Media releases are provided as is by companies and have not been edited or checked for accuracy. Any queries should be directed to the company itself.

Sober Sings the Praises of Sobig

  • 29 October, 2003 12:01

<p>A new Internet worm lavishes praise on the author of Sobig while masquerading as anti-virus software</p>
<p>Kaspersky Labs, a leading expert in data security software development, warns about the start of a virus epidemic from the Sober Internet worm. Sober was first detected this past Saturday, but is now observed surging in activity in connection with the beginning of the working week.</p>
<p>Sober is a classic network worm that spreads via e-mail. Infected e-mail messages can have various body texts in English and in German; additionally the infected file attachment can have one of several file extensions (PIF, BAT, SCR, COM, EXE). All of this makes it significantly more difficult to identify from outside appearances.</p>
<p>An example of a message infected with the Sober:</p>
<p>Subject:
New Sobig-Worm variation (please read)</p>
<p>Message body text:
New Sobig variation in the net.
You must change any settings before the worm control your computer!
But, read the official statement from Norton Anti Virus!</p>
<p>Attachment name:
NAV.pif</p>
<p>If the infected attachment is mistakenly opened, the Sober worm is activated and proceeds to display a false error message:</p>
<p>File not complete!</p>
<p>Using different file names, Sober creates three copies of itself in the Windows system directory, and registers these copies in the system registry's auto-run key. Next, the worm launches its spreading routine in which Sober first searches victim computers for files that may contain e-mail addresses (such as HTML, WAB, EML, PST, etc. file types), and then clandestinely, under the guise of the computer owner, sends itself out to the e-mail addresses found.</p>
<p>The worm's body contains text strings in which its author expresses his admiration for the creator of another network worm, Sobig.</p>
<p>The defense against Sober has already been added to the Kaspersky Anti-Virus database. More detailed information about this malicious program can be found in the Kaspersky Virus Encyclopedia (http://www.viruslist.com/eng/viruslist.html?id=302666).</p>
<p>For further information on Kaspersky Labs and kaspersky products, contact Raelene Forbes sales@kaspersky.com.au</p>

Most Popular

Brand Post

Shining a light on creativity

MSI has long pushed the boundaries of invention with its ever-evolving range of laptops but it has now pulled off a world first with the new MSI Creative 17.

Most Popular Reviews

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Latest Articles

Resources

PCW Evaluation Team

Tom Pope

Dynabook Portégé X30L-G

Ultimately this laptop has achieved everything I would hope for in a laptop for work, while fitting that into a form factor and weight that is remarkable.

Tom Sellers

MSI P65

This smart laptop was enjoyable to use and great to work on – creating content was super simple.

Lolita Wang

MSI GT76

It really doesn’t get more “gaming laptop” than this.

Jack Jeffries

MSI GS75

As the Maserati or BMW of laptops, it would fit perfectly in the hands of a professional needing firepower under the hood, sophistication and class on the surface, and gaming prowess (sports mode if you will) in between.

Taylor Carr

MSI PS63

The MSI PS63 is an amazing laptop and I would definitely consider buying one in the future.

Christopher Low

Brother RJ-4230B

This small mobile printer is exactly what I need for invoicing and other jobs such as sending fellow tradesman details or step-by-step instructions that I can easily print off from my phone or the Web.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?