F-Secure: Be Sure
Main
F-Secure Logo - Be Sure
Select local site


Privacy Policy
Legal Notices
Contact Us

F-Secure Virus Descriptions : Sober

[Summary] | [Disinfection] | [Detection]

THIS VIRUS IS RANKED AS LEVEL 2 ALERT UNDER
F-SECURE RADAR.

Radar Alert LEVEL 2

NAME:Sober
ALIAS:I-Worm.Sober
VARIANT:Sober.A

Sober is an email worm, sending messages in English and German, sometimes posing as a fix from an Anti-Virus company.

Summary

Sober is an email worm that disguises itself as a security warning for a possible new worm and a fix coming from an Anti-Virus company. The worm uses attachment names such as anti_virusdoc.pif, check-patch.bat, playme.exe.

Detailed Description

The worm was packed with a modified version of UPX and was written in Visual Basic. It has its own SMTP engine which will be used when sending e-mail messages.

System installation

It will modify the Windows' registry under:

 [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 or
 [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

to point to where the executable copies of the worm are dropped. Some of the possible locations are:

 %SysDir%\similare.exe
 %SysDir%\sysrunll.exe

E-mail spreading.

It will spoof different mail clients, using the headers:

 X-Mailer: Microsoft Outlook Express 6.00.2600.0000
 X-Mailer: Microsoft Outlook Express 5.00.3018.1300
 X-Mailer: Safety_Mail Server
 X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
 X-Mailer: Microsoft Outlook IMO, Build 9.0.

It will send e-mails with the following subjects:

In german:

 Neuer Virus im Umlauf!
 Back At The Funny Farm
 Sie versenden Spam Mails (Virus?)
 Ein Wurm ist auf Ihrem Computer!
 Langsam reicht es mir
 Sie haben mir einen Wurm geschickt!
 Hi Schnuckel was machst du so ?
 VORSICHT!!! Neuer Mail Wurm
 Re: Kontakt
 RE: Sex
 Sorry, Ich habe Ihre Mail bekommen
 Hi Olle, lange niks mehr geh
 Re: lol
 Viurs blockiert jeden PC (Vorsicht!)
 berraschung
 Ich habe Ihre E-Mail bekommen !
 Jetzt rate mal, wer ich bin !?
 Neue Sobig Variante (Lesen!!)
 Ich Liebe Dich

In english:

 Congratulations!! Your Sobig Worms are very good!!!
 You are a very good programmer!
 Yours faithfully
 Odin alias Anon
 Odin_Worm.exe
 New internet virus!
 You send spam mails (Worm?)
 A worm is on your computer!
 You have sent me a virus!
 Hi darling, what are you doing now?
 Be careful! New mail worm
 Re: Contact
 Sorry, I've become your mail
 Hey man, long not see you
 Viurs blocked every PC (Take care!)
 Surprise
 I've become your mail!
 Advise who I am!
 New Sobig-Worm variation (please read)
 I love you (I'm not a virus!)
 I permanently get Spam-Mails from you and inside is a virus!!
 You should remove these thing.

Attachment names are picked from the list:

 AntiVirusDoc.pif
 Check-Patch.bat
 Screen_Doku.scr
 Removal-Tool.exe
 Perversionen.scr
 CM-Recover.com
 Bild.scr
 schnitzel.exe
 robot_mail.scr
 RobotMailer.com
 Privat.exe
 AntiTrojan.exe
 Mausi.scr
 NackiDei.com
 Anti-Sob.bat
 security.pif
 Funny.scr
 Liebe.com
 Odin_Worm.exe
 check-patch.bat
 anti_virusdoc.pif
 perversion.scr
 removal-tool.exe
 screen_doc.scr
 potency.pif
 CM-Recover.com
 pic.scr
 playme.exe
 robot_mailer.pif
 private.exe
 anti-trojan.exe
 love.com
 nacked.com
 anti-Sob.bat
 NAV.pif
 funny.scr
 little-scr.scr


Back to the Top


Disinfection

F-Secure Anti-Virus starting from version 5.40 should successfully rename both infected files thus disinfecting a computer from Sober infection. If a Windows NT, 2000 or XP operating system is used, it is recommended to restart a computer after disinfection.


Back to the Top


Detection

Detection in F-Secure Anti-Virus was published on October 24th, 2003 in update:

[FSAV_Database_Version]

Version=2003-10-24_01


Back to the Top


Technical Details: Ero Carrera

Write-up: Katrin Tocheva, October 26th, 2003;

Description Updated: Alexey Podrezov, November 11th, 2003;

F-Secure Corporation