Name: Sober.T worm
Also known as: W32/Sober.Z.worm (Panda), W32/sober.T@MM (McAfee), W32.Sober.R@mm (Symantec), W32/sober.T@mm (F-Prot, Command), W32/Sober-P (Sophos), Win32.Sober.T@mm (BitDefender),
I-Worm.Sober.V (VirusBuster)
Type: Worm
Discovered: November 14, 2005
Email characteristics: Sober.T arrives in an email message that may be in either German or English language, depending on the recipient's domain. The Sober.T email carries an attachment with one of the following names:
registration.zip
Word-Text.zip
The zip file contains an executable named 'Word-Text_packedList.exe'
System Impact:: If the infected executable is run, Sober.T will create the following files:
C:\Windows\hjgerhds.exe
C:\Windows\ConnectionStatus\Microsoft\services.exe
C:\Windows\System32\gdfjgthv.cvq
C:\Windows\System32\langeinf.lin
C:\Windows\System32\nonrunso.ber
C:\Windows\System32\System32\rubezahl.rub
C:\Windows\System32\System32\runstop.rst
Note: The exact name of the Windows directory and System directory may vary depending on the operating system.
Sober.T modifies the HKCU and HKLM Registry Run keys in order to load when Windows is started:
'WinCheck =C:\Windows\ConnectionStatus\Microsoft\services.exe'
Removal Notes: Use up-to-date antivirus software to identify the worm's files. Either allow the antivirus software to delete these files, or they can be manually deleted. If opting for manual deletion, be sure to also remove the registry modifications made by the worm.