FYI Jim Trend Micro Newsletters Editor <> wrote: Date: Thu, 6 Oct 2005 08:05:45 -0700 From: "Trend Micro Newsletters Editor" <editor@xxxxxxxxxxxxxxxxxxxxxxxxxx> Subject: Trend Micro Medium Risk Virus Alert - WORM_SOBER.AC Dear Trend Micro customer, As of October 6, 2005 5:52 AM (Pacific Daylight Time; GMT-7:00), TrendLabs has declared a Medium Risk Virus Alert to control the spread of WORM_SOBER.AC. TrendLabs has received several infection reports indicating that this malware is spreading in USA, Japan, Australia, and Germany. This worm propagates via email messages. It uses its own SMTP engine to send a copy of itself as an attachment to target email addresses. It gathers the said addresses from files with certain extensions on an affected system. Most of the files with the said extensions are related to the Web pages visited by an affected user. This worm gathers these types of files under the assumption that visited Web pages may contain text strings that refer to email addresses. This worm may also send email messages written in German. Upon execution, it displays an error message. It drops a number of files, which aid its mass-mailing routine. The said routine consumes bandwidth that can slow down an affected network's processes. TrendLabs will be releasing the following EPS deliverables: TMCM Outbreak Prevention Policy 186 Official Pattern Release 2.879.00 Damage Cleanup Template 661.04 For more information on WORM_SOBER.AC, you can visit our Web site at: http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SOBER.AC Contact av_query@xxxxxxxxxxxxxxxxxxxxxx for inquiries and to report infections in your region.