1. /
  2. Security Response/
  3. W32.Sobig.A@mm


Risk Level 2: Low

January 9, 2003
February 13, 2007 11:42:13 AM
Also Known As:
W32/Sobig [McAfee], WORM_SOBIG.A [Trend], W32/Sobig-A [Sophos], I-Worm.Sobig [KAV], Win32.Sobig [CA]
Systems Affected:
Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP

NOTE: Due to a decreased rate of submissions, Symantec Security Response has downgraded this threat from Category 3 to Category 2 as of June 13, 2003.

The W32.Sobig.A@mm worm sends itself to all the addresses it finds in the .txt, .eml, .html, .htm, .dbx, and .wab files. The email message has the following characteristics:
From: big@boss.com
Subject: The subject will be one of these:
  • Re: Movies
  • Re: Sample
  • Re: Document
  • Re: Here is that sample

Attachment: The attachment will be one of these:
  • Movie_0074.mpeg.pif
  • Document003.pif
  • Untitled1.pif
  • Sample.pif

Before W32.Sobig.A@mm sends the messages, it sends a message to an address at pagers.icq.com.

The worm also attempts to copy itself to the following folders on all the open network shares:
  • \Windows\All Users\Start Menu\Programs\StartUp
  • Documents and Settings\All Users\Start Menu\Programs\Startup

Note: Symantec Security Response has received reports of W32.Sobig.A@mm downloading and installing the Backdoor Trojan, Backdoor.Lala.

Antivirus Protection Dates

  • Initial Rapid Release version January 10, 2003
  • Latest Rapid Release version September 28, 2010 revision 054
  • Initial Daily Certified version January 10, 2003
  • Latest Daily Certified version September 28, 2010 revision 036
  • Initial Weekly Certified release date January 10, 2003
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Writeup By: Douglas Knowles

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
Internet Security Threat Report