FYI: AVERT Medium Threat Advisory: W32/Sober.r@MM -- The latest McAfee DAT is v4599

FYI: AVERT Medium Threat Advisory: W32/Sober.r@MM -- The latest McAfee DAT is v4599

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
FYI: AVERT Medium Threat Advisory: W32/Sober.r@MM -- The latest McAfee DAT is v4599 David H. Lipman 10-06-2005
Posted by David H. Lipman on October 6, 2005, 10:14 am
If you were  Registered and logged in, you could reply and use other advanced thread options
"AVERT Medium Threat Advisory: W32/Sober.r@MM

Advisory
This is a Medium Threat Advisory for W32/Sober.r@MM.

Justification
W32/Sober.r@MM has been deemed Medium due to prevalence.

Read About It
Information about W32/Sober.r@MM is located on VIL at:
http://vil.nai.com/vil/content/v_136390.htm

Detection
W32/Sober.r@MM was first discovered on October 5, 2005 and detection will be
added to the 4598 dat files (Release Date: October 5, 2005). The EXTRA.DAT IS
AVAILABLE.

If you suspect you have W32/Sober.r@MM, please submit a sample to
http://www.webimmune.net.

Risk Assessment Definition
For further information on the Risk Assessment and AVERT Recommended Actions
please see:
http://www.mcafeesecurity.com/us/security/resources/risk_assessment.htm

Best Regards,

McAfee AVERT - Anti Virus and Vulnerability Research, Analysis, and
Solutions visit us at www.avertlabs.com "


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Gabriele Neukam on October 6, 2005, 12:01 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
On that special day, David H. Lipman, (DLipman~nospam~@Verizon.Net)
said...

> If you suspect you have W32/Sober.r@MM, please submit a sample to
> http://www.webimmune.net.

Suspect? It was in a mail, titled "Bcc Ich habe Ihre Mail erhalten!" in
my inbox today. Supposedly I had sent a photo to the wrong person,
which sent it back (as if I had lost it). I had to ask Virustotal for
identification. Perhaps I should update my AVG a second time today.

(Checks with new definitions)
"Virus found!" (Sober.T) Ok, danger is identified, system is fine.


Gabriele Neukam

Gabriele.Spamfighter.Neukam@t-online.de


--
Ah, Information. A property, too valuable these days, to give it away,
just so, at no cost.

Posted by Fitz on October 6, 2005, 2:13 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Yeah...I got this one today too. Symantec CE caught and deleted it. The
mail subject was something about a password change. NOT!

***

> On that special day, David H. Lipman, (DLipman~nospam~@Verizon.Net)
> said...
>
>> If you suspect you have W32/Sober.r@MM, please submit a sample to
>> http://www.webimmune.net.
>
> Suspect? It was in a mail, titled "Bcc Ich habe Ihre Mail erhalten!" in
> my inbox today. Supposedly I had sent a photo to the wrong person,
> which sent it back (as if I had lost it). I had to ask Virustotal for
> identification. Perhaps I should update my AVG a second time today.
>
> (Checks with new definitions)
> "Virus found!" (Sober.T) Ok, danger is identified, system is fine.
>
>
> Gabriele Neukam
>
> Gabriele.Spamfighter.Neukam@t-online.de
>
>
> --
> Ah, Information. A property, too valuable these days, to give it away,
> just so, at no cost.



Posted by louise on October 6, 2005, 3:21 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
DLipman~nospam~@Verizon.Net says...
> "AVERT Medium Threat Advisory: W32/Sober.r@MM
>
> Advisory
> This is a Medium Threat Advisory for W32/Sober.r@MM.
>
> Justification
> W32/Sober.r@MM has been deemed Medium due to prevalence.
>
> Read About It
> Information about W32/Sober.r@MM is located on VIL at:
> http://vil.nai.com/vil/content/v_136390.htm
>
> Detection
> W32/Sober.r@MM was first discovered on October 5, 2005 and detection will be
> added to the 4598 dat files (Release Date: October 5, 2005). The EXTRA.DAT IS
> AVAILABLE.
>
> If you suspect you have W32/Sober.r@MM, please submit a sample to
> http://www.webimmune.net.
>
> Risk Assessment Definition
> For further information on the Risk Assessment and AVERT Recommended Actions
> please see:
> http://www.mcafeesecurity.com/us/security/resources/risk_assessment.htm
>
> Best Regards,
>
> McAfee AVERT - Anti Virus and Vulnerability Research, Analysis, and
> Solutions visit us at www.avertlabs.com "
>
>
>
Thanks for posting this. I just went onto my NOD32, which is set
to automatically update. I manually updated and lo and behold,
there was an update which had not been automatically downloaded as
yet.

Louise

Posted by David H. Lipman on October 6, 2005, 3:45 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


| Thanks for posting this. I just went onto my NOD32, which is set
| to automatically update. I manually updated and lo and behold,
| there was an update which had not been automatically downloaded as
| yet.
|
| Louise

You're welcome ;-)

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Similar ThreadsPosted
AVERT Low-Profiled Threat Notice: OSX/Inqtana.a February 20, 2006, 3:57 am
Re: Zonelabs Latest Free Firewall September 25, 2007, 11:52 pm
RE: Zonelabs Latest Free Firewall September 26, 2007, 8:28 am
Is this a false positive or bug with IE 6, McAfee 8/9/10 or both IE 6 and McAfee? June 26, 2006, 6:57 am
Re: Microsoft Security Advisory (912840): Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution December 29, 2005, 2:21 pm
Avert Labs Dat Release Notification: 4789 Emergency Dat Files Release June 20, 2006, 8:34 pm
FYI: Avert Labs Dat Release Notification: 4828 Emergency Dat Files Release August 13, 2006, 9:21 am
FYI: Avert Labs Dat Release Notification: 4899 Emergency Dat Files Release November 17, 2006, 7:35 pm
FYI: Avert Labs Dat Release Notification: 4915 Emergency Dat Files Release December 10, 2006, 8:25 am
FYI: Avert Labs Dat Release Notification: 4997 Emergency Dat Files Release March 30, 2007, 9:31 pm

The site map in XML format XML site map

Contact Us | Privacy Policy