1. Home
  2. Computing & Technology
  3. Antivirus Software

Sober.I worm

By , About.com Guide

Name:
Sober.I worm
Also known as:
W32.Sober.I@mm WORM_SOBER.I (Trend) W32/Sober.j@MM (McAfee) Sober.H@mm (Norman) Trojan.Win32.VB.qa (AVP)
Type:
Mass-mailing email worm that attempts to download and execute a remote file.
Discovered:
November 19, 2004
Email characteristics:
Sober.I is a mass-mailing email worm that sends itself in both German and English, depending on the infected users' operating system language. Sober.I uses is own SMTP engine to send itself to email address found on infected systems, spoofing the From address. Sober.I does not employ any exploits - the recipient must open the attachment in order to become infected.
System impact:
Sober.I drops two copies of itself to the Windows System directory composing filenames using the following strings:

sys | host | dir | explorer | win | run | log | 32 | disc | crypt | data | diag | spool | service | smss32 | x Sober.I modifies the following registry keys, pointing to the aforementioned files in order to load when Windows is started:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunSober.I attempts to download a file and execute it.

Manual removal:
Use updated antivirus software to detect and remove this threat.
Also see::

Symantec description
Sophos description
Trend Micro description
McAfee description
Explore Antivirus Software
About.com Special Features

Holiday Central

What to eat, where to go, fun things to do and how to save money on the perfect gifts. More >

Family Tech Center

Stay connected and entertained with reviews on tips on the latest HDTVs, cellphones and more. More >

  1. Home
  2. Computing & Technology
  3. Antivirus Software
  4. Latest Threats
  5. Sober.I worm

©2009 About.com, a part of The New York Times Company.

All rights reserved.