<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>W32.Sober.O@mm/Sober.P in Security</title>
<link>http://www.dslreports.com/forum/r13312109</link>
<description></description>
<language>en</language>
<pubDate>Fri, 27 Nov 2009 07:07:43 EDT</pubDate>
<lastBuildDate>Fri, 27 Nov 2009 07:07:43 EDT</lastBuildDate>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13380444</link>
<description><![CDATA[<A HREF="/useremail/u/964038"><b>alien8</b></A> : This weekly virus graph from my isp shows the pattern nicely:<br>&raquo;<A HREF="http://portal.plus.net/support/features/virusblock_weekly.shtml" >portal.plus.net/support/features&middot;&middot;&middot;ly.shtml</A><br><br>You can see sober.p suddenly stopping! <br><br>Cheers,<br><br>Steve<br><SMALL>--<br>Tired of spam? Grab www.spampal.org</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13380444</guid>
<pubDate>Wed, 11 May 2005 02:19:47 EDT</pubDate>
</item>

<item>
<title>Shouw - Not only interesting but relevant!</title>
<link>http://www.dslreports.com/forum/remark,13378576</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : Thanks shouw, the information is very much interesting . <br><br>This series looks much better planned and the execution reflects the effort of a profit making venture. Corporate patch management should be so effective at rolling out code. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13378576</guid>
<pubDate>Tue, 10 May 2005 21:33:09 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13377186</link>
<description><![CDATA[<A HREF="/useremail/u/818836"><b>Schouw</b></A> : No intention to spam here, but you might find <A HREF="http://www.viruslist.com/en/weblog?weblogid=163590373">this</A> interesting.<br><br>It mentions - albeit briefly - why you aren't seeing any Sober mails at this moment.<br><SMALL>--<br>Not speaking for Kaspersky Lab</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13377186</guid>
<pubDate>Tue, 10 May 2005 18:42:52 EDT</pubDate>
</item>

<item>
<title>Re: Cattleprod.WIN32.A</title>
<link>http://www.dslreports.com/forum/remark,13376919</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : According to F-Secure's <A HREF="http://stats.f-secure.com/more_info.asp?Name=W32/Sober.P@mm&TimePeriod=24h&Lang=en&Country=All">statistics page for Sober.P</A>, submissions have dropped off dramatically today compared to yesterday.  Netsky.P and Lovgate.W are now ahead of Sober.P on their top 10.  Does it have a hard coded drop dead date?  There's no mention in any of the write-ups.  Has anyone been hit today, or seen a drop off in hits?<br><SMALL>--<br>SMTP: Spam and Malware Transfer Protocol.  Also used on rare occasion to transmit e-mail messages.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13376919</guid>
<pubDate>Tue, 10 May 2005 18:07:08 EDT</pubDate>
</item>

<item>
<title>Cattleprod.WIN32.A</title>
<link>http://www.dslreports.com/forum/remark,13374038</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : maybe the cattleprod worm could solve a lot of the problems;<br><div class="bquote">CATTLEPROD.WIN32.A <br>Platforms: Win 95, Win 98, Win ME, Win NT, Win 2K, Win XP<br><br>Aliases; Dingzap.MM, emptybelfry.WIN32@.b, LIGHTMEUP.KB.MM, mousefun.WIN32.zap, slimtorture.A  <br><br>Arrival Form: Email<br>Type: Win32, Worm, Trojan<br>Damage: None, provides user training and negative reinforcement<br><br>The arriving email will have the following characteristics:<br>Subject: The subject of this mail will be one of the following:<br><br>*IMPORTANT* Please Validate Your Email Account<br>*IMPORTANT* Your Account Has Been Locked<br>[random text string]<br>Email Account Suspension<br>Notice: **Last Warning**<br>Notice:***Your email account will be suspended***<br>Security measures<br>Your email account access is restricted<br>Your Email Account is Suspended For Security Reasons<br><br>Attached File: The attached file will have one of the following names:<br>[random text string]<br>document_full<br>email-doc<br>email-info<br>email-text<br>IMPORTANT<br>information<br>info-text<br>your_details<br><br>followed by one of the following extensions:<br>bat<br>cmd<br>exe<br>pif<br>scr<br>zip<br><br>Malicious Activity<br>--------------------------<br>When the worm is executed it does the following:<br><br>Causes keyboard and mouse to be energized with cattle prod voltage. <br><br>Screen saver activates with "What the hell were you THINKING when you opened that??? <br><br>Volume control locked to maximum, loops on  "Slim Whitman sings Queen's Greatest Hits" <br></DIV>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13374038</guid>
<pubDate>Tue, 10 May 2005 12:05:16 EDT</pubDate>
</item>

<item>
<title>Re: Sober / Mytob writeup - Aladdin</title>
<link>http://www.dslreports.com/forum/remark,13373606</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : Many of these worms are similar enough in behavior that it's easy to get them mixed up.  With the similarity in most of the emails, I'm surprised people still open them. ;)  Well maybe I shouldn't be surprised...<br><br>I see a worm email, 99% of the time I *know* it's a worm, and usually which worm it is without even scanning the attachment.  Especially if it's one I've seen before.  I can recognize the latest Sober just by the subject line.<br><br>My inboxes have been quiet the past few days too.  But then I've only seen a half dozen or so, not like some people who have been hammered with dozens or hundreds of copies.<br><SMALL>--<br>SMTP: Spam and Malware Transfer Protocol.  Also used on rare occasion to transmit e-mail messages.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13373606</guid>
<pubDate>Tue, 10 May 2005 11:00:23 EDT</pubDate>
</item>

<item>
<title>Re: Sober / Mytob writeup - Aladdin</title>
<link>http://www.dslreports.com/forum/remark,13373377</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : I've seen them used interchangeably last few days. Gah, the mess this stuf makes. <br><br>Here's why I posted here instead of a new thread -  DiskDrive <A HREF="/useremail/u/1103424"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> also noted the multi-nomenclature (new word :D )<br><br>&raquo;<A HREF="/forum/remark,13205316">New Sober Variant???</A> <br><br>Maybe I should put in a new topic? <br><br>EDIT - Noticed this morning, NO new SOBERS showed up at all - I had been as many as 20 a day, all scrubbed by RoadRunner. *waits for the next round* ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13373377</guid>
<pubDate>Tue, 10 May 2005 10:26:07 EDT</pubDate>
</item>

<item>
<title>Re: Sober / Mytob writeup - Aladdin</title>
<link>http://www.dslreports.com/forum/remark,13373220</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : EGeezer, that is a writeup for a Mytob variant, not Sober.  Different worm, different name, different email texts, same annoyances. ;)<br><SMALL>--<br>SMTP: Spam and Malware Transfer Protocol.  Also used on rare occasion to transmit e-mail messages.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13373220</guid>
<pubDate>Tue, 10 May 2005 10:02:27 EDT</pubDate>
</item>

<item>
<title>Sober / Mytob writeup - Aladdin</title>
<link>http://www.dslreports.com/forum/remark,13373171</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : I wish they could make up their mind. Call it something, stick to it - From Aladdin Systems, who usually do good writeups when they do them ;<br> <BLOCKQUOTE><SMALL>said by Aladdin newsletter:</SMALL><HR>====================================================<br>Aladdin Content Security Response Team - Virus Alert<br>====================================================<br><br>Win32.Mytob.eg<br>===========================<br><br>Virus/Vandal name: Win32.Mytob.eg<br>Threat Level: Medium<br>Alias: WORM_MYTOB.EG, Net-Worm.Win32.Mytob.au, W32/Mytob-AU<br>Platforms: Win 95, Win 98, Win ME, Win NT, Win 2K, Win XP<br>Updated on: May 10, 2005<br>Arrival Form: Email<br>Type: Win32, Worm, Trojan<br>Damage: Create files, Modify files, Send Email, Remote control, Lowers<br>security<br><br>Introduction<br>---------------------<br>Win32.Mytob.eg is a mass-mailing worm which opens a backdoor on infected<br>systems and terminates security-related processes.<br><br>The arriving email will have the following characteristics:<br><br>Subject: The subject of this mail will be one of the following:<br><br>*IMPORTANT* Please Validate Your Email Account<br>*IMPORTANT* Your Account Has Been Locked<br>[random text string]<br>Email Account Suspension<br>Notice: **Last Warning**<br>Notice:***Your email account will be suspended***<br>Security measures<br>Your email account access is restricted<br>Your Email Account is Suspended For Security Reasons<br><br>Body: The body of this mail will be one of the following:<br><br>[random text string]<br><br>Account Information Are Attached!<br><br>Once you have completed the form in the attached file , your account<br>records will not be interrupted and will continue as normal.<br><br>please look at attached document.<br><br>To safeguard your email account from possible termination, please see the<br>attached file.<br><br>To unblock your email account acces, please see the attachement.<br><br>We have suspended some of your email services, to resolve the problem you<br>should read the attached document.<br><br>Attached File: The attached file will have one of the following names:<br><br>[random text string]<br>document_full<br>email-doc<br>email-info<br>email-text<br>IMPORTANT<br>information<br>info-text<br>your_details<br><br>followed by one of the following extensions:<br><br>bat<br>cmd<br>exe<br>pif<br>scr<br>zip<br><br>Malicious Activity<br>--------------------------<br>When the worm is executed it does the following:<br><br>1. It drops a copy of itself, internet.exe, into the default Windows<br>System folder.<br><br>2. To run on every startup, the worm creates the following registry entry:<br><br>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run<br>Internet Services = 'internet.exe'<br><br>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices<br>Internet Services = 'internet.exe'<br><br>3. When it runs on an up-to-date version of Windows XP, the worm will<br>disable the firewall by modifying the following registry entry:<br><br>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess<br>Start = '4'<br><br>4. The worm is also capable of connecting to an IRC server and listening<br>to incoming commands coming from a specific channel. This may allow a<br>hacker to take over the infected system.<br><br>5. The worm then terminates several security-related processes and also<br>blocks access to such websites to prevent security updates.<br><br>6. Finally, the worm will harvest email addresses from the infected system<br>and send itself to most contacts found. Some addresses may be avoided by<br>the worm.<br><br>eSafe Users<br>---------------------<br>eSafe users are protected against this vandal using the latest<br>vandal/virus update.<br><HR></BLOCKQUOTE><br><br>[rant]<br>Given the hokey email subject lines and attachment names and how often they're associated with malware, it's amazing people still bite on them - but they do, providing us with gainful employment, hobbyist activity and bemusement ;). <br>[/rant] <br><br>EG ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13373171</guid>
<pubDate>Tue, 10 May 2005 09:53:55 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13360003</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : <div class="bquote"><SMALL>said by  amysheehan <A HREF="/useremail/u/122916"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br><div class="bquote"><SMALL>said by  Chris 313 <A HREF="/useremail/u/1043110"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>I'm ok. I didn't even touch the zip file.<br> </DIV>I was just curious to know whether MSN actually had stripped the contents of that zip file since the text of the email said it was clean...<br><br> </DIV>That's likely a fake message put there by the worm itself. <br>If you look at other copies of similar worms lately, they<br>are all doing something like this, claiming that the <br>attachment was scanned by antivirus software and found clean.<br><SMALL>--<br>"Kayura or Badamon, whichever you are, you should know that I will never give up this battle. By the will of the Ancient, I shall succeed!" - Shuten (Anubis) from the Ronin Warriors.To RIAA/MPAA - You can sue but you can't catch everyone!</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13360003</guid>
<pubDate>Sun, 08 May 2005 15:04:19 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13359983</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : According to UK antivirus company Sophos, the Sober.P <br>worm now constitutes roughly 5% of all email traffic (as<br>of Friday Morning), and 77% of all virus activity they<br>are seeing:<br><br>&raquo;<A HREF="http://news.com.com/Sober+worm+makes+a+comeback/2100-7349_3-5698411.html?tag=nefd.top" >news.com.com/Sober+worm+makes+a+&middot;&middot;&middot;nefd.top</A><br><SMALL>--<br>"Kayura or Badamon, whichever you are, you should know that I will never give up this battle. By the will of the Ancient, I shall succeed!" - Shuten (Anubis) from the Ronin Warriors.To RIAA/MPAA - You can sue but you can't catch everyone!</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13359983</guid>
<pubDate>Sun, 08 May 2005 15:01:09 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13350392</link>
<description><![CDATA[<A HREF="/useremail/u/1056836"><b>ravencajun</b></A> : I am getting about 40-60 or so a day for the past few days all to my junk mail folder on my hotmail account.  None on my gmail, none on my yahoo, no other email addys are getting hit.  I just have to keep deleteing the junk mail from the folder several times a day to get rid of all of them.  The size is a good tale tell sign for sure. <br><br>Apparently someone is opening the things for them to be so rampant.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13350392</guid>
<pubDate>Sat, 07 May 2005 00:54:47 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13343307</link>
<description><![CDATA[<A HREF="/useremail/u/1163957"><b>Shriyash</b></A> : actually kaptz, the file is 0.05MB not kb, and so the size will be around 53kb, so i think the worm wasnt stripped of its potency.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13343307</guid>
<pubDate>Fri, 06 May 2005 07:44:41 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13343286</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : <div class="bquote"><SMALL>said by  amysheehan <A HREF="/useremail/u/122916"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>I was just curious to know whether MSN actually had stripped the contents of that zip file since the text of the email said it was clean... </DIV>The text stating the attachment is "clean" or "no virus found" is generated by the worm itself and is meaningless.  It's just another one of its social engineering tactics, to get people to "trust" the attachment.<br><br><STRIKE>However, I did notice that your zip file was only .05K in size, meaning it was probably stripped before it even reached your hotmail/MSN account.  Perhaps it passed through an outbound scanner before it reached you.</STRIKE><br><br>EDIT: It says .05M so it could still contain the worm which is roughly 73K in size encoded.  Nice way of measuring attachment size there, Microsoft...<br><SMALL>--<br>SMTP: Spam and Malware Transfer Protocol.  Also used on rare occasion to transmit e-mail messages.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13343286</guid>
<pubDate>Fri, 06 May 2005 07:39:10 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13342871</link>
<description><![CDATA[<A HREF="/useremail/u/1043110"><b>Chris 313</b></A> : <div class="bquote"><SMALL>said by  amysheehan <A HREF="/useremail/u/122916"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR><div class="bquote"><SMALL>said by  Chris 313 <A HREF="/useremail/u/1043110"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR>I'm ok. I didn't even touch the zip file.<br> </DIV>I was just curious to know whether MSN actually had stripped the contents of that zip file since the text of the email said it was clean...<br>Someone else I know had that kind of text in the email and the file had NOT been cleaned -  they didn't open the zip but scanned it only to find it was not cleaned as MSN had 'suggested'...<br>More worried about others who are more worried about not deleting it as junk and opening the zip without a thought...:)<br> </DIV>I don't know weather the file was actually clean as I dumped everything in my Junk folder after making the screenshot. <br><br>Being worried about others is where a good crash course in today's internet threats and protection and prevention comes in. <br><br>I personally got sick of seeing all the crap being mixed in with my legit mail and set up my protection to only receive from addresses i know, all else is sent to junk and i sort it out daily.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13342871</guid>
<pubDate>Fri, 06 May 2005 03:47:36 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13342805</link>
<description><![CDATA[<A HREF="/useremail/u/122916"><b>amysheehan</b></A> : <div class="bquote"><SMALL>said by  Chris 313 <A HREF="/useremail/u/1043110"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR>I'm ok. I didn't even touch the zip file.<br> </DIV>I was just curious to know whether MSN actually had stripped the contents of that zip file since the text of the email said it was clean...<br>Someone else I know had that kind of text in the email and the file had NOT been cleaned -  they didn't open the zip but scanned it only to find it was not cleaned as MSN had 'suggested'...<br>More worried about others who are more worried about not deleting it as junk and opening the zip without a thought...:)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13342805</guid>
<pubDate>Fri, 06 May 2005 03:16:03 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13342760</link>
<description><![CDATA[<A HREF="/useremail/u/1043110"><b>Chris 313</b></A> : I'm ok. I didn't even touch the zip file.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13342760</guid>
<pubDate>Fri, 06 May 2005 02:56:51 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13342711</link>
<description><![CDATA[<A HREF="/useremail/u/705588"><b>91439306</b></A> : I noticed that at the beginning of the week when this started here, I was finding that they had originated from the .nl domain extention. I guess it spread to Germany and then the US about the same time. Nasty, because unlike previous worms, Earthlink's Spaminator is not blocking the e-mails. It'd AV is stripping out the virus, at least here on my account. Volume is getting annoying though.<br><SMALL>--<br>Take care,<BR><BR>Mark & Mary Ann Weiss<BR><BR>Hear my Kurzweil Creations at: &raquo;<A HREF="http://www.dv-clips.com/theater.htm" >www.dv-clips.com/theater.htm</A><BR>'&raquo;<A HREF="http://www.mwcomms.com/auctions.htm" >www.mwcomms.com/auctions.htm</A><BR>'&raquo;<A HREF="http://www.mwcomms.com" >www.mwcomms.com</A><BR>'&raquo;<A HREF="http://www.adventuresinanimemusic.com" >www.adventuresinanimemusic.com</A><BR></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13342711</guid>
<pubDate>Fri, 06 May 2005 02:38:32 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13342613</link>
<description><![CDATA[<A HREF="/useremail/u/122916"><b>amysheehan</b></A> : <div class="bquote"><SMALL>said by  Chris 313 <A HREF="/useremail/u/1043110"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR>It looks like i got one.<br><br>Does this look it?<br><br>It was sent to my junkmail folder.<br> </DIV>Let's hope that the Zip file was cleaned before it was downloaded...<br><br>My son got one earlier that included the zip attachment however we found it had been cleaned by RR before he ever downloaded the message...<br><br>:)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13342613</guid>
<pubDate>Fri, 06 May 2005 02:05:41 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13342602</link>
<description><![CDATA[<A HREF="/useremail/u/1043110"><b>Chris 313</b></A> : It looks like i got one.<br><br>Does this look it?<br><br>It was sent to my junkmail folder.<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/13342602?c=819710&ret=L2ZvcnVtL3IxMzMxMjEwOS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="26331 bytes" WIDTH=600 HEIGHT=450 SRC="/r0/download/819710.thumb600~575311ed6d07b08d774885b51b6da114/SoberWormPic.gif/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13342602</guid>
<pubDate>Fri, 06 May 2005 02:02:49 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13340330</link>
<description><![CDATA[<A HREF="/useremail/u/447260"><b>Greg_Z</b></A> : Look at long headers kamootee.  Posting the short headers will not disclose what server is actually sending this crap out to the outside world.  Knology.net is where this crap is coming from.<br><SMALL>--<br>One man's customer loyalty is another man's misguided arrogance.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13340330</guid>
<pubDate>Thu, 05 May 2005 20:32:04 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13340311</link>
<description><![CDATA[<A HREF="/useremail/u/447260"><b>Greg_Z</b></A> : <div class="bquote"><SMALL>said by  macbloghaus <A HREF="/useremail/u/1037560"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>Thank god i have amac.<br>One reason why i switch is all the damn virus that you have to look out for..<br>I have a dell laptop and won't cut it on and connect due to virus.<br>So good luck guys and long live mac<br> </DIV>Sorry to say, just because a person uses Linux or MacOS does not make them anymore then a "carrier".  It is the reason that no matter what OS a person uses, they should still use strict rules in not opening any unknown sender emails.<br><SMALL>--<br>One man's customer loyalty is another man's misguided arrogance.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13340311</guid>
<pubDate>Thu, 05 May 2005 20:30:17 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13340157</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : Four copies in my mom's Yahoo email, all of course went<br>right into her bulk mail folder. <br><br>That's the only place I've seen any of them.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13340157</guid>
<pubDate>Thu, 05 May 2005 20:10:51 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13337207</link>
<description><![CDATA[<A HREF="/useremail/u/1109164"><b>kamootee</b></A> : mail_info.zip, account_info-text.zip, error-mail_info.zip, and secu.... <br><br>Admin@food4hungry.org <br><br>Itaccount_info-text.zip   <br>Item ID 14543   <br>Action Quarantined   <br>User Name     <br>User Email    <br>Last Error Norman found Sober.O@mm   <br>More Info Sober.O@mm found in account_info-text.zip\Winzipped-Text_Data.txt .exe    <br>________________________________________________________________________________<br><br>postmaster@aol.com <br><br>5/5/2005 1:50:33 AM   <br>Item Name: mail_info.zip   <br>Item ID 14517   <br>Action Quarantined   <br>User Name     <br>User Email    <br>Last Error Norman found Sober.O@mm   <br>More Info Sober.O@mm found in mail_info.zip\Winzipped-Text_Data.txt .pif   <br>________________________________________________________________________________<br><br>5/5/2005 1:34:45 AM   <br>Item Name: account_info-text.zip   <br>Item ID 14516   <br>Action Quarantined   <br>User Name     <br>User Email    <br>Last Error Norman found Sober.O@mm   <br>More Info Sober.O@mm found in account_info-text.zip\Winzipped-Text_Data.txt .pif    <br>_______________________________________________________________________________<br><br>postmaster@dhs.ca.gov<br><br>5/5/2005 1:19:06 AM   <br>Item Name mail_info.zip   <br>Item ID 14515   <br>Action Quarantined   <br>User Name  <br>User Email <br>Last Error Norman found Sober.O@mm   <br>More Info Sober.O@mm found in mail_info.zip\Winzipped-Text_Data.txt .pif    <br>_______________________________________________________________________________<br><br>register@dph.sbcounty.gov<br><br>5/4/2005 10:35:00 PM   <br>Item Name account_info-text.zip   <br>Item ID 14514   <br>Action Quarantined   <br>User Name     <br>User Email    <br>Last Error Norman found Sober.O@mm   <br>More Info Sober.O@mm found in account_info-text.zip\Winzipped-Text_Data.txt .pif    <br>________________________________________________________________________________<br><br>hostmaster@neucom.com<br><br>5/5/2005 9:29:05 AM   <br>Item Name account_info-text.zip   <br>Item ID 14542   <br>Action Quarantined     <br>User Email    <br>Last Error Norman found Sober.O@mm   <br>More Info Sober.O@mm found in account_info-text.zip\Winzipped-Text_Data.txt .exe    <br>_______________________________________________________________________________<br><br>register@clickmarks.com <br><br>5/4/2005 8:34:03 PM   <br>Item Name account_info-text.zip   <br>Item ID 14513   <br>Action Quarantined   <br>User Name     <br>User Email    <br>Last Error Norman found Sober.O@mm   <br>More Info Sober.O@mm found in account_info-text.zip\Winzipped-Text_Data.txt .pif    <br><br>Admin@comcast.net<br><br>mail_info.zip   <br>Item ID 14512   <br>Action Quarantined   <br>User Name     <br>User Email    <br>Last Error Norman found Sober.O@mm   <br>More Info Sober.O@mm found in mail_info.zip\Winzipped-Text_Data.txt .pif   <br><br>info@axiom-systems.com<br><br>5/5/2005 5:59:35 AM   <br>Item Name account_info.zip   <br>Item ID 14518   <br>Action Quarantined   <br>User Name     <br>User Email  <br>Last Error Norman found Sober.O@mm   <br>More Info Sober.O@mm found in account_info.zip\Winzipped-Text_Data.txt .pif    <br><br>Recipient To webmaster@mars.pl<br><br>account_info-text.zip   <br>Item ID 14511   <br>Action Quarantined   <br>User Name     <br>User Email    <br>Last Error Norman found Sober.O@mm   <br>More Info Sober.O@mm found in account_info-text.zip\Winzipped-Text_Data.txt .pif    <br><br>service@imckesson.com<br><br>Item Name mail_info.zip   <br>Item ID 14510   <br>Action Quarantined   <br>User Name     <br>User Email    <br>Last Error Norman found Sober.O@mm   <br>More Info Sober.O@mm found in mail_info.zip\Winzipped-Text_Data.txt .exe    <br><br>dtaitt@chcs.org<br><br>5/4/2005 5:09:26 PM   <br>Item Name our_secret.zip   <br>Item ID 14509   <br>Action Quarantined   <br>User Name    <br>User Email   <br>Last Error Norman found Sober.O@mm   <br>More Info Sober.O@mm found in our_secret.zip\Winzipped-Text_Data.txt .exe    <br><br>hostmaster@poweronemedia.com <br>5/4/2005 4:53:54 PM   <br>Item Name error-mail_info.zip   <br>Item ID 14497   <br>Action Quarantined   <br>User Name     <br>User Email    <br>Last Error Norman found Sober.O@mm   <br>More Info Sober.O@mm found in error-mail_info.zip\Winzipped-Text_Data.txt .exe    <br><br>register@mrmib.ca.gov <br>5/4/2005 4:35:37 PM   <br>Item Name error-mail_info.zip   <br>Item ID 14495   <br>Action Quarantined   <br>User Name     <br>User Email    <br>Last Error Norman found Sober.O@mm   <br>More Info Sober.O@mm found in error-mail_info.zip\Winzipped-Text_Data.txt .exe    <br>___________________________________________<br><br>webmaster@molinamedical.com<br><br>5/4/2005 4:17:54 PM   <br>Item Name error-mail_info.zip   <br>Item ID 14494   <br>Action Quarantined   <br>User Name     <br>User Email    <br>Last Error Norman found Sober.O@mm   <br>More Info Sober.O@mm found in error-mail_info.zip\Winzipped-Text_Data.txt .exe    ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13337207</guid>
<pubDate>Thu, 05 May 2005 14:05:50 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13337042</link>
<description><![CDATA[<A HREF="/useremail/u/1037560"><b>macbloghaus</b></A> : Thank god i have amac.<br>One reason why i switch is all the damn virus that you have to look out for..<br>I have a dell laptop and won't cut it on and connect due to virus.<br>So good luck guys and long live mac]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13337042</guid>
<pubDate>Thu, 05 May 2005 13:42:36 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13336078</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : <div class="bquote"><SMALL>said by  skyroket <A HREF="/useremail/u/408869"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>I'm getting a crapload of undeliverables.  It seems obvious to me that there's nothing one can do about this.  Is that an accurate assumption? </DIV>About the only thing you can do is see if the original sender's IP address is in any of the bounced messages, see if it looks familiar, or matches someone you've legitimately received emails from, and notify them that they are infected.<br><br>Or you could ascertain the IP, do a whois on it, notify their ISP's abuse department and hope they do something.  Don't hold your breath though, you'll turn blue and pass out. :)<br><SMALL>--<br>SMTP: Spam and Malware Transfer Protocol.  Also used on rare occasion to transmit e-mail messages.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13336078</guid>
<pubDate>Thu, 05 May 2005 11:41:17 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13336060</link>
<description><![CDATA[<A HREF="/useremail/u/408869"><b>skyroket</b></A> : All fine and dandy, we're protected from this virus, and malicious email attachments both...but what if the virus is sending itself to other people using MY email address as the sender's address.  I'm getting a crapload of undeliverables.  It seems obvious to me that there's nothing one can do about this.  Is that an accurate assumption?<br><SMALL>--<br>These guys are cool; and by cool, I mean totally sweet.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13336060</guid>
<pubDate>Thu, 05 May 2005 11:39:11 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13335723</link>
<description><![CDATA[<A HREF="/useremail/u/1159554"><b>norwegian</b></A> : seeing as i got 17 in one hit, ill pass on the names<br><br>dixakagin(at)gundamfan(dot)com<br> admin(at)hotmail(dot)com <br>info(at)hotmail(dot)com <br>raym(at)eiw(dot)com.au <br>symondeb(at)eiw(dot)com.au<br>symondeb(at)eiw(dot)com.au<br> ifjpk(at)gay-personals(dot)com <br>3ddlyall(at)kalgold(dot)com.au <br>webmaster(at)mail.daily-horoscopes(dot)com <br>hostmaster(at)hotmail(dot)com <br>service(at)hotmail(dot)com<br>postmaster(at)boc(dot)com <br>postmaster(at)zoog02(dot)com<br> register(at)emerge(dot)net.au<br><br>these were all in there today<br>some are ones about virus scans all clear, acct details and passwords, you name it, it was there lets hope no one opens them up, or sans might go rainbow colors<br> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13335723</guid>
<pubDate>Thu, 05 May 2005 10:52:03 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13335651</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Got five more in my email honeypot this morning.<br><br>New Subject titles are generated to try and fool the recipient. The dead give away is the file size that stays the same - they were all 73Kb. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13335651</guid>
<pubDate>Thu, 05 May 2005 10:41:10 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13335482</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : Congratulations,  pcdebb <A HREF="/useremail/u/254898"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> ;)<br><br>I've received a total of four so far, across 3 different email addresses.  Nothing compared to some of last year's outbreaks but the most hits I've seen this year so far.<br><br>Two that came into my own domain, I was able to figure out the sender by matching the IP address in the headers to some legitimate emails that came from the same IP.  So I sent them an email telling them that they were infected.  It's not very often that I'm able to do that; usually when I get hit with a worm it comes from an IP that I have no record of otherwise.<br><SMALL>--<br>SMTP: Spam and Malware Transfer Protocol.  Also used on rare occasion to transmit e-mail messages.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13335482</guid>
<pubDate>Thu, 05 May 2005 10:19:04 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13335353</link>
<description><![CDATA[<A HREF="/useremail/u/254898"><b>pcdebb</b></A> : I got one! :p  came from admin@yahoo.com.  I was on my way out to work so I didnt bother with examining the headers.<br><SMALL>--<br><A HREF="http://pcdebb.blogspot.com/">babbling</A> | <A HREF="http://mvm.removed.us/">mvm</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13335353</guid>
<pubDate>Thu, 05 May 2005 09:59:15 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13334715</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : Gmail rejects any attachment with certain filename suffixes such as .exe, .zip, .scr, .pif, etc, regardless of if they're infected or not.<br><br>The gobbeldygook you see in the bounce is the original message with the attachment (encoded in base64 so it can be emailed), but without being interpreted as an attachment, so you see the code.<br><br>I actually figured out who was sending me the Sobers, it was a local non-profit org.  I sent them an email to let them know they have an infection on their hands. :huh:  Hopefully they'll act on it soon.<br><SMALL>--<br>SMTP: Spam and Malware Transfer Protocol.  Also used on rare occasion to transmit e-mail messages.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13334715</guid>
<pubDate>Thu, 05 May 2005 07:33:43 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13332489</link>
<description><![CDATA[<A HREF="/useremail/u/1163957"><b>Shriyash</b></A> : i tired to send/forward 1 copy of this worm to my gmail acc.<br>just to see if it would.<br><br>i was surprised that it didnt. i got a "failure notice".<br><div class="code"><PRE><span class="codetext">Hi. This is the qmail-send program at yahoo.com.<br>I'm afraid I wasn't able to deliver your message to the following addresses.This is a perm<br> *anent error; I've given up. Sorry it didn't work out.<br>64.233.185.27 failed after I sent the message.<br>Remote host said: 552 5.7.0 Illegal Attachment<br> <br>(*) WARNING 1 long line(s) split</SPAN></PRE></DIV><br>as you can see, gmail it seems rejected this attachment calling it illegal.!<br><br>now , it also gave me the analysis of this atttachment, so what is all this? is that the worms code? {it goes on and on, i just got a small section of it}<br>is it encrypted?<br><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/13332489?c=819059&ret=L2ZvcnVtL3IxMzMxMjEwOS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="187393 bytes" WIDTH=600 HEIGHT=658 SRC="/r0/download/819059.thumb600~bb83b88427cbaa4747fbe6c5b97be3ea/sober_p.JPG/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13332489</guid>
<pubDate>Wed, 04 May 2005 21:57:47 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13331383</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : Symantec has added a !enc detection (W32.Sober.O@mm!enc)in today's LiveUpdate.  So now NAV will delete the entire email instead of just the attachment.<br><SMALL>--<br>SMTP: Spam and Malware Transfer Protocol.  Also used on rare occasion to transmit e-mail messages.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13331383</guid>
<pubDate>Wed, 04 May 2005 19:40:26 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13331040</link>
<description><![CDATA[<A HREF="/useremail/u/447260"><b>Greg_Z</b></A> : Sober.s goes through cookies, web history, contact list, to find places to send itself out.  I have been looking at the header info on the ones that I have been getting, and they are coming out of a server at knology.net.<br><br>X-Originating-IP: [69.1.27.198]<br>Received: from rvvvxjm.us (user-69-1-27-198.knology.net [69.1.27.198])<br><br>I have sent a information email to people to let them know about this nasty and to not open up the attachment.<br><SMALL>--<br>One man's customer loyalty is another man's misguided arrogance.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13331040</guid>
<pubDate>Wed, 04 May 2005 18:57:57 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13330871</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : First time I've ever received an infected mass mailing (at home). I had the first one yesterday, and 3 today, all to a Yahoo account.<br><SMALL>--<br>TheJoker</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13330871</guid>
<pubDate>Wed, 04 May 2005 18:37:37 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13330841</link>
<description><![CDATA[<A HREF="/useremail/u/611455"><b>skj</b></A> : Got 23 more of them today.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13330841</guid>
<pubDate>Wed, 04 May 2005 18:34:52 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13329979</link>
<description><![CDATA[<A HREF="/useremail/u/233244"><b>cjsmith</b></A> : I have been receivin these e-mails for about a week now. Luckily AVG7F have been blocking them, easy to delete from the Virus Vault. :)<br>---------<br>Viruses found in the attached files.<br>The file mail_info.zip: Virus identified  I-Worm/Sober.P. The attachment was moved to the virus vault.<br>---------<br><SMALL>--<br>I'm on the outside looking inside<br>What do I see<br>Much confusion, disillusion<br>All around me.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13329979</guid>
<pubDate>Wed, 04 May 2005 16:48:16 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13329590</link>
<description><![CDATA[<A HREF="/useremail/u/309944"><b>thedip</b></A> : Here's a graph from Brightmail.<br>While the total daily worms hasn't surpassed total daily spam,<br>certain hours of the day it has. Our system gets an average of <br>30k emails a day, it has gone up quite a bit since this worm <br>hit.<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/13329590?c=818870&ret=L2ZvcnVtL3IxMzMxMjEwOS54bWw%3D"><IMG TITLE="20549 bytes" BORDER=0 WIDTH=381 HEIGHT=456 SRC="/r0/download/818870~a29a38a9814780002871584dde43a77e/percentspam.PNG"></A><br>Percents</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13329590</guid>
<pubDate>Wed, 04 May 2005 15:58:37 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13329485</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : maybe my spam counting stats are off but the stats for @dslr.net look like this, all that red is Sober.<br><br><IMG SRC="http://mail.dslr.net/cgi-bin/mailgraph.cgi/mailgraph_1_err.png">]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13329485</guid>
<pubDate>Wed, 04 May 2005 15:43:00 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13329441</link>
<description><![CDATA[<A HREF="/useremail/u/309944"><b>thedip</b></A> : Yesterday was the first time ever that the % of incoming email that was worms/virii exceeded % of spam, thanks to this worm!<br><br>% of sober emails:<br>5/1/05   1% (21 emails)<br>5/2/05 	8%   (2,247 emails)<br>5/3/05 	32%  (12,462 emails)<br>5/4/05 	33%  (10,935 emails so far)<br><br>Brightmail Antispam has blocked all of them :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13329441</guid>
<pubDate>Wed, 04 May 2005 15:37:37 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13329308</link>
<description><![CDATA[<A HREF="/useremail/u/1198867"><b>kemacee</b></A> : We've been hammered with some 3700+ just in our catch-all alone... All the proper accounts have gotten at least 20-50 today, and I've been hearing from friends who have gotten quite a few as well.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13329308</guid>
<pubDate>Wed, 04 May 2005 15:19:18 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13329080</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : Sober variants tend to spread well in Europe, especially Germany, since it sends messages in German to German speaking domains.  Plus this latest variant is clever in its social engineering in the German emails (the soccer tickets thing), moreso than the English emails, which are the typical "your email bounced, see the attachment for details" sort of thing.<br><br>I received a 2nd one. <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Account and Password Information are attached!<br><br>Visit: http: //www.lacoe.edu<br><br>*** AntiVirus: No Virus found<br>*** "$MY_DOMAIN" Anti-Virus<br>*** http: //www.$MY_DOMAIN.com<br><br>Attachment: account_info.zip  <br><HR></BLOCKQUOTE>Gotta love the ones that say "No Virus Found"... like I'm going to fall for that. :D<br><SMALL>--<br>SMTP: Spam and Malware Transfer Protocol.  Also used on rare occasion to transmit e-mail messages.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13329080</guid>
<pubDate>Wed, 04 May 2005 14:49:22 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13328994</link>
<description><![CDATA[<A HREF="/useremail/u/612933"><b>Chizep</b></A> : According to this article:<br> <BLOCKQUOTE><SMALL>said by &raquo;<A HREF="http://news.com.com/Sober+worm+spreads+like+wildfire/2100-7349_3-5693981.html?part=rss&tag=5693981&subj=news:" >news.com.com/Sober+worm+spreads+&middot;&middot;&middot;bj=news:</A></SMALL><HR>Sober.P, first detected on Monday, now <B>accounts for 77 percent of all viruses detected by Sophos's threat-monitoring stations worldwide</B>, the British security company said on Tuesday. At the same time, Kaspersky Lab, a Russian maker of antivirus software designed to combat such threats, described the worm's spread in Western Europe as an "epidemic."<HR></BLOCKQUOTE><br>Wow. :mad:]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13328994</guid>
<pubDate>Wed, 04 May 2005 14:38:16 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13328911</link>
<description><![CDATA[<A HREF="/useremail/u/526691"><b>Penguins</b></A> : SpamAssassin seems to be hammering these pretty well, only 2 or 3 of these have actually wormed past it in the last week or so.<br><SMALL>--<br>Pure magic in 2k of 6502.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13328911</guid>
<pubDate>Wed, 04 May 2005 14:27:38 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13328883</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : we got 800 in the last 3 days, 95% Sober, without any catch all account. It must be currently chewing up quite a bit of worldwide mail system bandwidth.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13328883</guid>
<pubDate>Wed, 04 May 2005 14:24:46 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13328616</link>
<description><![CDATA[<A HREF="/useremail/u/632357"><b>Phil BK</b></A> : Getting hammered with this in our catchall account. It doesn't hurt anyone since it's only to scan for legit emails with the wrong address. However I am getting at least 200 of these every 5 min into that account. It seems the virus doesn't just take addresses and mail to them, it makes them up out of common addresses and sends them to the domain. So since this account grabs all the email with non existant accounts, it is getting hammered hard.<br><SMALL>--<br>If at first you don't succeed...bug them till you get what you want.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13328616</guid>
<pubDate>Wed, 04 May 2005 13:52:22 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13327329</link>
<description><![CDATA[<A HREF="/useremail/u/483140"><b>boognish</b></A> : There is 120-150 email boxes.  I don't have the reports I get set up to see who is getting the viruses just who sends them.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13327329</guid>
<pubDate>Wed, 04 May 2005 10:54:19 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13327152</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : Boognish, just curious, how many addresses are on your Exchange server (ballpark)?  Just wondering if this Sober tends to hit the same addresses over and over, or if it's hitting a wide swath of addresses.<br><br>My address had one email this morning, but a year ago my wife got nailed with 50+ emails of an earlier Sober variant, all from the same IP.  So some Sobers, in at least some cases, can bang the same addresses over and over.<br><SMALL>--<br>SMTP: Spam and Malware Transfer Protocol.  Also used on rare occasion to transmit e-mail messages.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13327152</guid>
<pubDate>Wed, 04 May 2005 10:28:50 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13327149</link>
<description><![CDATA[<A HREF="/useremail/u/292724"><b>BillRoland</b></A> : Interesting how only a few weeks ago some were proclaiming an end to the mass spreading e-mail worm.  The Norman engine on GFI MailSecurity has picked off just about 350 of these in the last 2 days.  Looks like Sober.O is just proving that worms haven't become irrelevent...yet.<br><SMALL>--<br>"Don't steal.  The government hates competition."</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13327149</guid>
<pubDate>Wed, 04 May 2005 10:28:33 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13327127</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : got a more than a couple of these nastys in my gmail inbox today, exact matches ! i think this worm is really spreading far and wide.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13327127</guid>
<pubDate>Wed, 04 May 2005 10:23:28 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13326767</link>
<description><![CDATA[<A HREF="/useremail/u/483140"><b>boognish</b></A> : We are still getting hammered by this last night and this morning.  Most of them look like one of these.<br><div class="code"><PRE><span class="codetext">Registration Confirmation The attachment "account_info-text.zip" was marked for Deletion f<br> *or the following reasons:<br> Virus W32.Sober.O@mm was found in Winzipped-Text_Data.txt           .pif.<br> <br>Subject of the message:  FwD: mailing error The attachment "mail_info.zip" was marked for <br> *Deletion for the following reasons:<br> Virus W32.Sober.O@mm was found in Winzipped-Text_Data.txt           .pif.<br> <br>Subject of the message:  mailing error The attachment "error-mail_info.zip" was marked for<br> * Deletion for the following reasons:<br> Virus W32.Sober.O@mm was found in Winzipped-Text_Data.txt           .pif.<br> <br>The attachment "our_secret.zip" was marked for Deletion for the following reasons:<br> Virus W32.Sober.O@mm was found in Winzipped-Text_Data.txt           .pif.<br> <br><br>(*) WARNING 3 long line(s) split</SPAN></PRE></DIV>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13326767</guid>
<pubDate>Wed, 04 May 2005 09:13:36 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13326545</link>
<description><![CDATA[<A HREF="/useremail/u/122916"><b>amysheehan</b></A> : To reinstall Live Update see:<br><br>How to download and install the newest version of LiveUpdate [from Symantec support]<br>&raquo;<A HREF="http://service1.symantec.com/SUPPORT/sharedtech.nsf/docid/1999051911110813?Open&src=bar_sch_nam&docid=2002071909270613&nsf=sharedtech.nsf&view=7e7f15291a25d938882567e50048a048&dtype=&prod=&ver=&osv=&osv_lvl=" >service1.symantec.com/SUPPORT/sh&middot;&middot;&middot;osv_lvl=</A><br><br>;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13326545</guid>
<pubDate>Wed, 04 May 2005 08:21:15 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13326498</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : Tim dob, you should get the removal tool from here: &raquo;<A HREF="http://securityresponse.symantec.com/avcenter/venc/data/w32.sober.removal.tool.html" >securityresponse.symantec.com/av&middot;&middot;&middot;ool.html</A><br><br>You'll have to reinstall LiveUpdate afterward, since Sober.O deletes it.<br><br>Well, I had my first hit this morning.  The subject on my sample is "Your email was blocked" and the attachment was named mail_info.zip.<br><SMALL>--<br>SMTP: Spam and Malware Transfer Protocol.  Also used on rare occasion to transmit e-mail messages.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13326498</guid>
<pubDate>Wed, 04 May 2005 08:08:44 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13326100</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Hi.<br>I need help the virus deled your Symantec<br>it deled your update Fil but how do i fix this must i Re-Istall or ..<br>who knows this help me plz !<br><br> <IMG SRC="http://www.game-legion.com/W32.Sober.O@mm.JPG"> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13326100</guid>
<pubDate>Wed, 04 May 2005 04:52:18 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13326088</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : [img/] &raquo;<A HREF="http://www.game-legion.com/W32.Sober.O@mm.JPG" >www.game-legion.com/W32.Sober.O@mm.JPG</A> [img]]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13326088</guid>
<pubDate>Wed, 04 May 2005 04:45:32 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13325981</link>
<description><![CDATA[<A HREF="/useremail/u/1163957"><b>Shriyash</b></A> : Spread of Sober E-Mail Worm Variant Slowing<br>As always, PC users urged to update their antivirus software.<br><br>&raquo;<A HREF="http://www.pcworld.com/news/article/0,aid,120682,00.asp" >www.pcworld.com/news/article/0,a&middot;&middot;&middot;2,00.asp</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13325981</guid>
<pubDate>Wed, 04 May 2005 03:48:59 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13325787</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Our campus has greater than 12,000 e-mail infecting of new Sober series, with no successful infect of computers. <br><br>NOD32 is stopping him since Monday, now by name, but as the unknown virus before update. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13325787</guid>
<pubDate>Wed, 04 May 2005 02:20:17 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13325781</link>
<description><![CDATA[<A HREF="/useremail/u/527502"><b>QS</b></A> : I feel so left out, I have honestly never been hit by an email worm before. And I mean never. Kinda wish i would at least get one, so my AV can stretch it's legs =P]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13325781</guid>
<pubDate>Wed, 04 May 2005 02:17:05 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13325291</link>
<description><![CDATA[<A HREF="/useremail/u/335226"><b>compuwizz</b></A> : Just to clear things up. We do have virus scanning on our e-mails. One of my professors said last year that they process about 2 million messages per day. I beleive it was when MyDoom or another virus hit campus, before the definitions were even created, there were 10 million e-mails in a 4 hour period. It literally brought the servers to a standstill and they were down for at least 3 days while they processed the backlog of mail. The campus really took a hit, so much that we do these days relies on e-mails whether it be pdf quizes or announcements.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13325291</guid>
<pubDate>Wed, 04 May 2005 00:15:18 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13324862</link>
<description><![CDATA[<A HREF="/useremail/u/1163957"><b>Shriyash</b></A> : just a couple of snaps for anyone curious ;)<br>:p<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/13324862?c=818608&ret=L2ZvcnVtL3IxMzMxMjEwOS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="41397 bytes" WIDTH=600 HEIGHT=422 SRC="/r0/download/818608.thumb600~c2ab38fa3572a36baa417ecd3bef0f23/sober_2.JPG/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/13324862?c=818609&ret=L2ZvcnVtL3IxMzMxMjEwOS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="25058 bytes" WIDTH=600 HEIGHT=224 SRC="/r0/download/818609.thumb600~d42b8e68e8e0d47de9f78f06dca42113/sober_3.JPG/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13324862</guid>
<pubDate>Tue, 03 May 2005 23:16:39 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13324744</link>
<description><![CDATA[<A HREF="/useremail/u/1163957"><b>Shriyash</b></A> : over the last 2 days, i have recieved several copies of this virus in my Yahoo bulk mail folder.<br>they are typically 72kb to 73kb in size, they all have attachments , with names like "mail_info.zip" or "error_info.zip".<br><br>{gives me the jitters just looking at it!:hmm::huh:}:D<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/13324744?c=818599&ret=L2ZvcnVtL3IxMzMxMjEwOS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="30717 bytes" WIDTH=600 HEIGHT=133 SRC="/r0/download/818599.thumb600~40094fcc014477f1f1831deca728b959/Sober_virus.JPG/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13324744</guid>
<pubDate>Tue, 03 May 2005 23:01:32 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13323999</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : <div class="bquote"><SMALL>said by  compuwizz <A HREF="/useremail/u/335226"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>notice the heading at the top, it hit a listserv </DIV>And why does the listserv not have (a) a virus scanner, (b) attachment blocking, or (c) a moderator to screen messages posted to the list? :p<br><SMALL>--<br>SMTP: Spam and Malware Transfer Protocol.  Also used on rare occasion to transmit e-mail messages.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13323999</guid>
<pubDate>Tue, 03 May 2005 21:22:42 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13323875</link>
<description><![CDATA[<A HREF="/useremail/u/335226"><b>compuwizz</b></A> : Looks like my school is having fun with it<br><br>&raquo;<A HREF="http://antivirus.vt.edu/" >antivirus.vt.edu/</A><br><br>notice the heading at the top, it hit a listserv<br><br>Sending mail and webmail is flakey at best right now.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13323875</guid>
<pubDate>Tue, 03 May 2005 21:09:27 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13323569</link>
<description><![CDATA[<A HREF="/useremail/u/611455"><b>skj</b></A> : I have gotten about 50 of them since yesterday.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13323569</guid>
<pubDate>Tue, 03 May 2005 20:35:37 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13323483</link>
<description><![CDATA[<A HREF="/useremail/u/527351"><b>bskuared</b></A> : I'm getting over 100 a day of a variety of these.  Zone Alarm or AVG Free Cleans them all but still a major pain in the mailbox ;)  <br><SMALL>--<br>2b or not 2b<br><BR><br>--<br><BR><br>none of this really matters :)<br><br></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13323483</guid>
<pubDate>Tue, 03 May 2005 20:22:29 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13322994</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : <div class="bquote"><SMALL>said by  Chizep <A HREF="/useremail/u/612933"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>Getting hit with it here at my job right now.<br><br>Forutnately none of the users have been stupid enough open the zip and execute the contents.<br> </DIV>I haven't seen any copies at work yet, though there was<br>an unspecified warning about a new email virus sent by IT<br>and for all users to delete attachments from unknown<br>senders. I was not sure which it was until I had read <br>about the latest Sober variants.<br><br>None of my other email accounts have gotten hit yet. <br><SMALL>--<br>"Kayura or Badamon, whichever you are, you should know that I will never give up this battle. By the will of the Ancient, I shall succeed!" - Shuten (Anubis) from the Ronin Warriors.<br>To RIAA/MPAA - You can sue but you can't catch everyone!</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13322994</guid>
<pubDate>Tue, 03 May 2005 19:25:27 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13320389</link>
<description><![CDATA[<A HREF="/useremail/u/1109651"><b>wadonoel</b></A> : Mine came from register@cigna.com, sent through an Italian dynamic address. It's quite rare that I receive viruses on that account so it really must be wide spread.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13320389</guid>
<pubDate>Tue, 03 May 2005 14:06:24 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13320014</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Latest Subject title.<br><br>- Mailing error<br><br>:)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13320014</guid>
<pubDate>Tue, 03 May 2005 13:11:00 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13318760</link>
<description><![CDATA[<A HREF="/useremail/u/203572"><b>timcuth</b></A> : I got two, last night. Avast! caught them and I hit the recommended Delete button. I assume I am okay.<br><br>Tim]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13318760</guid>
<pubDate>Tue, 03 May 2005 10:20:20 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13318730</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Recieved 6 more under a variety of Subject titles overnight.<br><br>- Registration confirmation<br><br>- Your email was blocked<br><br>- FWD: Your password<br><br>- Your password<br><br>All are in the 73 - 74kb range.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13318730</guid>
<pubDate>Tue, 03 May 2005 10:15:34 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13318417</link>
<description><![CDATA[<A HREF="/useremail/u/483140"><b>boognish</b></A> : Wow this is a busy one.  Came in this morning to work and have 1000 quarantines of it from the exchange server.   We don't get that many quarantines of everything combined in a week.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13318417</guid>
<pubDate>Tue, 03 May 2005 09:24:23 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13318145</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : It amazes me that after 5 years of this people still fall for these things.  Yes, it's been (nearly) 5 years since LoveLetter started this lovely trend.<br><br>So far I've missed out on this one.  Unlike last year where I seemed to get hammered every time a new worm appeared.<br><SMALL>--<br>SMTP: Spam and Malware Transfer Protocol.  Also used on rare occasion to transmit e-mail messages.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13318145</guid>
<pubDate>Tue, 03 May 2005 08:26:44 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13318137</link>
<description><![CDATA[<A HREF="/useremail/u/612933"><b>Chizep</b></A> : <div class="bquote"><SMALL>said by  DevilFrank <A HREF="/useremail/u/839734"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR>I´m afraid this worm will be increasing in Germany today, because the message is very artful.<br>Many people in Germany hope they are to be the winner of an official ticket of the soccer World Cup 2006 that the FIFA will be drawing lots for. <br>And they will be clicking and clicking and clicking...<br> </DIV>Yep, social engineering at its best...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13318137</guid>
<pubDate>Tue, 03 May 2005 08:24:45 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13317324</link>
<description><![CDATA[<A HREF="/useremail/u/839734"><b>DevilFrank</b></A> : I´m afraid this worm will be increasing in Germany today, because the message is very artful.<br>Many people in Germany hope they are to be the winner of an official ticket of the soccer World Cup 2006 that the FIFA will be drawing lots for. <br>And they will be clicking and clicking and clicking...<br><SMALL>--<br>Regards from Germany. Please excuse my stumbling English</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13317324</guid>
<pubDate>Tue, 03 May 2005 02:21:53 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13315786</link>
<description><![CDATA[<A HREF="/useremail/u/254898"><b>pcdebb</b></A> : all quiet here, again, i miss out on all the fun :(]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13315786</guid>
<pubDate>Mon, 02 May 2005 22:19:57 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13315764</link>
<description><![CDATA[<A HREF="/useremail/u/248260"><b>Llama</b></A> : Gotten hit 14 times today with this one.  Roadrunner has actually caught all of them so far.  Avast is there as a backup.  Deleting/Bouncing/Blacklisting them with Mailwasher as they roll in.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13315764</guid>
<pubDate>Mon, 02 May 2005 22:18:03 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13315669</link>
<description><![CDATA[<A HREF="/useremail/u/185439"><b>ritzy57</b></A> : I received 28 E-mails with this virus attached. Mine all had the words, "Your Password," or "Registering Confirmation," or, "ok ok ok,,,,,here is it"<br>McAffee and AVG, did a great job! :)<br>This is the first time I have ever been hit with an E-mail virus, and,... I just got three more!<br>(feel like I'm standing in front of a big plate glass window, up high in a building, watching a fierce thunder and lightening storm rage outside)<br><SMALL>--<br>A day without sunshine is....depressing</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13315669</guid>
<pubDate>Mon, 02 May 2005 22:06:01 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13314118</link>
<description><![CDATA[<A HREF="/useremail/u/612933"><b>Chizep</b></A> : Trend Micro updated itself and all online clients.  <br><br>Running a full scan right now on all online clients (roughly 50 boxes.)<br><br>Will have piece of mind when I <I>don't</I> get any e-mail  notifications saying someone has been infected.  :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13314118</guid>
<pubDate>Mon, 02 May 2005 19:05:22 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13313672</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Received in my email honeypot.<br><br>Keep 'em comin', boys! :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13313672</guid>
<pubDate>Mon, 02 May 2005 18:15:52 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13313552</link>
<description><![CDATA[<A HREF="/useremail/u/927553"><b>RayMorris</b></A> : Hmmm... Weird... Just check our mail server log and we are also starting to get hit already. <br><br>Filtered out 7 copies of this baddie... :uhh:]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13313552</guid>
<pubDate>Mon, 02 May 2005 18:00:09 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13313068</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : I was going to post about this hours ago. I woke up to about 10 emails from this virus, then updated f-prot early (normally the updates fire off "only" once a day), and it started to block the M variant, but I'm still getting "Your Password" and "Registrating Confirmation" attached zips.. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13313068</guid>
<pubDate>Mon, 02 May 2005 17:03:28 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13313032</link>
<description><![CDATA[<A HREF="/useremail/u/612933"><b>Chizep</b></A> : Sweet.  Updated exchange.  Patiently waiting on Trend Micro...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13313032</guid>
<pubDate>Mon, 02 May 2005 17:00:22 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13312924</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : LiveUpdate has been issued, NAV & SAV should detect now.<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/13312924?c=817773&ret=L2ZvcnVtL3IxMzMxMjEwOS54bWw%3D"><IMG TITLE="32524 bytes" BORDER=0 WIDTH=360 HEIGHT=337 SRC="/r0/download/817773~b57b103ab11f58285a72e46d13c87131/Sober.jpg"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13312924</guid>
<pubDate>Mon, 02 May 2005 16:50:06 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13312899</link>
<description><![CDATA[<A HREF="/useremail/u/612933"><b>Chizep</b></A> : Ah yeah, so basically it's Sober.S?<br><br>I guess variants O, P, & S are more or less the same.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13312899</guid>
<pubDate>Mon, 02 May 2005 16:47:30 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13312811</link>
<description><![CDATA[<A HREF="/useremail/u/411904"><b>gdm</b></A> : Trend has screen shots of what the email is and states for trend pattern 2.611.00 is needed but i don't see it posted yet.<br><br>Solution for this &raquo;<A HREF="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FSOBER%2ES&VSect=Sn" >www.trendmicro.com/vinfo/virusen&middot;&middot;&middot;VSect=Sn</A><br><br>Latest trend pattern &raquo;<A HREF="http://www.trendmicro.com/download/pattern.asp" >www.trendmicro.com/download/pattern.asp</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13312811</guid>
<pubDate>Mon, 02 May 2005 16:38:20 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13312754</link>
<description><![CDATA[<A HREF="/useremail/u/612933"><b>Chizep</b></A> : Getting hit with it here at my job right now.<br><br>Have the following in place but its not catching it:<br><br>Symantec Mail Security for Exchange v4.5.0.719 with 5/1/2005 Rev 3<br>Trend Micro OfficeScan Client v6.5, Engine: 7.510, Pattern File: 2.609.00<br><br>I need to investigate manually updating both pieces.<br><br>Forutnately none of the users have been stupid enough open the zip and execute the contents.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13312754</guid>
<pubDate>Mon, 02 May 2005 16:32:12 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13312265</link>
<description><![CDATA[<A HREF="/useremail/u/292724"><b>BillRoland</b></A> : Yep, GFI Mail Security's Trojan and Threat Detection engine got hammered briefly before there were updated def's for it from Norman and BitDefender.  I love that module :)<br><SMALL>--<br>"Don't steal.  The government hates competition."</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13312265</guid>
<pubDate>Mon, 02 May 2005 15:31:07 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13312144</link>
<description><![CDATA[<A HREF="/useremail/u/763844"><b>Allnew</b></A> : Code yellow from Trend.<br><br>YELLOW ALERT - WORM_SOBER.S - 02.05.2005 (Yellow Alert):<br><br>TrendLabs has received several reports regarding this new SOBER variant that is currently spreading in Germany and the United States.<br>This worm spreads by mass-mailing copies of itself to target recipients. Using social engineering techniques, it sends out an email supposedly sent by the soccer organization FIFA, informing recipients that they have won tickets for the upcoming FIFA World Cup 2006 in Germany.<br>Social engineering, a propagation technique that is widely utilized by most worm programs, invests largely on computer users' instinctive tendency to open email messages, execute attachments that are enticing and apparently harmless, and download and unknowingly open attractively named files.<br>TrendLabs is working to provide a more in depth analysis of this malware. Details will be posted shortly.<br>You may also check the following URL anytime to get T-Time information:<br>&raquo;<A HREF="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SOBER.S" >www.trendmicro.com/vinfo/virusen&middot;&middot;&middot;_SOBER.S</A><br><SMALL>--<br>The two most common elements in the universe are Hydrogen and stupidity.Harlan Ellison (1934 - )</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13312144</guid>
<pubDate>Mon, 02 May 2005 15:16:15 EDT</pubDate>
</item>

<item>
<title>Re: W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13312134</link>
<description><![CDATA[<A HREF="/useremail/u/411904"><b>gdm</b></A> : Trend shows this as "S" vs "O" &raquo;<A HREF="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SOBER.S" >www.trendmicro.com/vinfo/virusen&middot;&middot;&middot;_SOBER.S</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13312134</guid>
<pubDate>Mon, 02 May 2005 15:15:13 EDT</pubDate>
</item>

<item>
<title>W32.Sober.O@mm/Sober.P</title>
<link>http://www.dslreports.com/forum/remark,13312109</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : Currently a <B>Category 3</B> threat per Symantec: &raquo;<A HREF="http://www.symantec.com/avcenter/venc/data/w32.sober.o@mm.html" >www.symantec.com/avcenter/venc/d&middot;&middot;&middot;@mm.html</A><br><br>McAfee (W32/Sober.p@MM): &raquo;<A HREF="http://vil.nai.com/vil/content/v_133409.htm" >vil.nai.com/vil/content/v_133409.htm</A><br><br>F-Secure (RADAR Alert 2): &raquo;<A HREF="http://www.f-secure.com/v-descs/sober_p.shtml" >www.f-secure.com/v-descs/sober_p.shtml</A><br><br> <BLOCKQUOTE><SMALL>said by Symantec Security Response:</SMALL><HR>Initial analysis indicates the worm may arrive as an email attachment named account_info-text.zip, mail_info.zip, or our_secret.zip. The zip file contains the worm executable as the file Winzipped-Text_Data.txt, with a double extension of .exe or .pif.<HR></BLOCKQUOTE><br><SMALL>--<br>SMTP: Spam and Malware Transfer Protocol.  Also used on rare occasion to transmit e-mail messages.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13312109</guid>
<pubDate>Mon, 02 May 2005 15:10:41 EDT</pubDate>
</item>

</channel>
</rss>
