Welcome to p2pnet.net - The original daily p2p and digital news site. Always First!
REGISTER | LOGIN
Cool Stuff
MPAA News
Games / Consoles
News
Music
Movies
Reviews
Open Source
Mobiles
Advertising
Products
P2P
Off Topic
Freedom
Politics
Interviews
Security
DRM
Links
Kids and Kartels
Scroogle Search: 
Search
 
Web p2pnet   
Search: 
Search
Torrent Site Tracker
    Sponsored by
Frostwire
 
p2pnet
 


mp3rocket
 
Add real-time p2pnet headlines to YOUR site ! Click here to download our newsfeed code

New email worm on the loose

p2pnet.net Virus News:- There’s a new worm in town.

Sober.1.

It’s a classic email worm except for its in-built ability to download other files from remote servers, declares the Kaspersky Virus Lab, saying it’s "receiving numerous notifications about the worm from Western Europe".

In most respects, Sober.i behaves like a typical email worm, says the company.

It’s activated only if the infected attachment is oepned, but if that happens, Sober displays a fake error message, namely:

WinZip Self-Extractor. WinZip_Data_Module is missing ~Error.

Then Sobewr.1 creates two files in the Windows directory with random names based on a list in the code, says Kaspersky. "These files harvest emails from the infected machine and send infected messages to these addresses."

The worm registers these files in the system registry auto-run key and creates additional files in the Windows directory and to spread, it scans the local machine for email addresses and mails copies of itself to every addresses it finds via a direct connection to an SMTP server.

"The infected emails have random subjects and body texts in English or German chosen from about a dozen variations," says Kaspersky, adding that he attachment containing the worm can have either a .pif, .zip or .bat extension.

===================

See:-

classic email worm - New Sober on the loose in Europe, Kaspersky Virus Lab, November 19, 2004

HOME

One Response to “New email worm on the loose”

  1. Reader's Write Says:

    Hope they find the guy that let this loose on the net and cut his Balls off!!!!!!

Leave a Reply

ONLY items referencing the post at hand, please. No links to personal sites, no personal attacks, trolling, freebie advertising, or off-topic posts. Thanks. And Cheers!

    Sponsored by
tek savvy