Sophos

W32/Sober-Gen

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Email attachments
Affected operating systems Windows
Protection available since 7 March 2005 18:44:16 (GMT)
Last updated 15 November 2005 22:36:14 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

Please follow the instructions for removing worms.

The name W32/Sober-Gen is used where a file belongs to a particular family of worms, but the variant is not separately identified. Sophos's proactive protection technology will identify such files as a -Gen variant.

  1. Ensure that you are using the most recent IDE files, as more precise detection could now be available. If necessary

  2. Please send us a sample to assist in improving our technology.
  3. Use the instructions for removing generically detected files to delete the file from your computer.
  4. If you require further assistance with disinfection, contact support.

More Information

Sophos Anti-Virus products detect members of the W32/Sober family as W32/Sober-Gen.

Members of the W32/Sober-Gen family are email worms that harvest email addresses from infected computers. Sophos Anti-Virus products detect members of the W32/Sober family as W32/Sober-Gen.

Members of the W32/Sober-Gen family are email worms that harvest email addresses from infected computers.

The worms typically send themselves as email attachments to addresses found in files with extensions such as:

PMR PHTM STM SLK INBOX IMB CSV BAK IMH XHTML IMM IMH CMS NWS VCF CTL DHTM CGI PP PPT MSG JSP OFT VBS UIN LDB ABC PST CFG MDW MBX MDX MDA ADP NAB FDB VAP DSP ADE SLN DSW MDE FRM BAS ADR CLS INI LDIF LOG MDB XML WSH TBB ABX ABD ADB PL RTF MMF DOC ODS NCH XLS NSF TXT WAB EML HLP MHT NFO PHP ASP SHTML DBX AERO COM COOP EDU GOV MUSEUM NAME INT NET ORG PRO INFO

Some variants also spread through Peer-to-peer applications such as KaZaA.

In order to run each time a user logs on, the worms typically create registry entries under the following:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
<name>
"<path to worm>"

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
<name>
"<path to worm>"

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer