14 Jan 2003
A new worm, similar to Yaha, has been discovered in the wild, mainly in the UK and The Netherlands.
'SoBig-A' affects PCs running Windows 95 onwards. It contains an SMTP engine to mail itself out to all addresses on the PC, and can spread through network shares.
The worm is easy to spot, with just four subject headers and attached file names.
These are: 'Re: Movies', 'Re: Sample', 'Re: Document' and 'Re: Here is that sample'.
The infected attachments are: 'Document003.pif', 'Sample.pif', 'Untitled1.pif' and 'Movie_0074.pif'.
Carole Theriault, antivirus specialist at Sophos, said: "We're not getting a lot of new reports as companies have got patches in fast. Basically, if you block .pif files anyway you won't be troubled by this one."
The worm also attempts to download and run software from an external website.
All antivirus software vendors have a patch available.
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
Orange and Intel talk us through the ins and outs of their San Diego smartphone
Connect with V3.co.uk
The wrong printers, for the wrong tasks on the wrong contracts
Who leads the BI pack and who should we be watching out for?
Helpdesk/Service Analyst x 3 3 Month Contract...
French Technical support Specialist (2/3rd Line) CCNA...
ECM Project Manager - CMS, "Document Management", Web...
Skills - Presales, Consultant / Consultancy, Technical...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?