Type: Win32 worm
Date: 12 October 2004
A virus identity (IDE) file which provides protection is
available now from the Sophos website, and will be incorporated
into the November 2004 (3.87) release of Sophos Anti-Virus.
Customers using Enterprise Manager, PureMessage and any of the
Sophos small business solutions will be automatically protected
at their next scheduled update.
At the time of writing, Sophos has received a small number of
reports of this worm from the wild.
Note: The IDE for W32/Snoop-A issued on 30 September 2004 at
11:15 (GMT) included detection for W32/Sdbot-PU,
Troj/Dloader-TO, Troj/Bckdr-CIC, Troj/Bancos-Z,
W32/Evaman-F, W32/Forbot-AQ and W32/Rbot-LI. The IDE has been
updated to enhance detection of W32/Forbot-AQ.
Information about W32/Snoop-A can be found at:
This IDE file also includes detection for:
Download the IDE file from:
Download all the IDE files available for the current version of
Sophos Anti-Virus in a single compressed file. The file is
available in two formats:
Read about how to use IDE files at