Event ID - 37

Port No37
Service NameW32.Sober.L@mm
RFC Doc0
ProtocolTCP
DescriptionW32.Sober.L@mm is a mass-mailing worm that uses its own SMTP engine to spread. The email may be in either English or German. The email has a variable subject and attachment name. The attachment has a .zip file extension.
Reference LinkPort Number:37 Service Name:W32.Sober.L@mm Port:TCP
AttackAccording to Symantec

Removal using the W32.Sober Removal Tool
Symantec Security Response has developed a removal tool to clean the infections of W32.Sober.L@mm. Use this removal tool first, as it is the easiest way to remove this threat.
Manual Removal:
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
1.Disable System Restore (Windows Me/XP).
2.Update the virus definitions.
3.Restart the computer in Safe mode or VGA mode.
4.Run a full system scan and delete all the files detected asW32.Sober.L@mm.
5.Delete the value that was added to the registry.

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.