Sophos

VBS/Potok-A

Category
Type
What to do
Prevalence low high

Summary

 
Included in our products from September 2001 (3.49)
Detected by All Sophos products

Action

More Information

VBS/Potok-A is an email-aware worm which uses Microsoft Outlook to spread itself.

The worm sends an email to the first 50 addresses in the Outlook address book with the following characteristics:

Subject line: "New Generation of drivers."

Message body: "Microsoft has published new driver for all types Video Cards, compatible with Windows 95/98/NT/2000/XP. You can read about it in attachment document. Best wishes, Microsoft."

Attached filename: "\driver.doc***.vbs"
(where *** represents 46 spaces)

Note: this file name has 46 spaces before its final .vbs extension in an attempt to fool users into thinking it is a Word document.

On a Windows NT machine using the NTFS filing system, the virus will hide part of its code in the Alternate Data Streams associated with the file ODBC.INI in the Windows subdirectory.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer