Quantcast
PC World: Technology Advice You Can Trust
Find a Review
Free Newsletters
Receive the latest reviews, how-to's, news, and more.
Weekly Brief
Daily Downloads
Daily Technology News
WiFi Finder
Locate wireless services by a specific address, city, state, country, airport, or zip code.
RSS Feeds
Get our latest content via convenient RSS feeds.
Latest News
Today @ PC World
Become a PCW Member
Join the community and start enjoying the benefits:
  • Get tech advice from thousands of PC World Members
  • Rate and recommend the latest tech products
  • Share your thoughts in blog and article comments
  • Get free excerpts and exclusive discounts on Super Guides
Read More About: Worms

Sobig Worm Getting Even Bigger

Virus spreads via e-mail and network folders and could allow its creator to take control of your PC.

Paul Roberts, IDG News Service

Tuesday, January 14, 2003 10:00 AM PST
Recommend this story?

A new computer virus, Sobig, is spreading on the Internet, according to alerts posted by a number of antivirus software companies.

Sobig is a worm that uses e-mail and shared network folders to infect machines running Microsoft's Windows operating system, according to information posted on the Web site of Helsinki antivirus company F-Secure.

The worm arrives in e-mail messages from a single sender, big@boss.com, and is stored in attached executable files with names such as Sample.pif, Untitled1.pif, and Movie_0074.mpeg.pif, according to F-Secure.

Working Through Windows

When opened, the worm places a copy of itself into the Windows folder on the infected machine, creates a process to run the worm program, and modifies the Windows Registry so that the worm program will launch whenever Windows is started.

Once it has infected a machine, the worm searches for e-mail addresses in a variety of text files on the computer's hard drive. It uses those addresses to send out more copies of itself. Sobig also searches for any shared folders on networks that the infected machine may have access to and places a copy of itself in any network folder it can access.

Although the new worm does not appear to steal sensitive information from the computers it infects, antivirus companies warned that the worm does connect to a Web site hosted by Yahoo's GeoCities, from which it tries to download and execute other files, according to F-Secure.

The GeoCities Web page used by Sobig was modified recently to instruct the worm to download a Trojan horse program known as Backdoor.Delf that gives the virus writer and others control of infected machines, according to Mikko Hyppönen, manager of antivirus research at F-Secure.

GeoCities has been notified about the page by F-Secure as well as the CERT Coordination Center, according to Hyppönen. Yahoo was not immediately available to comment on the Sobig worm.

Increased Risk

The worm first came to the attention of antivirus companies on Thursday and began spreading slowly, Hyppönen said.

In recent days, however, the virus has spread more rapidly, and the number of machines infected by Sobig has grown.

As of Tuesday, F-Secure gave the worm a Level 2 ranking, indicating that it is "causing large infections" and putting it in a category with well-known predecessors such as the Klez worm.

Other antivirus companies upgraded their threat ratings for Sobig as well. On Monday, Symantec's Security Response upgraded Sobig from a category 2 to a "moderate" category 3 threat.

Simple Steps

The success of Sobig since it first appeared surprised Hyppönen, who said that Sobig is a comparatively simple worm that lacks many of the sophisticated features that allow a new generation of viruses to spread.

For example, Sobig always arrives in e-mail messages from the same sender, big@boss.com, unlike recent successful worms such as Bugbear or Lirva, which generated their own sender addresses, swapped in trusted sender addresses from sources such as antivirus vendors, or selected them at random from a long list.

In addition, the Sobig e-mail messages use one of only a small number of subjects--such as "Movie," "Sample," and "Document"--and attachment names. Recent worms use a far larger list of possible subjects and attachment names or generate their own at random, making it harder for antivirus software to identify such threats, according to Hyppönen.

Finally, Sobig requires e-mail recipients to double-click on the attachment containing the worm. Recent vintage worms like Lirva and Bugbear often take advantage of a Microsoft Internet Explorer and Outlook vulnerability known as the IFrame exploit, which allows e-mail attachments to launch without any user interaction when an e-mail message is opened or simply viewed in an e-mail preview pane.

"I don't know why it's spreading. I cannot explain it at all," Hyppönen said.

Stopping the Spread

Most antivirus software vendors updated their software to be able to identify Sobig by Thursday. With auto-update features standard on such programs--and even without such features--the Sobig filter was available to most users in plenty of time to stop the spread of the worm, Hyppönen said

One possible explanation is that, while not widespread, Sobig may be particularly effective at sending out copies of itself. Hyppönen said that an analysis he conducted of 20 Sobig-infected e-mail messages led back to just three infected machines.

A similar phenomenon was noted with the Klez worm when it first appeared, Hyppönen said.

While Sobig's outbreak has probably peaked, the worm was likely to linger on the Internet for a long time, Hyppönen said.

Antivirus software vendors posted instructions on their Web pages for removing Sobig from infected machines and recommended that all users update their virus definitions to protect against the new worm.


Recommend this story?
Related Searches: sobigwormwindowsviruse-mail
HP Ink Center
Bring improved color and brilliance to your printed material. Visit the Resource Center for more info...
CDW Solution Center
Deliver speed and scalability in your storage systems. Find out how at the CDW Solution Center.
Asus Notebook Center
Ultra-fashionable thin and light notebooks with SmartLogon Face Recognition. Find out more at the Asus Resource Center.
Intel Processor Technology
Which Intel Processor is Right for You?Centrino, Core 2 Duo, Core 2 Quad, Core 2 Extreme? Check out the Intel Technology Center for more info...
Are you a gamer?Visit the Intel's Gaming section for the latest downloads, hottest gaming events and to learn about Intel & Gaming.
See what Intel can do for Vista...Discover how Windows Vista technology work in the benchmarks with Intel Centrino processor technology.
VoIP Web Demo
Join Altigen for a Live Web Demo and learn how VoIP technology can improve your business communications.
The Future Sales Force - A Consultative Approach
This white paper discusses the challenges of selling complex products and services, and the new skill sets sales professionals must employ.
Latest News
When simple measures--such as restarting--fail to patch up your Mac, it may be time to call on Disk Utility's First Aid tools... 16-May-2008
Epson's Stylus Photo R1900 uses pigment inks to produce long-lasting, borderless photographic prints at sizes up to 13 by 19... 16-May-2008
MacProVideo has released a new video tutorial for users of Apple's Logic 8 digital audio workstation. 16-May-2008
Ableton has released an LE version of its Live 7 sequencer. Ableton Live 7 LE is based on the same principles as its... 16-May-2008
Silicone cases provide the best of both worlds--a protective covering without adding a lot of bulk. In this week's iPod case... 16-May-2008
In my recent Macworld video blog, I discussed how to install and use WebKit, which is a version of Safari that includes the... 16-May-2008
Tidy Up, a utility that allows you to search for duplicate files and folders, has been updated adding support for Mac OS X... 16-May-2008
Big Fish Audio has released one of its most original music loop packages for users of music creation applications compatible... 16-May-2008
As a simple and effective way to backup a drive, Time Machine has been a welcome new feature in Leopard. However, it does not... 16-May-2008
iPass partners with likely first in-flight broadband firm over U.S. for what could be a highly affordable fixed monthly service plan, including Wi-Fi hotspots, for frequent travelers. 16-May-2008

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)