[windows2000] Fwd: Trend Micro Medium Risk Virus Alert - WORM_SOBER.AC

  • From: "Jim Kenzig http://kenzig.com" <jimkenz@xxxxxxxxxxxxxx>
  • To: thin@xxxxxxxxxxxxx, windows2000@xxxxxxxxxxxxx
  • Date: Thu, 6 Oct 2005 09:17:53 -0700 (PDT)


Trend Micro Newsletters Editor <> wrote:
Date: Thu, 6 Oct 2005 08:05:45 -0700
From: "Trend Micro Newsletters Editor" <editor@xxxxxxxxxxxxxxxxxxxxxxxxxx>
Subject: Trend Micro Medium Risk Virus Alert - WORM_SOBER.AC

Dear Trend Micro customer,

As of October 6, 2005 5:52 AM (Pacific Daylight Time; GMT-7:00), TrendLabs has 
declared a Medium Risk Virus Alert to control the spread of WORM_SOBER.AC. 
TrendLabs has received several infection reports indicating that this malware 
is spreading in USA, Japan, Australia, and Germany.

This worm propagates via email messages. It uses its own SMTP engine to send a 
copy of itself as an attachment to target email addresses. It gathers the said 
addresses from files with certain extensions on an affected system. Most of the 
files with the said extensions are related to the Web pages visited by an 
affected user. This worm gathers these types of files under the assumption that 
visited Web pages may contain text strings that refer to email addresses.

This worm may also send email messages written in German. 

Upon execution, it displays an error message. It drops a number of files, which 
aid its mass-mailing routine. The said routine consumes bandwidth that can slow 
down an affected network's processes.

TrendLabs will be releasing the following EPS deliverables:

TMCM Outbreak Prevention Policy 186
Official Pattern Release 2.879.00 
Damage Cleanup Template 661.04

For more information on WORM_SOBER.AC, you can visit our Web site at:
Contact av_query@xxxxxxxxxxxxxxxxxxxxxx for inquiries and to report infections 
in your region.

Other related posts:

  • » [windows2000] Fwd: Trend Micro Medium Risk Virus Alert - WORM_SOBER.AC