SoBig.D Worm Virus Information and Removal Help

What is SoBig.D Worm and How Did I Get It?
The SoBig worm spreads through email attachments and shared network folders. It sends copies of itself via is own SMTP engine and obtains the recipient addresses from information found in files with the following extensions:
  • .wab
  • .dbx
  • .htm
  • .html
  • .eml
  • .txt

The details of the email are

Sender: admin@support.com <or obtained email address>

The subject can be:

  • Application Ref: 456003
  • Re: Accepted
  • Re: App. 00347545-002
  • Re: Application
  • Re: Documents
  • Re: Movies
  • Re: Screensaver
  • Re: Your Application (Ref: 003844)
  • Your Application

The message body contains: Please see the attached file.

And the attachment is one of the following

  • accepted.pif
  • app003475.pif
  • application.pif
  • application844.pif
  • applications.pif
  • document.pif
  • movies.pif
  • ref_456.pif
  • screensaver.scr

The worm also attempts to copy itself to the following folders on all the open network shares:

  • \Windows\All Users\Start Menu\Programs\StartUp
  • Documents and Settings\All Users\Start Menu\Programs\Startup

The worm stops spreading via network shares on July 1, 2003.

How to Clean/Delete the SoBig.D worm?

Follow these steps in removing the SoBig.D worm.

1) Terminate the running program

  • Open the Windows Task Manager by either pressing CTRL+ALT+DEL on Win9x machines or CTL+Shift+Tab and clicking on the Processes tab on WinNT/2000/XP machines.
  • Locate the following program, click on it and End Task or End Process

       SFtrb Service or cftrb32.exe

  • Close Task Manager

2) Remove the Registry entries

  • Click on Start, Run, Regedit
  • In the left panel go to

HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>Current Version>Run

  • In the right panel, right-click and delete the following entry

SFtrb Service

Repeat this procedure for the following location

HKEY_CURRENT_USER>Software>Microsoft>Windows>Current Version>Run

  • Close the Registry Editor

3) Delete the infected files

  • Click Start, point to Find or Search, and then click Files or Folders.
  • Make sure that "Look in" is set to (C:) and that "Include subfolders" is checked.
  • In the "Named" or "Search for..." box, type, or copy and paste, the file names:
    rssp32.dat
    cftrb32.exe
  • Click Find Now or Search Now.
  • Delete the displayed files.

4) Reboot the computer and run a thorough virus scan using your favorite antivirus program.

Removal of Other SoBig worm viruses

SoBig.A
SoBig.B
SoBig.C
SoBig.D
SoBig.E
SoBig.F

 

space.gif (58 bytes)

 

Search PCHell.com
site search by freefind advanced

 




Tools for Removing Spyware, Adware, and Malware


PC HELL
Other Pages

Spyware/Adware Removal Help

MSBlast.exe Worm Removal

Welchia (Dllhost.exe and SVCHost.exe) Worm Removal

Uninstall McAfee Instructions

Uninstall Norton Instructions

Uninstall Avast Instructions

Uninstall AVG Instructions

Uninstall Antivir Instructions

Uninstall Panda Instructions

How to Manually Run the Microsoft Malicious Software Removal Tool

Bloodhound.Exploit.6 Virus Removal

MyDoom Virus Removal

MiMail.C Virus Removal

Swen Worm Virus Removal

SoBig.F Worm Removal

Dumaru Virus Removal

BugBear.B Worm Removal

SoBig.E Worm Removal

Pop Up Ad Removal Info

KAK Worm Removal

MiMail.A Worm Removal

W95.MTX Virus Removal

Snow White Virus Removal

BadTrans Trojan Removal

Wininit Virus (Bymer Trojan)

Happy99 Worm Removal

VBS Netlog Worm Removal

Pretty Park Worm Removal

Sasser Worm Virus Removal

Backdoor SDBot.H Trojan Removal

VBS.Loveletter Help

Computer Security Information

Back Orifice Information

PC HELL Main Page

 






iPadastic - News, Tutorials, Help, Tips, and Hints for the iPad



Download Hoyle Games
including Casino 3D, Card, Board, and Solitaire games.



Written by Mark Hasting

Recommended Software for PC Hell Visitors
Malwarebytes Anti-Malware
Malwarebytes Anti-Malware
iolo System Mechanic® - Fix, Speed Up Your PC
iolo System Mechanic®
Emsisoft Anti Malware
Emsisoft Anti Malware
space.gif (58 bytes)

Search PCHELL.COM

Return to PC Hell
Return to PC Hell

Google