Home Malware Programs Worms Sober.t

Sober.t

Posted: March 28, 2006

Sober.t is a rapidly spreading Internet worm that propagates by e-mail through messages with attached Zip archives containing copies of the spyware.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 excel_table.zip
    2 hjgerhds.exe
    3 services.exe
    4 tabelle.zip

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun\_wincheckHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunwincheck
Loading...