W32/Sober.D@mm is a new variant of the Sober family of mass-mailing worms that was first detected by FRISK Software virus analysts late on sunday evening, 7 March 2004.
Previous Sober variants gained their largest distribution in Germany and this newest one is no exception. As was with its predecessors, e-mails carrying this variant are spreading in both German and English language versions.
The e-mails carrying W32/Sober.D@mm falsely claim to be from Microsoft and to provide an update to protect users from a new version of Mydoom. On infection Sober.D displays a fake message stating that the patch has been successfully installed. The worm then scans the infected computer's hard drive for files with pre-defined filename extentions. It harvests e-mail addresses from these files and susequently spreads further by sending itself to these harvested addresses using its own SMTP engine.
The English language e-mail contains minor variations on the following:
The German language e-mail contains minor variations on the following:
Users are advised to update their virus signature files and make sure they have the latest versions of F-Prot Antivirus installed on their computers.
After updating the virus signature files, users should scan their whole system with the F-Prot Antivirus OnDemand scanner to ensure that their computer security was not compromised before the virus signature files were updated.
The latest versions of F-Prot Antivirus detect W32/Sober.D@mm using virus signature files dated 8 March 2003 or later.