Sobig Worm Crawls Again in New Version
Annoying Sobig.E travels by e-mail attachment, antivirus vendors warn.
Todd R. Weiss, Computerworld
The latest version of the Sobig worm is making its way through computer networks around the world, apparently causing no direct damage but hogging bandwidth and IT resources in its path.
The new worm, called W32.Sobig.E@MM, has been showing up around the globe since yesterday, according to Graham Cluley, senior technical consultant for antivirus software vendor Sophos in Oxford, England. So far, it's only annoying, but it could be a precursor to more serious and damaging attacks, he says.
The worm affects network PCs that run the Windows 95/98/Me and Windows NT/2000 operating systems, according to Sophos. It spreads by scouring an infected computer's hard drive for e-mail addresses, in address books and even in Web browser cache files, and then sending itself out to the addresses it finds. It can spoof its sender's address, so the recipients believe they have gotten a message from someone they know.
Hassle, Not Harm
This is the latest in a series of Sobig worms in recent months, Cluley says. The new version is being sent as a .zip file, perhaps to allow it to spread in corporate environments where .exe and other file types are automatically blocked in incoming e-mail messages, he says. "It's hard to speculate" why the new approach was taken, he says.
While the virus does no actual harm, the spoofed messages can elicit anger from customers and users who receive the worm, Cluley says. He notes that a future version of the worm could work to set up infected machines for relaying spoofed messages that could be used for destructive purposes.
The new worm is set to automatically time itself out and stop spreading on July 14, according to Sophos. One possible reason for the ending date, Cluley says, is that the virus creator may believe it would provide a good defense if he is caught and prosecuted. "In our minds, that's nonsense, because a virus like this can spread around the world in a matter of hours," which makes an ending date a moot issue, he says.
Caution Urged
Marty Lindner, a team leader for incident handling at the CERT Coordination Center at Carnegie Mellon University in Pittsburgh, says the rapid spread of the worm since yesterday means recipients are still opening files in messages even when they have been warned countless times in the past that it's unsafe to do so.
The virus apparently spread too quickly for the antivirus vendors to react and update their antivirus products, he says.
"This is a good indication of the viruses winning" this round, Lindner says. "You can't always rely on antivirus as the silver bullet." Users need to pay more attention to incoming files and e-mail, and must not open files if they're not expecting to receive them for specific reasons, he says.
Also posting warnings, information, and fixes for the Sobig-E worm are vendors Symantec and McAfee Security.
The subject line of the worm identifies itself as an application, movie, document, screen saver, or application, in addition to other variants.
The prior version, Sobig-D, was first seen last week. Earlier versions of the worm, such as W32/Sobig-C and W32/Sobig-B, would sometimes purport to come from Bill Gates at Microsoft or from Microsoft technical support, according to Sophos.
- Sponsored Resource:Improve your network with the right mix of features, performance and pricing.
- Sponsored Resource:Growing your business requires the right tools. Dell's networking servers can help.
- Sponsored Resource:Thinking about a new Laptop? Lenovo has models to meet everyone's needs.
- Sponsored Resource:Twitter: A how-to guide for using Twitter as a business tool.
- Sponsored Resource:Smartphone security threats are on the rise. Is it time to safegaurd your device?

For more enterprise computing news, visit Computerworld. Story copyright © 2007 Computerworld Inc. All rights reserved.
Print 65% more pages than with refilled inks. Trust Original HP Inks. Hit Print Reliably.
Upgrade to IE 8
Solve Tech Issues Fast
Featured APC Accessories For Your System
10% Off Entire Cart at Online Store
-
APC Back-UPS ES
Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
- APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.
People who read this also read:
Best Prices on Security Software
Norton Internet Security 2009 - 1 User/3 PCPrice: $29.97
Norton Internet Security 2009 - 1 User/1 PCPrice: $15.95
Norton 360Price: $25.00
Internet Security 2009Price: $15.99
Norton Internet Security 2009 - 1 User/3 PC, Small BoxPrice: $20.50
Internet Security 2009Price: $24.95
- 2007 Microsoft Office Suites Comparison This paper compares and contrasts four suites of the 2007 Microsoft Office system: Microsoft Office Standard 2007, Microsoft Office Professional Plus 2007, Microsoft Office Enterprise 2007 and Microsoft Office Ultimate 2007. This paper is intended to help organizations understand the applications and capabilities offered, and to identify the suite that best fits their needs.
- Windows Vista Migration: The Business Proposition It's not so much a matter of "if" but "when" for most organizations regarding migration to Windows Vista. Laying the groundwork now for this migration can yield higher ROI than waiting until later. This Computerworld Technology Briefing explains it all.


