F - S O B I G
-------------

The F-Sobig utility disinfects computers infected with 
W32/Sobig.B@mm, W32/Sobig.C@mm, W32/Sobig.E@mm and W32/Sobig.F@mm
worm variants.  These worms are also known as 'Palyh' and 'Mankx'.

Detailed description on the W32/Sobig.B@mm worm is available at
http://www.f-secure.com/v-descs/sobig.shtml

Detailed description on the W32/Sobig.C@mm worm is available at
http://www.f-secure.com/v-descs/sobig_c.shtml

Detailed description on the W32/Sobig.E@mm worm is available at
http://www.f-secure.com/v-descs/sobig_e.shtml

Detailed description on the W32/Sobig.F@mm worm is available at
http://www.f-secure.com/v-descs/sobig_f.shtml


DISINFECTION PROCEDURE
----------------------

1. Unpack the F-Sobig utility from the provided ZIP archive
either with WinZip or PkUnzip utilities. A trial version of
WinZip archiver can be downloaded from the following website:

http://www.winzip.com/ddchomea.htm
                                   
2. Run the unpacked F-Sobig.exe file from a hard disk to 
eliminate W32/Sobig.B@mm or W32/Sobig.C@mm, W32/Sobig.E@mm or
W32/Sobig.F@mm worm infection. You can run the utility by
either double clicking on it from Windows Explorer or you
can start it from a command interpreter (COMMAND.COM or
CMD.EXE) by typing its name at command prompt and pressing
'Enter' (for advanced users).

First the F-Sobig utility will kill W32/Sobig.B@mm or 
W32/Sobig.C@mm, W32/Sobig.E@mm or W32/Sobig.F@mm worm's process
in memory. Then the utility will remove the registry values and
the additional worm copies from the startup folders.

3. Reboot the system. After restart your system should be clean.

If you have F-Secure Anti-Virus installed, the utility will
temporarily disable on-access scanner to be able to disinfect
your system. After the utility completes disinfection, it
enables on-access scanner.

You can get a trial version of F-Secure Anti-Virus and the
latest updates for it from our website:

http://www.europe.f-secure.com/download-purchase/
http://www.europe.f-secure.com/download-purchase/updates.shtml



IMPORTANT NOTES
---------------

If Sobig infection is in a network environment, then the network 
should be temporarily taken down before all workstations and 
servers are disinfected. A single infected workstation can 
re-infect already cleaned computers.

If a computer with Windows NT, 2000 or XP operating system is 
being disinfected, please log in as Administrator or as a user 
with local admin rights, otherwise the F-Sobig utility might not 
disinfect the system correctly.

If you have Windows ME or XP, it is recommended to disable System 
Restore feature of these operating systems to prevent your 
computer from re-infection with Sobig worm. The fact is that 
System Restore feature of these operating systems might save the 
infected file into the special folder and copy it back to a hard 
drive it every time it's been deleted by F-Sobig utility. The 
instructions on how to disable System Restore feature are here:

Windows ME:
http://www.europe.f-secure.com/v-descs/sfc_dis.shtml

Windows XP:
http://www.europe.f-secure.com/v-descs/sfc_dis1.shtml

If you have any problems using this utility please contact us on 
'anti-virus-support@f-secure.com' address.
