
W32.SOBER.I@MM
SPREADING IN THE WILD
Virus Name : W32.Sober.I@mm
Alias : I-Worm.Sober.I,
W32/Sober.J@mm, W32/Sober-I, WORM_SOBER.I,
Sober.I
Virus type : Internet
worm
Threat
level : Medium
Virus
details :
Sober.I is
a mass mailing worm uses e-mail addresses
collected from the system to distribute infected
mails. The worm uses its own SMTP engine to
spread. The worm is written in visual basic and
compressed with UPX.
Sober arrives
as an e-mail attachment with random message
subject and message body. The infected mail
attachment extension is chosen bat, .com, .exe,
.pif, or .scr. [ Example: anti_virusdoc.pif ].
The infected attachment will be in ZIP file too.
The
infected mail sample is given below

When the infected e-mail
attachment is executed, it displays the message
box "WinZip_Data_Module is missing
~Error: {<random number>}"
and copies itself to Windows system folder with
random exe file name. Then it modifies the
registry to load automatically on next startup.
The registry key modification is given below.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Sober.I worm downloads a
remote file in the infected system. The infected
mail will be in English or German. This worm is
also known as W32/Sober.j@MM, WORM_SOBER.I, and
W32/Sober.I. Sober.I worm appeared on 19th
November 2004.
How can I protect my
system?
Solo has incorporated W32.Sober.I@mm in its signature file to
protect users from this worm attack. Solo
antivirus registered users are already protected
from this worm. Make sure that you have installed
registered version of Solo Antivirus to protect
your system from all virus threats.
How
to remove this worm?
If
you are already infected with this worm, you can
remove it from your computer using Solo Antivirus
software. Solo antivirus can detect and
remove W32.Sober.I@mm safely. Use the
following link to Download 30 day trial
version of Solo antivirus
to
remove viruses from your computer.

Solo anti-virus not only
scans for all viruses, it contains a unique System
Integrity Checker to protect you from
New Internet Worms, Backdoors and
malicious VB, Java Scripts. It also
effectively removes all existing Internet Worms,
File viruses, malicious VBS, Java scripts,
Trojans, Backdoors, boot sector, partition table
and macro viruses.
You can
purchase Solo antivirus using the link 

|