-
August 19th, 2003, 12:41 PM
#1
Heads Up**W32.Sobig.F@mm
Hi Guys..
W32.Sobig.F@mm
This is currently a Cat 2 on Symantec (at 11:40UTC)
No full info.. check for the latest info On Symantec
From Sophos the following ..
W32/Sobig-F is a worm that spreads via email and network shares.
W32/Sobig-F copies itself to the Windows folder as winppr32.exe and sets one of the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\TrayX
= <Windows folder>\winppr32.exe /sinc
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\TrayX
= <Windows folder<\winppr32.exe /sinc
The worm sends itself as an attachment to email addresses collected from various files on the victim's computer.
Cheers..
PAnda Software; gives this one a Amber Status - News here status at 13:22UTC
"Consumer technology now exceeds the average persons ability to comprehend how to use it..give up hope of them being able to understand how it works." - Me http://www.cybercrypt.co.nr
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|