Technology Computer & Networking security

Sober hangover begins

Worm stops spread
The Sober variant dubbed Sober.P by antivirus vendors Kaspersky and Mcafee, Sober.O by Symantec, Sober.N by Sophos, and Sober.S by Trend Micro, abruptly stopped its mass-mailing at midnight GMT on May 9th. During its peak, the only other decline was seen over the weekend of May 7th and 8th, which coincided with the Mother?s Day holiday in the U.S.

According to antivirus researchers at Kaspersky Labs, the Sober.P worm has entered its update phase, during which time the worm downloads files from pre-defined locations, executing those files on the impacted systems, thus launching a new round of malware infection possibly for the purpose of spam.


Social engineering the key
Sober.P relies on simple social engineering in order to compel recipients to open the infected attachment. Though the media has reported that the worm sends itself as an invitation to attend the World Cup, this particular message is extremely rare. Most often, Sober.P sends itself as a bounced/rejected message. Presumably, user?s curious to see what they allegedly sent are compelled to open the attachment, thus becoming infected.

Detection and removal is difficult
Once a system has become infected, Sober.P prevents other programs from accessing its files, thus some antivirus software may be unable to detect its presence on an already infected system. And some antivirus software that may be able to detect the in-memory process may still be unable to stop the process and thus unable to remove the worm.

The free McAfee AVERT Stinger tool has been updated to detect and remove the Sober.P worm from infected systems. However, Stinger can only detect Sober.P if the sytem has been booted in Safe Mode.

Additionally, older versions of Stinger do not detect Sober.P (even in Safe Mode), thus you must download the latest version of Stinger (dated on or after May 2, 2005). While Stinger is an excellent tool, it is designed to detect and remove only a relatively small number of viruses and does not prevent virus infection. Thus it should not be considered a substitute for antivirus software.
SHARE
RELATED POSTS on "Technology"
Home Security Systems: Which One Should I Get For My Family
Home Security Systems: Which One Should I Get For My Family
How to Protect Yourself From Fake Antivirus Programs and Other Scamware/Scareware
How to Protect Yourself From Fake Antivirus Programs and Other Scamware/Scareware
Another Facebook Spam E-mail Again?
Another Facebook Spam E-mail Again?
Using Free Anti Adware and Spyware - Tips To Keep Your PC Safe
Using Free Anti Adware and Spyware - Tips To Keep Your PC Safe
Is Online Data Backup Part of Your Disaster Recovery Plan?
Is Online Data Backup Part of Your Disaster Recovery Plan?
How To Recover Deleted Emails From Outlook?
How To Recover Deleted Emails From Outlook?
AVGRsstx DLL Error Fix
AVGRsstx DLL Error Fix
Virtualized datacenter: Greatly in demand!
Virtualized datacenter: Greatly in demand!
Cybercrime In the Workplace
Cybercrime In the Workplace
Automatic Manual Virus and Spyware Removal
Automatic Manual Virus and Spyware Removal
Data Recovery Is Easy In Notebook Repairs
Data Recovery Is Easy In Notebook Repairs
What Is Windows Defence Unit - How to Fix Windows Defence Unit Automatically
What Is Windows Defence Unit - How to Fix Windows Defence Unit Automatically
What Are Students Spending Most Time On?
What Are Students Spending Most Time On?
Deleted Mp3 Recovery - How to Restore Deleted Mp3 Files Easily
Deleted Mp3 Recovery - How to Restore Deleted Mp3 Files Easily
How to Install & Adjust the Extractor on the M-1911
How to Install & Adjust the Extractor on the M-1911
Home Security Cameras Provide Additional Reassurance
Home Security Cameras Provide Additional Reassurance
How to Recover Digital Pictures and Raw Images: an Easy Way
How to Recover Digital Pictures and Raw Images: an Easy Way
Data Recovery Vendor Considerations
Data Recovery Vendor Considerations
Resolving “The Delegate page is not available” Exchange Server Error
Resolving “The Delegate page is not available” Exchange Server Error
Malware Software to Remove Spyware and Adware in Computer
Malware Software to Remove Spyware and Adware in Computer

Leave Your Reply

*