Sober Worm Spreads

執筆者
Jay Munro
Jay Munro
Published: Nov 6, 2003
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

This summers crop of mass mailing DCOM- and RPC-exploiting worms has made “get the patch” a mantra for most savvy users. However, the latest worm throws that reliable action into the gray area, especially for novice users. Thats because the latest batch of worms are posing as e-mailed fixes from Microsoft.

W32/Dumaru (several variants),and W32/Swen.A, are multi-level or blended threats that hit your email box demanding that you “Install this patch immediately”, among other subject lines. If your antivirus software is a little out of date, and doesnt catch these recent threats, you could be in trouble since these worms will disable most AV processes. The latest up and coming threat is W32.Sober, which appears to have originated in Germany and is quickly spreading through Europe and the US.

While business and consumers deal with the latest virus scourge, several sources reported last week that US State department, of all places, got hit Sept 24th. An unclassified section of the State Departments intranet system was shut down for around nine hours by the W32/Welchia worm. W32/Welchia, first reported in August, is an almost altruistic worm, disabling and deleting MSBlast.exe from a previously W32/Blaster.worm infected machine, and installing itself. It then attempts to download and update the system with Microsofts DCOM/RPC vulnerability patch, preventing re-infection by Blaster.

Non-viral, malicious software (malware) in the form of spyware (keyboard loggers, URL trackers), adware (browser plug-ins that track and pop up advertising) and porn dialers (dials 900 or foreign long distance numbers at exorbitant rates) are on the increase and just as troublesome as viruses.

McAfee and Symantec have recently added to their latest antivirus products, McAfee VirusScan 8 and Norton AntiVirus 2004 detection for these “extended threats”. The fledgling detection and elimination procedures found in these products may be less sophisticated than spyware detectors like Lava Softwares Adaware and SpyBot Search and Destroy, but with their wider coverage of consumer markets they should help alleviate the larger infection problem.

Microsoft made two announcements of note: The release of the Update Rollup for Windows XP, and that they are going from their weekly patch release schedule to a monthly one. This is a relief to patch inundated IT departments that need to test all code before rollout to their users. Microsoft said however, they will still release emergency updates when needed.

At press time, we started tracking a new worm, W32/Mimail.C and its varieties. This destructive worm is currently spreading quickly, and has been added to most venders virus definition lists. We will be detailing the threat and fix next week.

Advertisement

/zimages/4/28571.gifTo read the full PC Magazine Newsletter,click here.

Jay Munro

Jay Munro

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。