- Servers
- Desktops
- Laptops
- Tablet PCs
- PDAs
- Smart phones
- Digital cameras
- Camcorders
- Printers & multifunction devices
- Scanners
- Copiers
- Monitors & projectors
- Hard drives & burners
- Peripherals
- Productivity
- Accounting & finance
- Data management
- Graphics & publishing
- Web publishing
- Operating systems
- Security & utilities
- Downloads & trial software
- Handheld software
- Instant messaging
- Cell phones & plans
- Voice over Internet
- Telephones
- Routers & gateways
- Wireless networking
- Network adapters
- Internet access
- Web hosting
- Domain search
- Hotspot Zone
- Desktops
- Laptops
- Servers and storage
- PDAs
- Cell phones
- Monitors & projectors
- Printers
- Networking and wireless
- Security and utility software
- Productivity software
- Access, hosting, and services
- All business buying guides
CNET Security Center: Your complete source of antivirus and Internet security information.
Virus uses both English and German text to lure victims.
By Robert Vamosi (May 2, 2005)
What it does: Sends e-mail in either German or English
Means of transmission: E-mail
How to recognize: German version involves World Cup events; English version mentions password information
Who is at risk: Windows users
How it works
Sober.p arrives in an e-mail message. The sender address is spoofed, and the body text, either in German or in English, varies. The attachment file usually ends in .zip:
account_info.zip
autoemail-text.zip
LOL.zip
Fifa_Info-Text.zip
mail_info.zip
okTicket-info.zip
our_secret.zip
PassWort-Info.zip
Within the ZIP file is a file named winzipped-text_data.txt [several blank spaces].pif
According to security vendor Trend Micro, once executed, Sober.p creates the following files in the %Windows%\Connection Wizard\Status folder:
csrss.exe
services.exe
smss.exe
It also creates the following versions of itself:
packed1.sbr
packed2.sbr
packed3.sbr
And adds the following files, which contain email-related data:
sacri1.ggg
sacri2.ggg
sacri3.ggg
voner1.von
voner2.von
voner3.von
Sober also creates the following files in the following directories:
%Windows%\Connection Wizard\Status\fastso.ber
%System%\adcmmmmq.hjg
%System%\langeinf.lin
%System%\nonrunso.ber
%System%\seppelmx.smx
%System%\xcvfpokd.tqa
In order for the virus to run every time the infected machine is rebooted, the virus adds the following to the system Registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Run "_WinStart" = C:\WINDOWS\Connection Wizard\Status\services.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run " WinStart" = C:\WINDOWS\Connection Wizard\Status\services.exe
Removal
A few antivirus software companies have updated their signature files to include this worm. This will stop the infection upon contact and in some cases will remove an active infection from your system. For more information, see F-Secure, McAfee, Sophos (as Sober.n), Symantec (as Sober.o), and Trend Micro (as Sober.s).
