W32/Sober.N@mm

Download VIRUSfighter NOW
W32/Sober.N@mm Destructivity: Spreading: Overall risk:
  
• Detected by virus detection files published: 4/19/2005 • Type: Worm
• Virus characteristics first published: 4/19/2005 • Spreading mechanism: Email
• Virus characteristics latest update: 10/30/2007 • Overall risk: Medium
• Alias: W32/Sober-M • Payload: Terminates security processes
• Infection type: Microsoft Windows 95/98/98 SE/ME/NT 4/2000/XP/2003/Vista  

Virus type Spreading
mechanism
Destructivity
and payload
Additional
descriptions
Detection
and removal
Email characteristics:
  • Subject: I've_got your EMail on my_account! or FwD: Ich bin's nochmal
  • Body:

    Hello,
    First, Very Sorry for my bad English.
    Someone is sending your private e-mails on my address.
    It's probably an e-mail provider error!
    At time, I've got over 10 mails on my account, but the recipient are you.
    I have copied all the mail text in the windows text-editor for you & zipped then.
    Make sure, that this mails don't come in my mail-box again.

    Or

    Verdammt,,,,
    ich hatte vergessen Dir meinen Text mitzuschicken.
    Aber bitte nicht woanders darueber Reden, ich wuerde mich dann zu Tode
    blamieren!
    Ich melde mich.
    Bis bald ;)

  • Attachment: your_text.zip or Private-Texte.zip

When the worm is first executed, it copies itself to a subfolder under the Windows folder, and starts to scan text files for email addresses. These addresses are then used as both sender and recipients for later infected mails. At the same time, the worm creates a text file containing garbage text and displays this using NOTEPAD. 

Emalis sent will have German or English text depending on the recipient address.

File system changes:

Creates \config\system\zipped.wrm
Creates \config\system\maddys.xyz
Creates \config\system\services.exe
Creates mail.document.Datex-packed.txt in a TEMP folder
Creates \nonrunso.ber
Creates \langeinf.lin
Creates \adcmmmmq.hjg
Creates \xcvzpokd.tqa

Registry changes:

Creates key HKCU\Software\Microsoft\Windows\CurrentVersion\Run _SystemCheck = \config\system\services.exe
Creates key HKLM\Software\Microsoft\Windows\CurrentVersion\Run " SystemCheck" = \config\system\services.exe
 

# - A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z
To protect and serve, VirusFighter