W32/Sober.Y is an email worm. The worm will infect Windows systems and spreads through email.
The infected email carries a spoofed 'From' address picked up randomly from the infected system.
The subject of the infected mail will be any one of the following:
Your Password
smtp mail failed
Your IP was logged
Mail delivery failed
Registration Confirmation
You visit illegal websites
hi,_ive_a_new_mail_address
Paris_Hilton_&_Nicole_Richie
Spam: Registration Confirmation
The body of the infected mail will be any one of the following:
Account and Password Information are attached! ---
The Simple Life:
View Paris Hilton & Nicole Richie video clips , pictures & more ;)
Download is free until Jan, 2006!
Please use our Download manager.
Account and Password Information are attached!
***** Go to: http://www.{random}.com
***** Email: {random}.com
hey its me, my old address dont work at time. i dont know why?!
in the last days ive got some mails. i' think thaz your mails but im not sure!
plz read and check ...
cyaaaaaaa
This is an automatically generated Delivery Status Notification.
SMTP_Error []
I'm afraid I wasn't able to deliver your message.
This is a permanent error; I've given up. Sorry it didn't work out.
The full mail-text and header is attached
Dear Sir/Madam,
we have logged your IP-address on more than 30 illegal Websites.
Important:
Please answer our questions!
The list of questions are attached.
Yours faithfully,
Steven Allison
*** Federal Bureau of Investigation -FBI-
*** 935 Pennsylvania Avenue, NW, Room 3220
*** Washington, DC 20535
*** phone: (202) 324-3000
The infected attachment will be any one of the following;
Proland
Software is the developer of Protector Plus range of antivirus software
packages. Protector Plus 2007 is available for Windows Vista, Windows 95/98/Me, Windows
XP, Windows NT/2000/2003 servers and workstations, MS-Exchange 2000/2003, MS-DOS
and NetWare servers.
Protector Plus range of antivirus products
offer on-line virus detection and removal. All the packages have the ability
to detect and isolate all types of viruses, trojans, worms and other types
of malware.
Protector Plus antivirus software can detect and remove W32/Sober.Y Worm reliably.
These products are updated on a continuous basis and the latest upgrades
for all the platforms are made available for downloading from this site.