









 | W32/Sober.A| Name | W32/Sober.A | | Aliases | W32/Sober@MM, W32.Sober@mm, W32/Sober-A., sober, sober.a | | Discovered on | October 24, 2003 |
Virus Information - W32/Sober.A:
W32/Sober.A is a mass mailing worm. This
worm will infect Windows systems. This worm spreads through email.
The subject and the body of the infected
mail will be random text. In some cases the infected mail purports to have
originated from an antivirus company.
The infected attachment will be any one of the following extensions;
.scr
.com
.bat
.pif
.exe
Upon execution of the infected attachment, it displays a dialog
box with a message, "File not complete!". After this, the worm
copies itself as
similare.exe
drv.exe
systemchk.exe
in the Windows\System folder. The worm modifies registry at
the following location to load itself during each startup.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
The worm collects the available email addresses from the infected
system and stores all the collected email addresses in a file called MEDIA.DLL,
in the Windows\System\MACROMED\HELP folder. After this the worm mails itself
to these addresses using its own SMTP engine.

|