W32/Sober.R@mm
| W32/Sober.R@mm |
Destructivity: |
| • Detected by virus detection files published: 10/6/2005 | • Type: Worm |
| • Virus characteristics first published: 10/6/2005 | • Spreading mechanism: Email |
| • Virus characteristics latest update: 12/2/2005 | • Overall risk: High |
| • Alias: CME-151, W32.Sober.Q@mm, W32/Sober.Y.worm, W32/Sober-O, WORM_SOBER.AC | • Payload: Terminates AV processes. |
| • Infection type: Microsoft Windows 95/98/98 SE/ME/NT 4/2000/XP/2003/Vista |
| Virus type |
Spreading mechanism |
Destructivity and payload |
Additional descriptions |
Detection and removal |
||||||||||
Email characteristics:
When executed the worm will show a bogus error message ("CRC Header must be $7ff8"), and then install itself on the system. It will then search available sources for email addresses to send itself to. Sober detects recipient country and will select English or German language depending on this. English text is shown here. File system changes: Creates <WINDOWS>\ConnectionStatus\services.exe (the worm itself) It will also create these empty files, which has the effect that older Sobervariants will not run: Registry changes: Adds the key HKCU\Software\Microsoft\Windows\CurrentVersion\Run _WinINet = <WINDOWS>\ConnectionStatus\services.exe Files types searched for emailaddresses: pmrphtm stm slk inbox imb csv bak imh xhtml imm imh cms nws vcf ctl dhtm cgi pp ppt msg jsp oft vbs uin ldb abc pst cfg mdw mbx mdx mda adp nab fdb vap dsp ade sln dsw mde frm bas adr cls ini ldif log mdb xml wsh tbb nbsp abx abd adb pl rtf mmf doc ods nch xls nsf txt wab eml hlp mht nfo php asp shtml dbx |
||||||||||||||