W32.Sober.G@mm

Risk Level 2: Low

Printer Friendly Page

Discovered: May 13, 2004
Updated: May 15, 2004 4:15:55 AM
Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows NT, Windows 2000

W32.Sober.G@mm is a mass-mailing worm that uses its own SMTP engine to spread itself. The subject of the email varies, and it will be in either English or German. The email sender address is spoofed.

The name of the email attachment varies, and it will have a .bat, .com, .pif, .scr, or .zip file extension. It may also have double extension.

This threat is written in the Microsoft Visual Basic programming language and is compressed with UPX.

Antivirus Protection Dates

  • Initial Rapid Release version pending
  • Latest Rapid Release version pending
  • Initial Daily Certified version pending
  • Latest Daily Certified version pending
  • Initial Weekly Certified release date pending

Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Search by name
Example: W32.Beagle.AG@mm
ThreatCon Widget