<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>All About Worms &#187; Sober Worm</title>
	<atom:link href="http://www.allaboutworms.com/category/computer-worms/sober-worm/feed" rel="self" type="application/rss+xml" />
	<link>http://www.allaboutworms.com</link>
	<description></description>
	<lastBuildDate>Fri, 03 Feb 2012 15:00:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>What is a Sober Worm?</title>
		<link>http://www.allaboutworms.com/what-is-a-sober-worm</link>
		<comments>http://www.allaboutworms.com/what-is-a-sober-worm#comments</comments>
		<pubDate>Mon, 20 Dec 2010 20:15:44 +0000</pubDate>
		<dc:creator>Michelle</dc:creator>
				<category><![CDATA[Computer Worms]]></category>
		<category><![CDATA[Sober Worm]]></category>
		<category><![CDATA[Worm Removal Tool]]></category>
		<category><![CDATA[computer worm]]></category>
		<category><![CDATA[free worm remover]]></category>
		<category><![CDATA[malicious software removal tool]]></category>
		<category><![CDATA[trojan worm]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://www.allaboutworms.com/?p=3655</guid>
		<description><![CDATA[According to Symantec, the Sober Worm then uses its own SMTP engine to send itself to all the email addresses it finds. The subject in the email may be any of the following. . . 
]]></description>
			<content:encoded><![CDATA[<p>Sober Worm (W32.Sober@mm) is a computer worm that was discovered on October 24, 2003. Although the Sober Worm was listed as &#8220;low&#8221; level or &#8220;risk level 2,&#8221; this computer worm still caused a number of problems with computer systems ranging from slow running systems to slow running software programs. </p>
<p>Sober Worm was also known as: W32/Sober@MM [McAfee], I-Worm.Sober [Kaspersky], W32/Sober-A [Sophos], WORM_SOBER.A [Trend]. Sober [F, W32/Sober.A@mm [Frisk], W32/Sober.A [Norman], Win32/Sober.A [Eset], Win32.Sober.A [Computer Associ. It affected Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, and Windows XP. This mass-mailing worm used its own SMTP engine to spread itself. The subject of the email varied, and it was in either English or German. </p>
<p>The name of the email attachment varied as well, and it had a .bat, .com, .exe, .pif, or .scr file extension. The threat was written in the Microsoft Visual Basic programming language and it was compressed with UPX. When W32.Sober@mm is first run, it displayed a fake error message &#8220;File not complete!&#8221; After this, it created several copies of itself to the %System% directory using variable filenames such as:</p>
<p>antiv.exe<br />
driver.exe<br />
driverini.exe<br />
drv.exe<br />
expoler.exe<br />
filexe.exe<br />
hlp16.exe<br />
lssas.exe<br />
qname.exe<br />
spoole.exe<br />
swchost.exe<br />
syshost.exe<br />
systemchk.exe<br />
systemini.exe<br />
winchk.exe<br />
winlog32.exe<br />
winreg.exe</p>
<p>After the Sober Worm infects a computer, it retrieves email addresses from local files and stores them in the Media.dll.file. According to Symantec, it then uses its own SMTP engine to send itself to all the email addresses it finds. The subject in the email may be any of the following:</p>
<p>The email subject is one of the following:</p>
<p>Neuer Virus im Umlauf!<br />
Sie versenden Spam Mails (Virus?)<br />
Ein Wurm ist auf Ihrem Computer!<br />
Langsam reicht es mir<br />
Sie haben mir einen Wurm geschickt!<br />
Hi Schnuckel was machst du so ?<br />
VORSICHT!!! Neuer Mail Wurm<br />
Re: Kontakt<br />
RE: Sex<br />
Sorry, Ich habe Ihre Mail bekommen<br />
Hi Olle, lange niks mehr gehört!<br />
Re: lol<br />
Viurs blockiert jeden PC (Vorsicht!)<br />
Überraschung<br />
Ich habe Ihre E-Mail bekommen !<br />
Jetzt rate mal, wer ich bin !?<br />
Neue Sobig Variante (Lesen!!)<br />
Back At The Funny Farm<br />
Ich Liebe Dich<br />
New internet virus!<br />
You send spam mails (Worm?)<br />
A worm is on your computer!<br />
Now, it&#8217;s enough<br />
You have sent me a virus!<br />
Hi darling, what are you doing now?<br />
Be careful! New mail worm<br />
Re: Contact<br />
RE: Sex<br />
Sorry, I&#8217;ve become your mail<br />
Hey man, long not see you<br />
Viurs blocked every PC (Take care!)<br />
Surprise<br />
I&#8217;ve become your mail!<br />
Advise who I am!<br />
New Sobig-Worm variation (please read)<br />
I love you (I&#8217;m not a virus!)</p>
<p>The email also included an attachment. It could/could have been any of the following:</p>
<p>AntiVirusDoc.pif<br />
Check-Patch.bat<br />
Screen_Doku.scr<br />
Removal-Tool.exe<br />
Perversionen.scr<br />
Bild.scr<br />
robot_mail.scr<br />
RobotMailer.com<br />
Privat.exe<br />
AntiTrojan.exe<br />
Mausi.scr<br />
NackiDei.com<br />
Anti-Sob.bat<br />
security.pif<br />
Funny.scr<br />
Liebe.com<br />
Odin_Worm.exe<br />
anti_virusdoc.pif<br />
check-patch.bat<br />
removal-tool.exe<br />
screen_doc.scr<br />
potency.pif<br />
perversion.scr<br />
pic.scr<br />
CM-Recover.com<br />
playme.exe<br />
robot_mailer.pif<br />
little-scr.scr<br />
love.com<br />
nacked.com<br />
Hengst.pif<br />
schnitzel.exe<br />
anti-trojan.exe<br />
NAV.pif<br />
private.exe</p>
<p>To get rid of Sober Worm, Symantec recommends using the following steps or you should download the removal tool directly from the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-102410-5713-99&#038;tabid=3" target="_blank">Symantec website</a> or the official Windows website at <a href="http://www.microsoft.com/security/malwareremove/default.aspx" target="_blank">www.microsoft.com</a>. </p>
<p>The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines. </p>
<p>1. Disable System Restore (Windows Me/XP).<br />
2. Update the virus definitions.<br />
3. Restart the computer in Safe mode or VGA mode.<br />
4. Run a full system scan and delete all the files detected as W32.Sober@mm.<br />
5. Delete the values that were added to the registry.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.allaboutworms.com/what-is-a-sober-worm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Sober Worm</title>
		<link>http://www.allaboutworms.com/the-sober-worm</link>
		<comments>http://www.allaboutworms.com/the-sober-worm#comments</comments>
		<pubDate>Mon, 16 Jan 2006 21:00:28 +0000</pubDate>
		<dc:creator>Anne</dc:creator>
				<category><![CDATA[Computer Worms]]></category>
		<category><![CDATA[Sober Worm]]></category>

		<guid isPermaLink="false">http://www.allaboutworms.com/?p=33</guid>
		<description><![CDATA[The Sober worm is a highly-damaging email worm that spreads by emailing itself to all addresses in a user's email address book, for which the Sober worm uses its own on-board SMTP (Simple Mail Transfer Protocol) engine. ]]></description>
			<content:encoded><![CDATA[<p>The Sober worm is a highly-damaging mass-mailing email worm  (self-replicating computer program) that spreads by emailing itself to all addresses in a user&#8217;s email address book, for which the Sober worm uses its own on-board SMTP (Simple Mail Transfer Protocol) engine. </p>
<p>The Sober worm was first discovered on October 24, 2003, with new strands of the Sober worm resurfacing during 2004 and 2005. The last big outbreak happened on November 21st, 2005, with the  Sober X worm disguised as an email from various United States government agencies, <a href="http://www.aunty-spam.com/fake-email-from-the-fbi" target=_blank>including the FBI</a>. </p>
<p>Once the attachment is opened, the worm disables all anti-virus systems and acts as spyware (stealing and transmitting personal information).  It also creates entries and copies itself in the system directory.  Upon opening the attachment, the worm may display a message box that reads &#8220;No viruses, trojans, or spyware found! Status: Ok.&#8221; Once installed and run, the worm may also show a fake error message that reads &#8220;Error in packed header.&#8221; Both of these tricks are used to persuade users that no problem exists with the attachment. But in reality, the Sober worm consumes network bandwith, displays fake error messages when programs are opened, terminates antiviruses and other security systems, and creates false registry entries in the computer.</p>
<p>The Sober worm sends itself with different subject names in either English or German (examples include, but are not limited to,&#8221;New internet virus!,&#8221; &#8220;You have sent me a virus!,&#8221; &#8220;Re: Contact,&#8221; and  &#8220;Sorry, I&#8217;ve become your mail, and I&#8217;ve become your mail!&#8221;). </p>
<p>The attachment names may be any of the following, or something else: anti_virusdoc.pif, Anti-Sob.bat, AntiTrojan.exe, anti-trojan.exe, AntiVirusDoc.pif, Bild.scr, Check-Patch.bat, check-patch.bat, CM-Recover.com, Funny.scr, Hengst.pif, Liebe.com, little-scr.scr, love.com, Mausi.scr, nacked.com, NackiDei.com, NAV.pif, Odin_Worm.exe, perversion.scr, Perversionen.scr, pic.scr, playme.exe, potency.pif, Privat.exe, Removal-Tool.exe, removal-tool.exe , robot_mail.scr, robot_mailer.pif, RobotMailer.com, schnitzel.exe, screen_doc.scr, Screen_Doku.scr, or security.pif. </p>
<p>A new form of the Sober worm was set to attack the Internet on January 6th, 2006, but fortunately the hype created by security software companies prevented major problems.</p>
<p><font size="2"><b>Recommended Reading (click on the picture for details):</b></font><br />
<a href="http://www.amazon.com/exec/obidos/redirect?tag=dearesq%26link_code=xm2%26camp=2025%26creative=165953%26path=http://www.amazon.com/gp/redirect.html%253fASIN=0596009267%2526tag=dearesq%2526lcode=xm2%2526cID=2025%2526ccmID=165953%2526location=/o/ASIN/0596009267%25253FSubscriptionId=0EMV44A9A5YT1RVDGZ82" target=_blank><img src="http://images.amazon.com/images/P/0596009267.01._SCMZZZZZZZ_.jpg" alt="PC Pest Control" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.allaboutworms.com/the-sober-worm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

