Internet Access by Area Code
Internet Service by City/State
 FAQFAQ   SearchSearch     RegisterRegister   ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in  ISP Guide    

WORM_SOBER.G information



 
Top Rated Dialup Internet Service Providers & Top Rate DSL Provider
Post new topic   Reply to topic    ISP Guide -> ISP Guide Forum Index -> Internet Utilities & Software  
Get Instant quotes for
Home: DSL Cable Satellite
Business: DSL T1 VoIP


Latest Discussions 
   Adobe Photoshop CS4 Ultra Light Edition
   what is lucoms~1.exe process ? Is lucoms ...
   Download McAfee Total Protection 2009
   Wireless Internet
   isass.exe makes computer restarts
Popular Discussions 
  what is lucoms~1.exe process ? Is lucoms ...
  Windows XP- lsass.exe 60second System Sh ...
  what is dumprep.exe process ? Is dumprep ...
  Windows XP/2000/ME : lsass.exe error
  lsass.exe removal
Hottest Discussions 
   Windows XP- lsass.exe 60second System Sh ...
   Netscape Internet Keywords
   what is lucoms~1.exe process ? Is lucoms ...
   Dialup connection problems
   Links not responding, IE 6 freezes when ...
Other Topics
best commercial firewalls
Dialup connection problems
how many people use ISP software?
Broadband Connection help
Best gaming modem
Moderators Wanted!!
Is Aol is best for Gaming?
Norton or AVG?
firewall problems
Internet Accelerator
Other Forums
Hardware/ Networking and All Operating Systems (Windows 98/XP/MAC/Linux)
Technical Questions & Answers
Tips & Tricks
Author
Message
bob



Joined: 26 May 2004
Posts: 524

Offline

PostPosted: Thu Jul 01, 2004 7:18 pm    Post subject: WORM_SOBER.G information Reply with quote

Friends I have got some useful information about this latest worm from F secure
Here is this
The worm is written in Visual Basic. The worm's file is a PE executable of length 49661 bytes, packed with a modified version of UPX file compressor. The worm has its own SMTP engine.
Installation to system
When the worm's file is started it shows the following messagebox:
If a user clicks 'Yes' button, the worm creares the converted_<filename>.txt file where <filename> is the name of the worm's file. The worm writes random garbage to that file and opens it with Notepad:
Then the worm installs itself to system. It copies itself to Windows System folder with a semi-randomly generated name and EXE extension. The following text strings are used to generate the file name of the worm's executable:
sys
host
dir
expolrer
win
run
log
32
disc
crypt
data
diag
spool
service
smss32
After that the worm creates startup keys for its file in Windows Registry. The key names are also semi-randomly generated from the above given list. The following keys are created:
 
Display posts from previous:   
Post new topic   Reply to topic     ISP Guide -> ISP Guide Forum Index -> Internet Utilities & Software All times are GMT - 6 Hours
Email this topic to a friend

Page 1 of 1
ISP Disscussion Topics

Main Forum Category
 
Other Network Forums
 •  ISP Discussions & Reviews
 •  ISP Technical Support
Broadband ISP Discussion
Forum Announcements and Site Reviews
 
 • Broadband Forum  
 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Related topics
 Topics   Replies   Author   Views   Last Post 
No new posts Netscape User Files location with Windows XP 2 frank 783 Tue Jul 06, 2004 5:56 pm
Charles
No new posts Microsoft Outlook 2003 User profiles 2 denny 1246 Fri Jul 02, 2004 4:59 pm
Tod
No new posts Error: No Matches Found for <User Name> 2 Curt 4104 Thu Jul 01, 2004 8:39 am
Curt
No new posts What's the command for connection speed and stats on my USER 0 jenipher 927 Fri Jun 25, 2004 4:48 pm
jenipher
No new posts Trip.net-The Cheap ISP 4 michel 1325 Thu Jun 17, 2004 6:23 pm
Guest
 



Premium Network Of Directories
Affiliate Resources
Free Web Directory
Call to India
Domain-Name Registration
Web Hosting Provider
ISP Providers
Free Downloads
Broadband Internet
Outsourcing company Directory
Data Recovery Guide
Affiliate Resources
Call to Mexico
 
Other Internet Resources: ISP Resources