SOBIG.F Virus Promises Ill Be Back

On 21 August 2003 Symantec Security Response upgraded the W32.SOBIG.F threat to a category 4.

It is the sixth version of this worm.

SOBIG.F follows a computer worm known as "Blaster," or "MSBlaster," which infected at least 500,000 computers all over the world only a week ago. The "Nachi" worm which is designed to protect pcs from "Blaster" caused its own havoc including infiltrating unclassified computers on the Navy-Marine intranet and the collapse of the check-in system of Air Canada.

Associated Press has stated that 1 in 17 emails sent around the world has been infected.

According to Paul Wood of MessageLabs it took anti-virus companies at least 12 hours to release updated software to combat the worm.

W32.Sobig.F@mm is, in fact, a worm, not a virus. This worm sends itself to every email address it finds in files with the following extensions:

  • .TXT

  • .WAB

  • .MHT

  • .HTML

  • .HTM

  • .HLP

  • .EML

  • .DBX

The "SOBIG" worm is found in emails in your inbox with the following subject headings:

  • RE: DETAILS

  • RE: THANK YOU!

  • RE: YOUR APPLICATION

  • RE: YOUR DETAILS

  • RE: DETAILS

  • RE: APPROVED

  • RE: THAT MOVIE

  • RE: WICKED SCREENSAVER

I have personally received emails with all of these subject headings on a daily basis. The body of the email simply refers you to an attached file. It is absolutely critical that you DO NOT open this attachment. It is this attachment that contains the "SOBIG" worm.

The "SOBIG" worm is attached to files with the following names:

  • Movie0045.pif

  • Your_document.pif

  • Thank_you.pif

  • Document_all.pif

  • Details.pif

  • Document_9446.pif

  • Wicked_scr.scr

    < p>
  • Application.pif

The last day on which the "SOBIG" worm will spread is 9 September, 2003. Although this means email address collection and mass-mailing will stop at that date a computer infected with the worm will still try to download updates from master servers even after this date.

The worm affects Windows 95, 98, Me, Nt, 2000 and XP but leaves Unix, OS/2, Windows 3.x, Macintosh and Linux unaffected.

Thankfully Symantec Security Response has created a removal tool which is free to clean an infected computer. To access Symantec's free removal tool visit: http://securityresponse.symantec.com/avcenter/venc/data/w32.sobig.f@mm.html

< p>For a free virus scan visit: http://www.stop-sign.com

This past month's computer attacks follows a historical trend ? virus activity surges when college students have free time on their hands in the summer.

However, there is a suspicion that these kind of virus attacks may be driven by profit motives because worms such as SOBIG.F place a "trojan horse" on infected drives of unsuspecting pc owners which allows spammers to quickly distribute millions of unsolicited emails around the world.

Poorly designed software is declared the main cause of increased virus activity by computer designers as software is often distributed without appropriate amounts of testing.

Microsoft last year announced its intention to slow down software development so that software can be made more safe from infiltration.

Regardless of the cause, here is the reality:

  • Sobig.A was found on January 9 2003 with no expiry.

  • Sobig.B was found on May 18, expiring May 31 2003.

  • Sobig.C was found on May 31, expiring on June 8 2003.

  • Sobig.D was found on June 18, expiring on July 2 2003.

  • Sobig.E was found on June 25, expiring on July 14 2003.

  • Sobig.F was found on August 19, to expire 10 September 2003.

The spread of the SOBIG.F worm is being hailed the fastest ever.

History, therefore, tells us that Sobig.G is, in fact, just around the corner, faster and stronger than each of its predecessors.

As Sobig.F nears its expiry on 10 September 2003 I can almost envisage its evil grin as it declares, "I'll be back."

About The Author

Copyright 2003. Karin Manning. All Rights Reserved. Karin Manning is the webmistress of http://www.reprintrights4u.com and the publisher of Net Wealth, filled with up to the minute tips and techniques for growing your business online. To subscribe visit http://www.reprintrights4u.com and fill in the Newsletter Popunder on entry.

karin@reprintrights4u.com

In The News:


pen paper and inkwell


cat break through


Selecting a Personal Digital Assistant

A Computer in Your HandCarrying around an address book and... Read More

Does Microsoft Show Hackers How To Attack?

After another security hole recently surfaced in Microsoft's Windows operating... Read More

Image Formats: GIF, JPEG, BMP

When browsing the internet you are likely to come across... Read More

What Are You Looking For In A Cheap MP3 Player?

Are you stymied by the vast offerings in cheap mp3... Read More

HTML Explained: Part 1

Want to save money while promoting your web-based business? Of... Read More

What Exactly are Screensavers? - part II

Here are some tips on how to use screensavers:First of... Read More

Compile .BAT Files into Native Windows Applications (.EXE)

Since the DOS days, batch files have been one of... Read More

Buying A PC Flat Screen Monitor

For six years, my Samsung PC 13.8 inch SyncMaster conventional... Read More

Best PC Pocket GPS

Stop Getting LostOne of the greatest uses for a pocket... Read More

How to Buy a Plasma Television Set

Most people think that all you have to do to... Read More

Reliable File and Folder Sharing in Windows Xp

This tip is on sharing files and folders on a... Read More

Cisco Certification: Building Your Own Home Lab, Part I

CCNAs and CCNA candidates hear it all the time: â??Get... Read More

Cisco Certification: A Survival Guide To The Cisco Cable Jungle

One of the most confusing parts of beginning your Cisco... Read More

How To Become A True CCNA

I've worked my way from the CCNA to the CCIE,... Read More

MCSE 70-290 Certification Primer

Microsoft Certifications are one of the most widely acclaimed, pursued,... Read More

Review of Rio MP3 Players

Below you will find some useful information and comments about... Read More

The Benefits of the New Firefox Browser

You probably heard of the new Firefox browser version 1.0... Read More

Basic Problem in a PC

I have a p3 500MHz PC with 128MB RAM, 10.2... Read More

Customize Your Portable Player with an MP3 Player Accessory

Everywhere you look today people are listening to personal audio... Read More

COOKIES - What Are They!!

Cookies, not the kind that Mom makes, but the computer... Read More

10 Tips to Stay Safe and Secure Online

The Internet can be a dangerous place.While you're enjoying the... Read More

Selecting the Perfect Big Screen TV

Selecting a TV isn't as easy as it used to... Read More

Dynamite Comes in Small Packages - Tiny Personal Audio MP3 Players Pack Powerful Music Enjoyment

MP3 players are Hot! Playing music has come a long... Read More

Digital Cameras: How Many Pixels Do I Need?

With the bewildering number of digital cameras on the market,... Read More

Digital Cameras + Photo Printers = Quality Instant Photographs

In the 1950's and 1960's Polaroid's instant cameras were all... Read More

Home Video? Bring it On

So you got yourself a digital camcorder. If you want... Read More

EDTV vs HDTV

Confused by EDTV vs HDTV? We don't blame you. The... Read More

Bios Term

BIOS - Basic Input Output SystemThe central processing unit of... Read More

Advantages and Guidelines of Automated Testing

"Automated Testing" is automating the manual testing process currently in... Read More

Registry Tools Demystified

Not sure what Windows registry is or how it works?... Read More

This Page Cannot Be Displayed ? What to Do When Your Internet Breaks

The DNS (Domain Name System) servers are what your computer... Read More

Enhanced Web Browsing With Toolbars

As the Web grows more crowded and just plain "noisy"... Read More

Printing Multiple Copies of Photos

I do a holiday letter every year and send them... Read More