|
|
To print: Select File and then Print from your browser's menu
-------------------------------------------------------------- This story was printed from ZDNet Australia. --------------------------------------------------------------
|
Sober.d prevention and cure By Robert Vamosi, ZDNet US March 09, 2004 URL: http://www.zdnet.com.au/insight/security/soa/Sober-d-prevention-and-cure/0,139023764,139116485,00.htm
help & how-to This virus masquerades as a Microsoft patch for the MyDoom worm. What appears to be yet another Microsoft security patch for the MyDoom worm is actually a computer virus. Sober.d (w32.sober.d@mm, also known as Roca.a) is the fourth member of the Sober mass-mailing virus family written in Visual Basic, and it exists only to send e-mail in either German or English. Users of Linux, the Mac OS, and Unix are not affected. Because Sober.d spreads via e-mail and does no other damage, this worm rates a 4 on the ZDNet Virus Meter.
How it works
"New MyDoom Virus Variant Detected!
"Protection: The attached file is either an EXE or a ZIP file with one of the following names:
sys-patch Once executed, Sober.d copies files into the C:\winnt\system32 or C:\windows\system32 directory folder:
mslogs32.dll (a copy of e-mail addresses found) In order for the virus to run every time the infected machine is rebooted, the virus adds the following to the system Registry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion \Run\disc32data "spool32" = %SYSDIR%\diagwinhost.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion \RunOnce "diagdir" = %SYSDIR%\diagwinhost.exe %1
Removal
Copyright © 2009 CBS Interactive, a CBS Company. All Rights Reserved. |