
![]() | W32/Sober.C
W32/Sober.C is a mass mailing worm. It is a variant of W32/Sober.A. This worm will infect Windows systems. This worm spreads through email. The worm arrives with a random subject within its list in English or German languages. The infected attachment will be any one
of the following; The body of the infected mail will be randomly composed in either English or German languages. Upon execution of the infected attachment, it displays a dialog box with a fake runtime error message containing "<worm_file_name> has caused an unknown error". After this, the worm creates similar copies of itself with a random file name and extensions in the Windows\System folder. The worm modifies registry at the following location to load itself during each startup. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
The worm stores all the collected email
addresses in a file called savesyss.dll, under the Windows\System
folder. After this the worm mails itself to these email addresses using
its own SMTP engine. |
Copyright © 2005 Proland
Software.All rights reserved