If you should receive an e-mail that looks like this:
DELETE IT IMMEDIATELY and DO NOT CLICK ANY OF THE LINKS IN THE MESSAGE!
This scam has been out there about a month now, mostly in Europe and in Newsgroups, but I've started coming across it on the computers of local clients. Be advised: Microsoft DOES NOT ISSUE E-MAIL UPDATE ALERTS.
Also making the rounds is "SOBER", which will appear to be an e-mail from someone you know warning you of a worm.
Quote:New Worm Spreads By Posing As Virus Fix
Wed Oct 29, 3:35 AM ET Add Technology - TechWeb to My Yahoo!
A new worm is making the rounds, which poses as a virus fix to tempt users to open the attached file.
The worm, dubbed Sober by security firms, spreads via e-mail, contains a host of different subject lines in both German and English, and delivers its payload via an attached file that claims to be a fix for a bogus worm.
Among the subject lines seen in copies of the worm are those that prey upon users' fears of security problems, such as "A worm is on your computer," "You have sent me a virus," and "New Sobig-Worm variation (please read)."
The attached file can be disguised with .exe, .scr, .bat, or .pif extensions. Opening the file propagates the worm to the target PC.
Sober has had its greatest impact in Europe, particularly the U.K. and Germany, and is currently considered a low or medium risk by most security firms. Symantec, for instance, ranks it as a '2' in its 1 through 5 scale.
The Article
Quote:Wednesday 29th October 2003
Sober virus on popular European tour
PC PRO OnLine 16:28
The Sober virus - discovered on Monday - now accounts for 50 per cent of reported incidents, warns Sophos, and is continuing its rise throughout the UK and Germany.
Carole Theriault, security consultant at Sophos, said that on Monday, Sober reports accounted for 20 per cent, but that level has now reached 50 per cent.
'It's a fairly obvious worm,' she said, but she had an idea why the virus was still spreading. 'These worms play on computer users' fears and can be difficult to spot with email subject lines and messages chosen at random.'
The subject lines and messages are either in German or English, depending on the domain of the recipient's email address, but Theriault suspected the virus originated in Germany, as the English is so poor, while the German versions are more coherent.
One of the messages praises the writer of the SoBig virus: ''Congratulations!! Your Sobig Worms are very good!!!You are a very good programmer! Yours faithfully Odin alias Anon,' it reads
It spreads by sending itself on to addresses found on the victim's computer, but is not otherwise malicious.
Theriault also warned that without updated antivirus software, the worm can be very difficult to remove.
It installs itself using two files that watch over each other, so if you try to delete one of them, the other automatically reinstalls it. 'You've got to try and stop them both together,' she said, 'which makes it very difficult to delete manually.'
For more information, visit the
SOPHOS website
.
Get, use, and keep updated, a reputable Anti-Virus program.