W32/Sober.N@mm
| W32/Sober.N@mm |
Destructivity: |
| • Detected by virus detection files published: 4/19/2005 | • Type: Worm |
| • Virus characteristics first published: 4/19/2005 | • Spreading mechanism: Email |
| • Virus characteristics latest update: 10/30/2007 | • Overall risk: Medium |
| • Alias: W32/Sober-M | • Payload: Terminates security processes |
| • Infection type: Microsoft Windows 95/98/98 SE/ME/NT 4/2000/XP/2003/Vista |
| Virus type |
Spreading mechanism |
Destructivity and payload |
Additional descriptions |
Detection and removal |
||||||||||
Email characteristics:
When the worm is first executed, it copies itself to a subfolder under the Windows folder, and starts to scan text files for email addresses. These addresses are then used as both sender and recipients for later infected mails. At the same time, the worm creates a text file containing garbage text and displays this using NOTEPAD. Emalis sent will have German or English text depending on the recipient address. File system changes: Creates Registry changes: Creates key HKCU\Software\Microsoft\Windows\CurrentVersion\Run _SystemCheck = |
||||||||||||||