Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

New VIRUS threat Sober.p (4% of emails contain .zip files-DO NOT OPEN!)
http://vil.nai.com/vil/content/v_133409.htm ^ | May 4 2005 | Self

Posted on 05/04/2005 5:16:08 PM PDT by Las Vegas Dave

Virus Name Risk Assessment W32/Sober.p@MM Corporate User : Low-Profiled Home User : Medium

Virus Information Discovery Date: 05/02/2005 Origin: Unknown Length: 53,727 bytes (zip) 53,554 bytes (executable) Type: Virus SubType: E-mail Minimum DAT: 4443 (03/09/2005) Updated DAT: 4482 (05/02/2005) Minimum Engine: 4.3.20 Description Added: 05/02/2005 Description Modified: 05/02/2005 3:59 PM (PT) Description Menu Virus Characteristics Symptoms Method Of Infection Removal Instructions Variants / Aliases Rate This page Print This Page Email This Page Legend

Virus Characteristics: -- Update 2nd May 13:00 PST -- Due to increased prevalence, this threat has had its risk assessment raised to MEDIUM for Home Users.

If you think that you may be infected with Sober.p, and are unsure how to check your system, you may download the Stinger tool to scan your system and remove the virus if present. This is not required for McAfee users as McAfee products are capable of detecting and removing the virus with the latest update. (see the removal instructions below for more information).

Note: Receiving an email alert stating that the virus came from your email address is not an indication that you are infected as the virus often forges the from address.

This threat is proactively detected with the 4443 DAT files, or newer, as W32/Sober.gen@MM.

This threat arrives in an email message with one of the following attachment names:

account_info.zip autoemail-text.zip LOL.zip Fifa_Info-Text.zip mail_info.zip okTicket-info.zip our_secret.zip _PassWort-Info.zip Inside the ZIP archive is a file named winzipped-text_data.txt .pif

Like many Sober variants, this variant uses several different email messages randomly, in either English or German depending on the version of Windows. One such German message states that the recipient has won tickets to the worldcup:

Subject : WM-Ticket-Auslosung Body: Herzlichen Glueckwunsch,

beim Run auf die begehrten Tickets für die 64 Spiele der Weltmeisterschaft 2006 in Deutschland sind Sie dabei.

Weitere Details ihrer Daten entnehmen Sie bitte dem Anhang.

Ihr "ok2006" Team St. Rainer Gellhaus

--- FIFA-Pressekontakt: --- Pressesprecher Jens Grittner und Gerd Graus --- FIFA Fussball-Weltmeisterschaft 2006 --- Organisationskomitee Deutschland --- Tel. 069 / 2006 - 2600 --- Jens.Grittner@ok2006.de --- Gerd.Graus@ok2006.de

An example of a randomly generated English message is as follows:

Subject: Your Password Body: Account and Password Information are attached!

Visit: http://www. {sender's domain}

*** AntiVirus: No Virus found *** "{recipient's domain} " Anti-Virus *** http://www. {recipient's domain}


TOPICS: Miscellaneous
KEYWORDS: exploit; getamac; internetexploiter; lookoutexpress; lowqualitycrap; microsoft; patch; securityflaw; trojan; virus; windows; worm
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-8081-96 next last
To: Ramius

You mean like the automatic update and patch system that's enabled by default on all Mac OS X systems? :-P


41 posted on 05/04/2005 5:52:03 PM PDT by Spktyr (Overwhelmingly superior firepower and the willingness to use it is the only proven peace solution.)
[ Post Reply | Private Reply | To 33 | View Replies]

Comment #42 Removed by Moderator

To: Blue Champagne
Me too. My ISP must use good anti-virus software (knock on wood) because I haven't received any yet.
43 posted on 05/04/2005 5:53:24 PM PDT by octobersky
[ Post Reply | Private Reply | To 10 | View Replies]

To: AFPhys

If you're running Linux, may I suggest clamav?


44 posted on 05/04/2005 5:54:48 PM PDT by Spktyr (Overwhelmingly superior firepower and the willingness to use it is the only proven peace solution.)
[ Post Reply | Private Reply | To 37 | View Replies]

To: Las Vegas Dave

I just had one email that had 12 of these in it alone, have had over a dozen emails each day for the last several with that virus in it. It gets past earthlink virus scan filter but norton catches it.


45 posted on 05/04/2005 6:00:58 PM PDT by RedBloodedAmerican
[ Post Reply | Private Reply | To 1 | View Replies]

To: Las Vegas Dave
When I saw the first one that said "Your email has been blocked," I had, very recently, sent out an email that I had copied to one other person. I thought it was about one of those. When I opened the email I saw that it had a www.hotmail.com link (my email server) and in the attachment was the .zip file. That is when I just deleted it, not opening anything.

In about 10 minutes my mail had a whole bunch of them, all from different addresses so I just dumped them all without looking. I figured something was going on.

I have really good spyware and a good virus program so I wasn't worried, and I didn't open them anyhow. But I guess we are going to see these for a while. What a pain. What is the point with these people?

46 posted on 05/04/2005 6:01:45 PM PDT by CitizenM ("An excuse is worse than an lie, because an excuse is a lie hidden." Pope John Paul, II)
[ Post Reply | Private Reply | To 35 | View Replies]

Comment #47 Removed by Moderator

To: Oystir
can anyone explain this to me... I received about 20 of these in the last 48 hours and I never, never get spam.

Most email viruses, once they infect a machine, will mail themselves to everyone on your mailing list. So, it could be that someone you know has gotten infected, and so is now the source of these emails to you.
48 posted on 05/04/2005 6:24:00 PM PDT by fr_freak
[ Post Reply | Private Reply | To 23 | View Replies]

To: PFKEY
Anyone who still gets infected by opening attatchments is just plain stupid.

I've gotten some that are actually executables in the body of my email message. I caught one and tried to dissect it, but lacking the proper tools, I finally nuked it. Just opening that email would have launched it. Despicable things. It was probably a keystroke logger that would report back to its master in an attempt to harvest financial userIDs and passwords.

49 posted on 05/04/2005 6:32:55 PM PDT by lafroste (gravity is not a force. See my profile to read my novel absolutely free (I know, beyond shameless))
[ Post Reply | Private Reply | To 13 | View Replies]

To: Spktyr

It needs patches? How come? :-)

Don't get me wrong... I'm a big Mac-Head from OS 5 on my old Mac SE. I still have a powerbook 520c around here somewhere... and I support lots of macs at work. I love 'em.

I just don't get all strung out on the OS wars. I like them all for various reasons, and there's nothing inherently wrong with any of them. It's how people use them that matters.


50 posted on 05/04/2005 6:38:12 PM PDT by Ramius
[ Post Reply | Private Reply | To 41 | View Replies]

To: lafroste
I've gotten some that are actually executables in the body of my email message. I caught one and tried to dissect it, but lacking the proper tools, I finally nuked it. Just opening that email would have launched it. Despicable things. It was probably a keystroke logger that would report back to its master in an attempt to harvest financial userIDs and passwords.

Will they also execute in the preview pane or does the email actually have to be opened in its own seperate window. (i.e. doble clicked versus single clicked)

51 posted on 05/04/2005 6:38:57 PM PDT by PFKEY
[ Post Reply | Private Reply | To 49 | View Replies]

To: Las Vegas Dave
What really pisses me off about this stuff is that the reaction of some companies is so brain-dead stupid. You can't even send zip files to some people these days, because their copier environment is fragile (life in the Windows world). This can make it difficult to send things through email that need to be sent.

This frustrates the hell out of me that it has come to this. I'd go on, but it would just degenerate into insults and profanity.:-)

52 posted on 05/04/2005 6:43:52 PM PDT by zeugma (Come to the Dark Side...... We have cookies!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Las Vegas Dave

I've been getting them for about 3 days Norton caught the first one and I've been deleting the rest its about 8 to 10 a day so far.


53 posted on 05/04/2005 6:46:02 PM PDT by Rightly Biased (Salvation is not a prayer and an experience its a life changing event <><)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ramius
Someday... the same worm will take 'em all down at once, and we can be there to lick the delicious tears of sadness. /cartman. :-)

I know a lot of windows bigots who are waiting for the same thing. ...and waiting... and waiting... and waiting...

54 posted on 05/04/2005 6:48:43 PM PDT by zeugma (Come to the Dark Side...... We have cookies!)
[ Post Reply | Private Reply | To 33 | View Replies]

To: Rickkimble
so, how hard is it to switch over to linux?

Depends upon what you use your computer for. Describe your requirements, and I can tell you if what you need is available with a standard distribution without much tweaking.

55 posted on 05/04/2005 6:51:29 PM PDT by zeugma (Come to the Dark Side...... We have cookies!)
[ Post Reply | Private Reply | To 47 | View Replies]

To: zeugma

Stay tuned... :-)

...and I'm not a Windows bigot.


56 posted on 05/04/2005 6:51:35 PM PDT by Ramius
[ Post Reply | Private Reply | To 54 | View Replies]

To: Rickkimble
Switching is as easy as downloading and installing from here. (Note: there are a number of linux distributions, this is just the one I happen to use.) I strongly recommend these sites to get you going.

There's a steep learning curve assosciated with gaining a thorough comprehension of the operating system (historically, Linux has been targeted more toward people who needed a powerful system more than a user-friendly one) but if you are planning on using email, wordprocessing, etc., you won't need to know any more than you need to know to run windows.

If you want to try out a linux variant without installing anything, you can run it on a live-cd and it will load itself into ram without ever affecting your system.

Personally, I started using Linux in 8th grade, and have been using Windows less and less until last year I got rid of it altogether. It just can't do what I can do on Linux. (And I'm also paranoid about people taking over my machine.)

57 posted on 05/04/2005 6:54:33 PM PDT by explodingspleen (http://mish-mash.info/)
[ Post Reply | Private Reply | To 47 | View Replies]

To: Las Vegas Dave
Ha...hasn't affected my computer at all :P


58 posted on 05/04/2005 7:03:21 PM PDT by reagan_fanatic (It takes all kinds of critters...to make Farmer Vincents fritters)
[ Post Reply | Private Reply | To 1 | View Replies]

To: HairOfTheDog

Your impression of Linux sounds like it is about eight years dated. Builds now pretty much autodetect everything.

Most Linux distributions are now so easy to install it is amazing. Pretty much just have to download or otherwise obtain them, hit "install" and "Presto" you have a dual-boot system with hardware autodetected. I love FEDORA and have not had to 'tweak' it at all. From there, you can choose the system you want to boot into, and discover Linux at your leisure. My daughter almost always chooses Linux nowadays, and I exclusively use it for internet activities.

I also use KNOPPIX oft-times ... it is run completely off the CD-ROM drive, and won't touch your hard drive at all until and unless you make it so. It is a great diagnostic tool.


59 posted on 05/04/2005 7:09:56 PM PDT by AFPhys ((.Praying for President Bush, our troops, their families, and all my American neighbors..))
[ Post Reply | Private Reply | To 39 | View Replies]

Comment #60 Removed by Moderator


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-8081-96 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson