About
Subscribe
  • Home
  • /
  • Internet
  • /
  • Sophos warns of bilingual bogus Microsoft virus fix

Sophos warns of bilingual bogus Microsoft virus fix

Sober-D worm poses as zipped security patch
By Netxactics
Johannesburg, 09 Mar 2004

NetXactics, local Sophos distributor, has announced that Sophos researchers have warned customers to be wary of a bilingual bogus Microsoft virus fix, which claims to protect against the MyDoom worm.

The W32/Roca-A worm (also known as W32/Sober-D), has already been sighted several times in the wild, and arrives in the form of an e-mail with the following characteristics:

Subject line:
Microsoft : Please Read!

Message text:
New MyDoom Virus Variant Detected!

A new variant of the W32.Mydoom (W32.Novarg) worm spread rapidly through the . Anti-virus vendor Central Command claims that 1 in 45 e-mails contains the MyDoom virus. The worm also has a backdoor Trojan capability. By default, the Trojan component listens on port 13468.

Protection

Please download this digitally signed attachment. This Update includes the functionality of previously released patches.

Attached to the e-mail is a ZIP file, which contains the W32/Roca-A worm. If the worm determines it is being sent to a German e-mail address, it presents itself in German language instead of English.

"As the Sober.C worm has shown in recent months, viruses which use more than one language when communicating with users can be more successful at not raising suspicion," said Brett Myroff, CEO of NetXactics. "Companies should ensure their anti-virus is automatically updated, and screen for dangerous filetypes at their e-mail perimeter."

Share

NetXactics

NetXactics is a South African-based company, focused on the provision of security solutions. It is the sole distributor in Sub-Saharan Africa for UK-based Sophos Plc, one of the leaders in the provision of anti-virus and anti-spam software for the corporate environment. For more information, visit NetXactics at www.netxactics.co.za.

Sophos

Sophos is one of the world`s largest specialist developers of anti-virus and anti-spam software. Headquartered in the UK, the company designs solutions specifically to protect businesses and organisations, including large corporations, banks and governments, from viruses and spam.