Sober.L is mass-mailing worm that appeared this morning around 10 AM PST and is believed to be spreading rapidly in Germany, and is beginning to appear in several other countries. The worm, like previous Sober variants, spreads in both English and German email addresses, depending on the language of the installed copy of Windows.
Messages containing Sober.L typically pretend to be from an administrator in regards to the victim's password. The emails are written with poor capitalization and broken English. Hopefully, this will be a warning flag that will limit spread outside of Germany (although the German message also suffers from poor punctuation and capitalization.)
Sober.L has been declared a Medium risk at Trend Micro.
Details
Sober.L was discovered on March 8, 2005, with details first published around noon PST. It is a worm that spreads via email. It also terminates a small handful of security programs. The attachment containing Sober.L is named either MailTexte.zip (German) or acc_text.zip (English).
Protection
Updated detections for most antivirus programs should appear within the next 24 hours or so. It is unlikely emergency detection will be published, as the worm reminds a Low risk threat on all descriptions at this time. In the meantime, users should practice common sense and avoid opening suspicious emails, and, when in doubt, contact the alleged recipient to see if they really sent them.
Infected users should wait for detection files and/or more detailed information and removal information to be published before attempting to remove the worm. Until then, infected users should avoid connecting to the Internet or any open network.
Links
McAfeeHelp Forums - Excellent resource for latest information and updates.
Secunia - Compiles latest descriptions and links.
Trend Micro - Detailed write-up with good removal instructions.
Symantec - Detailed write-up with limited removal instructions.
Posted
Mar 07 2005, 03:52 PM
by
trafton