W32/Sober.R@mm

Download VIRUSfighter NOW
W32/Sober.R@mm Destructivity: Spreading: Overall risk:
  
• Detected by virus detection files published: 10/6/2005 • Type: Worm
• Virus characteristics first published: 10/6/2005 • Spreading mechanism: Email
• Virus characteristics latest update: 12/2/2005 • Overall risk: High
• Alias: CME-151, W32.Sober.Q@mm, W32/Sober.Y.worm, W32/Sober-O, WORM_SOBER.AC • Payload: Terminates AV processes.
• Infection type: Microsoft Windows 95/98/98 SE/ME/NT 4/2000/XP/2003/Vista  

Virus type Spreading
mechanism
Destructivity
and payload
Additional
descriptions
Detection
and removal
Email characteristics:
  • Subject: Your new Password
  • Body:

    Your password was successfully changed!

    Please see the attached file for detailed information.

  • Attachment: pword_change.zip

When executed the worm will show a bogus error message ("CRC Header must be $7ff8"), and then install itself on the system. It will then search available sources for email addresses to send itself to.

Sober detects recipient country and will select English or German language depending on this. English text is shown here.

File system changes:

Creates <WINDOWS>\ConnectionStatus\services.exe        (the worm itself)
Creates <WINDOWS>\ConnectionStatus\netslot.nst            (MIME-encoded copy)
Creates <WINDOWS>\ConnectionStatus\socket.dli              (gathered email adresses) 

It will also create these empty files, which has the effect that older Sobervariants will not run:
Creates <WINDOWS>\System32\bbvmwxxf.hml    
Creates <WINDOWS>\System32\gdfjgthv.cvq
Creates <WINDOWS>\System32\bbvmwxxf.hml
Creates <WINDOWS>\System32\langeinf.lin
Creates <WINDOWS>\System32\nonrunso.ber
Creates <WINDOWS>\System32\rubezahl.rub
Creates <WINDOWS>\System32\seppelmx.smx

Registry changes:

Adds the key HKCU\Software\Microsoft\Windows\CurrentVersion\Run _WinINet    = <WINDOWS>\ConnectionStatus\services.exe
Adds the key HKLM\Software\Microsoft\Windows\CurrentVersion\Run WinINet    = <WINDOWS>\ConnectionStatus\services.exe

Files types searched for emailaddresses:

pmr
phtm
stm
slk
inbox
imb
csv
bak
imh
xhtml
imm
imh
cms
nws
vcf
ctl
dhtm
cgi
pp
ppt
msg
jsp
oft
vbs
uin
ldb
abc
pst
cfg
mdw
mbx
mdx
mda
adp
nab
fdb
vap
dsp
ade
sln
dsw
mde
frm
bas
adr
cls
ini
ldif
log
mdb
xml
wsh
tbb
nbsp
abx
abd
adb
pl
rtf
mmf
doc
ods
nch
xls
nsf
txt
wab
eml
hlp
mht
nfo
php
asp
shtml
dbx
# - A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z
To protect and serve, VirusFighter