W32.Sober-K-mm on the loose
W32.Sober-K-mm on the loose

Mutant Sober worm spreading fast

Security firm intercepts 1,400 copies of latest mass-mailer variant

Written by Steve Ranger

A newly discovered variant of the mass-mailing Sober email worm is spreading rapidly and has already been spotted in the UK, according to MessageLabs.

The email security company said that it has intercepted 1,400 copies of W32.Sober-K-mm since 5am GMT this morning in Germany, France, the US and the UK.

Sober-K-mm sends itself as an attachment and creates random subject lines and body texts in either English or German, depending on the email addresses harvested by the worm.

It can also show a fake notice from antivirus vendors warning about a new version of the virus, and attempts to dupe users into clicking on the attachment which contains the worm by claiming that it contains a software patch.

But computer users who activate the file attached in the email invoke the virus, which harvests email addresses from the computer's hard drive.

Subject lines in the email may include 'Alert! New Sober worm', 'Paris Hilton Sex Videos', 'You visit illegal websites' and 'Your new Password'.

Once activated, Sober.K-mm drops several copies of executable files onto an infected computer with 'filenamescsrss.exe', 'winlogon.exe' and 'smss.exe'.

The worm modifies the registry key Software\Microsoft\Windows\CurrentVersion\Run so that it executes on startup. It then displays the contents of the file (systemdrive%/windows/temp/doc_data-text.txt) in notepad.

Tags:

Further reading

Latest Sober mutant targets soccer fans

Promise of World Cup tickets hides deadly payload   More...

Alert level raised on latest sober mutant

You've got mail, but be careful   More...

Mass-mailers oust Trojans as main threat

The advice remains the same: do not click on attachments   More...

Zafi-D and Netsky top virus charts

But Bagle and Sober will be the ones to watch   More...

Related articles

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement