come from someone you know.

19 posted on 03/09/2005 6:51:16 AM PST by HairOfTheDog (It is no bad thing to celebrate a simple life!)
[ Post Reply | Private Reply | To 12 | View Replies]

To: HairOfTheDog; Ramius; ecurbh; g'nad; RMDupree
Sounds like if I just stay drunk, I'll be OK.

I think it's our duty to protect the Internet.

~sip~

20 posted on 03/09/2005 6:53:10 AM PST by Corin Stormhands (One Iraqi purple finger took more courage than John Kerry's three purple hearts.)
[ Post Reply | Private Reply | To 18 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-35 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson