W32/Sober.AA@mm
| W32/Sober.AA@mm |
Destructivity: |
| • Detected by virus detection files published: 11/22/2005 | • Type: Worm |
| • Virus characteristics first published: 11/22/2005 | • Spreading mechanism: Email |
| • Virus characteristics latest update: 10/30/2007 | • Overall risk: Medium |
| • Alias: CME ID 681, WORM_SOBER.AG, W32.Sober.X@mm, Win32.Sober.W, Sober.Y | • Payload: |
| • Infection type: Microsoft Windows 95/98/98 SE/ME/NT 4/2000/XP/2003/Vista |
| Virus type |
Spreading mechanism |
Destructivity and payload |
Additional descriptions |
Detection and removal |
||||||||||
Email characteristics:
When executed the worm will show a bogus error message ("Error in packed Header"), and then install itself on the system. It will then search available sources for email addresses to send itself to. Sober detects recipient country and will select English or German language depending on this. File system changes: Creates It will also create these empty files, which has the effect that older Sobervariants will not run: Registry changes: Adds the key HKCU\Software\Microsoft\Windows\CurrentVersion\Run _Windows = |
||||||||||||||