* 3,000 daily downloads
* 90,000 programs
* 450,000 monthly users
Home > Utilities > Antivirus > WinSobigFmm free Removal Tool
WinSobigFmm free Removal Tool

WinSobigFmm free Removal Tool

Immediate Delivery
Buy full version!
55 KB
Download free trail version!


WinSobigFmm free Removal Tool
Editor's Rating: 0/5
User's Rating: 0/5
Rated by 0 users: > Rate It
Add your opinion
> Read User's Reviews(0)


Publisher's description of WinSobigFmm free Removal Tool
Related:
Removal Tool Mass Mailer movie0045.pif w32 sobig f worm copies format subject tool name

Win32.Sobig.F@mm FREE Removal Tool Name: Win32.Sobig.F@mm
Aliases: W32/Sobig.F@mm

Type: Executable Mass Mailer
Size: ~70 KB
Discovered: 19.08.2000
Spreading: High
Damage: Low
In The Wild: Yes

Symptoms:
Registry keys:
HKLMSoftwareMicrosoftWindowsRunCurrentVersionTrayX with value:
%WINDIR%winppr32.exe /sinc
HKCUSoftwareMicrosoftWindowsRunCurrentVersionTrayX with value:
%WINDIR%winppr32.exe /sinc

Following files in the %WINDIR% folder:

Winstt32.dat
Winppr32.exe
Winstf32.dll

Technical description:

It arrives in e-mail in the following format:

Subject:
Randomly chosen from the following list:
"Re: Wicked screensaver"
"Re: That movie"
"Re: Your application"
"Re: Approved"
"Re: Re: My details"
"Re: Details"
"Your details"
"Thank you!"
"Re: Thank you!"

Body:
Please see the attached file for details.
Or
See the attached file for details

Attachment:
Randomly chosen from the following list:
"movie0045.pif"
"wicked_scr.scr"
"application.pif"
"document_9446.pif"
"details.pif"
"your_details.pif"
"thank_you.pif"
"document_all.pif"
"your_document.pif "

After the user opens the attachment the worm copies in the following location:
%WINDIR%winppr32.exe
and adds the following registry keys:
HKLMSoftwareMicrosoftWindowsRunCurrentVersionTrayX with value:
%WINDIR%winppr32.exe /sinc

HKCUSoftwareMicrosoftWindowsRunCurrentVersionTrayX with value:
%WINDIR%winppr32.exe /sinc

It searches for e-mails in the following file types:
html, wab, mht, hlp, txt, eml, htm, dbx

The worm also spreads trough network shares.
After the 10.09.2003 it stops spreading

Removal instructions:

The BitDefender Virus Analyse Team has releasead a free removal tool for this particular virus.

Important: You will have to close all applications before running the tool (including the antivirus shields) and to restart the computer afterwards. Additionally you'll have to manually delete the infected files located in archives and the infected messages from your mail client.

The BitDefender Antisobig-en.exe tool does the following:
  • it detects all the known Sobig versions;
  • it deletes the files infected with Sobig;
  • it kills the process from memory;
  • it repairs the Windows registry

    You may also need to restore the affected files.

    To prevent the virus from replicating itself from infected machines to clean machines, you should try to disinfect all computers in the network before rebooting any of them, or unplug the network cables.

  • 55 KB
    Buy full version! Download free trail version!
    Basic Information
    Downloads: 15 Last update: Jan 7, 2008
    Size: 55 KB Operating System: Windows All
    Price: - License: Freeware
    Related Solution Guide
    You may also be interested in:

    Top Sales in Utilities
    1. Solar System 3D
    2. Registry Mechanic
    3. RadarSync 2008
    4. EASEUS Data Recovery Wizard
    5. Spotmau PowerSuite...
    6. Easy ScreenSaver Studio
    7. Driver Detective
    8. Acronis True Image
    9. Registry Booster
    10. Norton AntiVirus 2008

    More to Try
    PC Washer is a powerful system cleaner that allows you to remove space wasting junk files from...
    Parallels Desktop 3.0 for Mac provides the best solution to enable Apple users to run Windows,...
    STOPzilla Anti-Spyware safely detects and removes Spyware, Adware, Popup Ads, Phishing Attacks,...
    KriptoDrive 2007 Makes your documents truly safe, so nobody can read them or manipulate them...
    EasyClone 2008 Technician is the complete solution to backup your hard disk. It copies the entire...
    PictureImp is the world's first "Zero-Click" web image downloader. You will definitely love...
    DownloadAtoZ.com
    Shareware Download
    Freeware Download
    Weekly Recommends
    Software Reviews
    Editor's Picks
    Solution Guides
    Online Manuals
    PC Games
    Puzzle Games
    Flash Games
    What's Hot
    Search
    Copyright © 2001-2008 DownloadAtoZ.com Download Free Fonts | Drivers Download | Codecs Download | DRM Removal | Submit Software