1. Home
  2. Computing & Technology
  3. Antivirus Software

Sober.T worm

By Mary Landesman, About.com

Name:
Sober.T worm
Also known as:
W32/Sober.Z.worm (Panda), W32/sober.T@MM (McAfee), W32.Sober.R@mm (Symantec), W32/sober.T@mm (F-Prot, Command), W32/Sober-P (Sophos), Win32.Sober.T@mm (BitDefender), I-Worm.Sober.V (VirusBuster)
Type:
Worm
Discovered:
November 14, 2005
Email characteristics:
Sober.T arrives in an email message that may be in either German or English language, depending on the recipient's domain. The Sober.T email carries an attachment with one of the following names:
registration.zip
Word-Text.zip

The zip file contains an executable named 'Word-Text_packedList.exe'

System Impact::
If the infected executable is run, Sober.T will create the following files:

C:\Windows\hjgerhds.exe
C:\Windows\ConnectionStatus\Microsoft\services.exe
C:\Windows\System32\gdfjgthv.cvq
C:\Windows\System32\langeinf.lin
C:\Windows\System32\nonrunso.ber
C:\Windows\System32\System32\rubezahl.rub
C:\Windows\System32\System32\runstop.rst

Note: The exact name of the Windows directory and System directory may vary depending on the operating system.

Sober.T modifies the HKCU and HKLM Registry Run keys in order to load when Windows is started:

'WinCheck =C:\Windows\ConnectionStatus\Microsoft\services.exe'

Removal Notes:
Use up-to-date antivirus software to identify the worm's files. Either allow the antivirus software to delete these files, or they can be manually deleted. If opting for manual deletion, be sure to also remove the registry modifications made by the worm.
Explore Antivirus Software
About.com Special Features

Stay connected and entertained with reviews on tips on the latest HDTVs, cellphones and more. More >

Easy ways to connect two computers for networking purposes. More >

  1. Home
  2. Computing & Technology
  3. Antivirus Software
  4. Latest Threats
  5. Sober.T Worm

©2009 About.com, a part of The New York Times Company.

All rights reserved.