Skip to main content

New version of Sober spreading actively

January 6, 2006

Updated worm spreading in Europe

Kaspersky Lab, a leading developer of secure content management solutions that protect against viruses, Trojans, worms, spyware, hacker attacks and spam, has detected a new version of Email-Worm.Win32.Sober. [insert name] [which is currently causing an epidemic in Western Europe.]

This latest version of Sober was detected on [insert date]. It downloads itself to computers previously infected by Sober.y, and then sends itself to email addresses harvested from the victim machine. It spreads as an [attachment] to infected messages. The attachment contains [the body of the worm] which is approximately [X KB] in size.

[Details of infected messages - languages, message header, message body etc.]

The worm is activated when the user clicks on the attachment. The worm causes a fake error message to be displayed ('CRC not complete') and then copies itself to the system directory, naming the copies as if they are system services. It also creates copies of itself in other files, and registers these files in the system registry. It creates a system registry entry ensuring that the worm will be launched each time Windows is rebooted on the victim machine.

Sober then scans the victim machine's address books and other files, and sends itself to email addresses which it harvests from these files.

An urgent antivirus database update containing detection for Sober has already been released. More details about the worm can be found in the Kaspersky Virus Encyclopaedia. [add appropriate link]

New version of Sober spreading actively

Updated worm spreading in Europe
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. With over a billion devices protected to date from emerging cyberthreats and targeted attacks, Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes leading endpoint protection, specialized security products and services, as well as Cyber Immune solutions to fight sophisticated and evolving digital threats. We help over 200,000 corporate clients protect what matters most to them. Learn more at www.kaspersky.com.

Related Articles Press Releases