W32.Sobig.f@mm worm

August 19, 2003

A new worm W32.Sobig.f@mm is spreading rapidly around the world and is widespread at Virginia Tech. The code can infect Windows 95, 98, Me, NT, 2000, Windows XP. Users are strongly encouraged to run Live Update to get the latest virus definitions and scan for the worm.

Infection Methods

W32.Sobig.f@mm is a mass-mailing, network aware worm that sends itself to all e-mail addresses if finds in your address book. This worm also spoofs the sender's e-mail address and also can use the address 'admin@internet.com'. This worm will stop spreading on September 10, 2003.

Removal Tools

Recommended: Download the automatic removal tool for the Sobig.f worm.


You can find removal information for this worm at: http://securityresponse.symantec.com/avcenter/venc/data/w32.sobig.f@mm.removal.tool.htmlExternal Link

More information on this worm can be found at the following site:
http://www.sarc.com/avcenter/venc/data/w32.sobig.f@mm.htmlExternal Link