W32/Sober.T is an email worm. This worm is a variant of W32/Sober. The worm will infect Windows systems and spreads through email.
The infected email carries a spoofed 'From' address picked up randomly from the infected system.
The subject of the infected mail will be either in English or German language.
The subject of the mail in English will be as follows;
Registration Confirmation
The subject of the mail in German will be as follows;
Haben Sie diese EMail verschickt?
The body of the infected mail will be either in English or German language.
The body of the mail in English will be as follows;
Thanks for your registration.
Your data are saved in the zipped Word.doc file!
The body of the mail in German will be as follows;
Um es vorweg zu sagen: Ich bin kurz davor eine Anzeige gegen sie zu erstatten!
Sie spinnen ja wohl! Die E-Mmailhat meine Tochter gelesen!!!!!!
Ich habe Ihnen diese Word-Text Datei zu meiner Entlastung zurueckgeschickt.
Es waere von Vorteil, wenn Sie sich dazu aeussern wuerden!!
The infected attachment will be any one of the following;
registration.zip
Word-Text.zip
Upon execution of the infected attachment, the worm drops a file services.exe in the Windows folder.
It also drops the following files in the Windows System folder.
Proland
Software is the developer of Protector Plus range of antivirus software
packages. Protector Plus 2007 is available for Windows Vista, Windows 95/98/Me, Windows
XP, Windows NT/2000/2003 servers and workstations, MS-Exchange 2000/2003, MS-DOS
and NetWare servers.
Protector Plus range of antivirus products
offer on-line virus detection and removal. All the packages have the ability
to detect and isolate all types of viruses, trojans, worms and other types
of malware.
Protector Plus antivirus software can detect and remove W32/Sober.T Worm reliably.
These products are updated on a continuous basis and the latest upgrades
for all the platforms are made available for downloading from this site.