Panda Software Reports The Appearance of Sober.I
PandaLabs has detected the appearance of a new worm called Sober.I. This malicious code is designed to spread rapidly via email in a message that can be written in English or German. According to data gathered by Panda Software’s international tech support network, Sober.I is starting to spread across German-speaking countries, such as Germany and Austria, causing incidents in users’ computers.
The messages carrying Sober.I have extremely variable characteristics, as the subject, message body and name of the attachment are all selected at random. If the user runs the file containing Sober.I, it creates a large number of files on the computer, such as clsobern.isc and nonzipsr.noz, which are copies of the worm, or logsys.exe and syssmss32.exe, which are files used by the worm to carry out its actions.
When it has been run, Sober.I looks for email addresses on the affected computer, which it then sends itself out to using its own SMTP engine. If the domain of the email address belongs to Switzerland (.ch), Germany (.de), Austria (.at) or Liechtenstein (.li), the worm inserts German texts in the email message. If the domain is any other than those mentioned above the email will be sent in English.
Finally, Sober.I inserts several entries in the Windows Registry in order to ensure that it is run whenever the computer is started.
Due to the high possibility of being infected by Sober.I, Panda Software advises users to take precautions and update their antivirus software. Panda Software has made the corresponding updates available to its clients to detect and disinfect this new malicious code.
For further information about Sober.I, visit Panda Software’s Virus Encyclopedia at: http://www.pandasoftware.com/virus_info/encyclopedia/