Results 1 to 6 of 6

Thread: How to delete W32 Sober AA@mm from my computer system?

  1. #1
    Join Date
    Dec 2009
    Posts
    32

    How to delete W32 Sober AA@mm from my computer system?

    Normally I like to surf the net for the information related to games. I like to download and play games from internet. For this purpose I have to download many related add-ons. The thing was going very fine but now my personal computer is running very slow. Then I thought that this problem might be because of any kind of virus or worm. So I scanned my system and found that W32 Sober AA@mm is residing in my personal computer. I am trying to delete this virus from my computer system but it comes back again and again. Can anybody help me to get rid of the W32 Sober AA@mm from my personal computer?

  2. #2
    Join Date
    Feb 2008
    Posts
    2,635

    Re: System restore can solve your problem

    You can go for system restore. For restoring your system to its previous position you can follow these simple steps. Go to start then to Programs then to Accessories then to System tools. Now you can select system restore. Now in the system restore window, select the date for the system restores. Reboot your system and you will get your system as it was a one week before. There is no guarantee that system restore will solve your problem but it is one of the methods which is used as a counter measure.

  3. #3
    Join Date
    May 2008
    Posts
    2,945

    Re: W32 Sober AA@mm is a kind of worm

    W32 Sober AA@mm which is detected on your computer comes in the category of internet worm. The threat level of this worm is medium. But whatever be the amount of threat level it is not good for your personal computer so I will suggest you to delete this worm from your personal computer. Worms normally slows down the performance of computer system

  4. #4
    Join Date
    Jan 2006
    Posts
    3,792

    Re:Details related to W32 Sober AA@mm

    Sober.AA is a mass mailing worm uses e-mail addresses collected from the system to distribute infected mails. The worm uses its own SMTP engine to spread. The infected mail will be in English or German.
    The infected mail subject in English will be one of the following
    Error in your eMail
    Your Updated Password!
    The infected mail subject in German will be one of the following
    Ihr Passwort wurde geaendert!
    Fehlerhafte Mailzustellung
    Ihr Account wurde eingerichtet
    The infected mail Attachment name in English will be one of the following
    Passw_Data.zip
    Mail_Data.zip
    The infected mail Attachment name in German will be one of the following
    PDaten.zip
    Anleitung.zip
    The infected mail message body in English will be one of the following
    You notified us that you have forgotten your password.We have changed your password to a random sequence of letters and digits! For more detailed information, see the attached password file ...

    Your eMail has occurred an unknown error on our Server.Please read your mail and check the text.The full email is attached!
    The infected mail message body in German will be one of the following

    Ihr Passwort wurde erfolgreich geaendert.Ihre neuen Account-Daten und Passwort befinden sich gesichert im Anhang!

    Diese Nachricht wurde Automatisch generiert. - Ihre EMail konnte nicht empfangen oder gesendet werden.

    Danke das Sie sich fuer uns entschieden haben.Um ihren neuen Account zu aktivieren, folgen sie der kurzen Anleitung im Anhang. Es sind nur 2 Schritte noetig!
    When the infected e-mail attachment is executed, it displays a fake error message "WinZip Header is missing!" with title "WinZip Self-Extractor" and copies to %WINDOWS%\PoolData\services.exe. It also drops SMSS.EXE, CSRSS.EXE, and data files in the infected system.Then it modifies the registry to load automatically on next startup. The registry key modification is given below.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run = "WinData"="%WINDOWS%\PoolData\services.exe"
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run = "_WinData"="%WINDOWS%\PoolData\services.exe"

  5. #5
    Join Date
    Jan 2006
    Posts
    4,221

    Re: Solo Antivirus software can remove this worm

    If you are already infected with this worm, you can remove it from your computer using Solo Antivirus software. Solo antivirus can detect and remove W32.Sober.AA@mm safely. You can download this antivirus for the trial period. This antivirus is available for the trial period of 30 days. Solo anti-virus not only scans for all viruses, it contains a unique System Integrity Checker to protect you from New Internet Worms, Backdoors and malicious VB, Java Scripts. It also effectively removes all existing Internet Worms, File viruses, malicious VBS, Java scripts, Trojans, Backdoors, boot sector, partition table and macro viruses.

  6. #6
    Join Date
    Apr 2008
    Posts
    3,424

    Re: Preventive measures to avoid worm problem

    System restore and antivirus software will definitely remove this virus worm from your computer system but I will suggest you to follow some preventive measures to avoid problems like these. Upgrade you antivirus software and the other software which you are using in your system. Do not forget to enable your firewall setting and always used strong password for your personal computers.

Similar Threads

  1. How to delete this VBS.CoolNotepad from my computer system?
    By Orion lella in forum Networking & Security
    Replies: 5
    Last Post: 02-03-2010, 11:51 PM
  2. Protect system from W32/Sober.AA@mm
    By Quattro in forum Networking & Security
    Replies: 4
    Last Post: 19-02-2010, 01:26 AM
  3. How to delete this W95/Babylonia from my computer system?
    By Carley in forum Networking & Security
    Replies: 5
    Last Post: 03-02-2010, 11:59 PM
  4. How to delete W32.Sober.G@mm from my computer?
    By CAROLG in forum Networking & Security
    Replies: 5
    Last Post: 09-01-2010, 06:44 AM
  5. How to delete W32.Mytob.gen from my computer system?
    By CAROLG in forum Networking & Security
    Replies: 5
    Last Post: 07-01-2010, 12:11 AM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,750,786,710.71812 seconds with 16 queries