Malware . Sober Worm (Summary)
Software Name: Sober Worm
Company Name:
Product Name: Sober Worm
Classification: Malware
Website:
Brief:
A worm that propagates via email addresses obtained from infected machines. The worm may cause security vulneralbilities.
IMPORTANT!
Some of the Malware.Sober Worm components
are listed below. The list is compiled as a reference. The list might
not be complete and it doesn't represent instructions for manual removal.
We DO NOT recommend manual removal. Incorrect removal
of certain software might make your computer unstable or even unusable.
Removal of adware component might affect the related ad-supported software.
If you suspect that you have an unwanted instance of Sober Worm
installed on your computer we recommend a free
audit of your system with INAC Anti Spyware.
Sober Worm might create following folders (and inject its files inside
the folders):
Sober Worm might create following files (some of the files might be
loaded in memory while the software is running):
- %SYSTEM%\bbvmwxxf.hml
- %SYSTEM%\filesms.fms
- %SYSTEM%\langeinf.lin
- %SYSTEM%\nonrunso.ber
- %SYSTEM%\rubezahl.rub
- %SYSTEM%\runstop.rst
- %WINDOWS%\WinSecurity\csrss.exe
- %WINDOWS%\WinSecurity\mssock1.dli
- %WINDOWS%\WinSecurity\mssock2.dli
- %WINDOWS%\WinSecurity\mssock3.dli
- %WINDOWS%\WinSecurity\services.exe
- %WINDOWS%\WinSecurity\smss.exe
- %WINDOWS%\WinSecurity\socket1.ifo
- %WINDOWS%\WinSecurity\socket2.ifo
- %WINDOWS%\WinSecurity\socket3.ifo
- %WINDOWS%\WinSecurity\starter.run
- %WINDOWS%\WinSecurity\winmem1.ory
- %WINDOWS%\WinSecurity\winmem2.ory
- %WINDOWS%\WinSecurity\winmem3.ory
Sober Worm is often accompanied by the following tracking cookies:
n/a
Sober Worm might create following registry keys (and inject subkeys
and values):
n/a
Sober Worm might create following registry values:
n/a
Sober Worm might create registry values with following data:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|*|*\winsecurity*
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Run|*|*\winsecurity*
Sober Worm might insert following entries in the HOSTS file:
n/a
Click
here to scan your computer for Sober Worm free of charge
|