Name: I-WORM.SoBig.F
AKA:
Type: Internet Worm
Size: 73369 bytes
Platform: Win 95/98/ME/NT/2000/XP
Description:
SoBig.F is a new variant of the SoBig Worm; this worm spread itself throug email messages, retrieving address from Outlook's contacs or html files.
The worm sends email messages using the infected user as email sender (the address gets retrieved from outlook address book).
Messages has the following subjects:
Your Details, Thank you!, Re: Thank you!, Re: Wicked screensaver, Re: Your application,
Re: Approved, Re: Details, Re: That movie, Re: Re: My details
With the following bodies:
See the attached file for details
Please see the attached file for details
It attachs the following files:
wicked_scr.scr
movie0045.pif
application.pif
document_9446.pif
details.pif
your_details.pif
thank_you.pif
document_all.pif
your_document.pif
Once executed, SoBig.F worm creates the file winppr32.exe inside Windows' folder. It then edits the registry so to execute that file at every windows startup.