Home Malware Programs Worms W32.Sobig.F

W32.Sobig.F

Posted: March 28, 2006

W32.Sobig.F@mm is a worm that sends itself to all the email addresses it finds in the files that have the following extensions:
.dbx, .eml, .hlp, .htm, .html, .mht, .wab, .txt

File System Modifications

  • The following files were created in the system:
    # File Name
    1 details.exe
    2 details.pif.exe
    3 movie0045.exe
    4 wicked_scr.exe
    5 winppr32.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionHKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionunrayx
Loading...