virus
virus

Sober.c more toxic than first thought

McAfee upgrades status of bilingual worm

Written by Robert Jaques

The McAfee Anti-Virus Emergency Response Team (Avert) has today increased its original low-risk threat assessment of the 'moderately prevalent' Sober.c worm to 'medium risk' status.

Sober.c contains its own SMTP engine and targets email addresses which it harvests from the victims' machines.

Advertisement

Once activated, it emails itself to the user's Microsoft Outlook address book with outgoing messages constructed using its SMTP engine. The messages may be written in either English or German, and the attachment filename can vary.

Users should immediately delete any email containing the following:

Subject:

Attachments may end in any one of the following extensions and be preceded with .txt or .doc, and/or a random number:

After being executed, Sober.c extracts target email addresses from the victim's machine and writes them to the file SAVESYSS.DLL in the SysDir.

Two other copies of the worm are then dropped into SysDir, with varying filenames. For example, 'SysDir\ONDMONSTR.EXE' and 'SysDir\DATMSCRYPT.EXE'.

Avert warned in an advisory: "These two latter files are responsible for monitoring and maintaining that the worm stays resident in memory.

"Upon termination of one worm processes, another copy will restart the terminated process very quickly.

"Two processes run on the victim machine in order to ensure the worm stays memory resident."

More information on the Sober.c worm can be found here.

Tags:

Related articles

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

10 Oct 2008

7.33 MBPodcast Special: Views from the Valley More...

Podcast image

09 Oct 2008

12.99 MBComputing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security More...

Shaun Nichols and Iain Thomson

03 Oct 2008

6.49 MBPodcast Special: Views from the Valley More...

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

MoD building

Latest data breach leads MPs to demand culture change

MoD admits to losing a hard drive containing up to...  More...

Online shopping

E-retailers urged to prepare for Christmas

Credit crunch sending shoppers online for cheaper presents   More...

Mobile phone

Emerging markets drive mobile growth

Mobile penetration rates expected to reach 95 per cent by...  More...

Digital information

Poor data classification costing companies dear

Millions wasted on searching through clutter, says analyst   More...

Primary Navigation