Proland Software  Download Anti virus software now!

Home
Antivirus products
Download Antivirus Software
Order On-line
Support
Email
Protector Plus Antivirus Software for
Antivirus Software for Windows XP and 2000
Antivirus Software for Windows Vista
Antivirus Software for Windows Me and 98
Antivirus Software for Exchange
Antivirus Software for NetWare
Protector Plus Console
Buy Antivirus software now!


SpamChoke Antispam
Software

Subscribe to Virus Alert
Mailing List

Enter your Email
(Ex : john@company.com)


Download Anti virus software

W32/Sobig.E Worm

Blueball Information about the W32/Sobig.E worm:

W32/Sobig.E is an email worm. It is a variant of W32/Sobig.A. This worm will infect Windows systems. The worm spreads through email and shared drives on network.

The worm arrives as an email having the from address as support@yahoo.com or any random address picked from the infected system. The subject of the infected mail will be any one of the following;

004448554.pif
Application.pif
Applications.pif
movie.pif
new document.pif
Re: Application
Re: document.pif
Re: Documents
Re: Movie
Re: Movies
Re: Re: Application ref 003644
Re: Re: Document
Re: ScRe:ensaver
Re: Submitted
Referer.pif
Screensaver.scr
submited.pif
Your application

The content of the mail will be;

Please see the attached zip file for details.

The infected attachment will have any one of the following names;

application.zip
document.zip
movie.zip
screensaver.zip
your_details.zip

When the infected attachment is executed, the worm copies itself as winssk32.exe under the Windows folder. The worm modifies registry at the following location to run itself at the startup.

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

The worm attempts to find the shared resources on the network and tries to copy itself under the following folders of the target system;

Windows\All Users\Start Menu\Programs\StartUp
Documents and Settings\All Users\Start Menu\Programs\Startup

The worm tries to collect all the email addresses found in the files having the following extensions;

.txt
.eml
.html
.htm
.dbx
.wab

and stores these addresses in encrypted format as msrrf.dat in Windows folder. The worm tries to mail itself to these email addresses using its own SMTP engine.

This worm first appeared on 25th June 2003.

Blueball Other names of W32/Sobig.E worm:

This worm is also known as W32/Sobig.e@MM , W32/Sobig-E, W32.Sobig.E@mm


Click here to download a 30 day Evaluation Copy of
Protector Plus for your operating system

Blueball About Protector Plus Antivirus Software Packages:

Proland Software is the developer of Protector Plus range of antivirus software packages. Protector Plus is available for Windows Vista, Windows 95/98/Me, Windows XP, Windows NT/2000/2003 servers and workstations, MS-Exchange 2000/2003, MS-DOS and NetWare servers.

SpamChoke Antispam Software

New:
SpamChoke Antispam Software
Download Now!

Protector Plus range of antivirus products offer on-line virus detection and removal. All the packages have the ability to detect and isolate all types of viruses, trojans, worms and other types of malware.Protector Plus antivirus software can detect and remove W32/Sobig.E worm reliably.

These products are updated on a continuous basis and the latest upgrades for all the platforms are made available for downloading from this site.

Click here to order
Protector Plus Antivirus software
 

Download Anti virus software now!


You can download the 30 day evaluation copy of the
antivirus software free of cost for these platforms:
Antivirus Software for Windows XP and 2000 Antivirus Software for Windows Me and 98 Antivirus Software for Exchange Antivirus Software for NetWare


HomeAntivirus productsDownload Antivirus SoftwareOrder On-lineEmail

Copyright © 2007 Proland Sofrware. All rights reserved.


Download Anti virus software