W32/Sober.AA@mm

Download VIRUSfighter NOW
W32/Sober.AA@mm Destructivity: Spreading: Overall risk:
  
• Detected by virus detection files published: 11/22/2005 • Type: Worm
• Virus characteristics first published: 11/22/2005 • Spreading mechanism: Email
• Virus characteristics latest update: 10/30/2007 • Overall risk: Medium
• Alias: CME ID 681, WORM_SOBER.AG, W32.Sober.X@mm, Win32.Sober.W, Sober.Y • Payload:
• Infection type: Microsoft Windows 95/98/98 SE/ME/NT 4/2000/XP/2003/Vista  

Virus type Spreading
mechanism
Destructivity
and payload
Additional
descriptions
Detection
and removal
Email characteristics:
  • Subject: Several different English or German texts
  • Body:

    Several different English or German texts

  • Attachment: A zip file, containing a file called "file-packed_datainfo.exe"

When executed the worm will show a bogus error message ("Error in packed Header"), and then install itself on the system. It will then search available sources for email addresses to send itself to.

Sober detects recipient country and will select English or German language depending on this.

File system changes:

Creates \WinSecurity\services.exe         (the worm itself)
Creates \WinSecurity\smss.exe             (same)
Creates \WinSecurity\csrss.exe             (same)
Creates \WinSecurity\mssock1.dli        (gathered email adresses) 
Creates \WinSecurity\mssock2.dli        (same) 
Creates \WinSecurity\mssock3.dli        (same)
Creates \WinSecurity\winmem1.ory      (same)
Creates \WinSecurity\winmem2.ory      (same)
Creates \WinSecurity\winmem3.ory      (same) 
Creates \WinSecurity\socket1.ifo           (MIME-encoded copy) 
Creates \WinSecurity\socket1.ifo           (same) 
Creates \WinSecurity\socket1.ifo           (same)
Creates \WinSecurity\starter.run            (empty file)

It will also create these empty files, which has the effect that older Sobervariants will not run:
Creates \System32\bbvmwxxf.hml    
Creates \System32\langeinf.lin
Creates \System32\nonrunso.ber
Creates \System32\rubezahl.rub
Creates \System32\filesms.fms
Creates \System32\runstop.rst

Registry changes:

Adds the key HKCU\Software\Microsoft\Windows\CurrentVersion\Run _Windows    = \WinSecurity\services.exe
Adds the key HKLM\Software\Microsoft\Windows\CurrentVersion\Run Windows    = \WinSecurity\services.exe

# - A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z
To protect and serve, VirusFighter