ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Sobig.F lingers as cure backfires

Graeme Wearden ZDNet.co.uk

Published: 28 Nov 2003 17:50 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Sobig.F is still rampaging around the Internet, two months after the virus was supposed to have terminated itself.

Email security firm MessageLabs said on Friday that Sobig.F was the third most active virus in November, with some 264,000 copies being detected by its email virus-scanning servers.

Although this activity is well below the virus's peak, it is still surprising as Sobig.F -- like several other members of the Sobig family -- contained a built-in shutdown date that was supposed to prevent it propagating after 10 September. According to MessageLabs, Sobig.F's continued proliferation is due to a combination of factors, including the successful efforts that prevented it wreaking even more havoc and the fact that many PCs are set to the wrong date.

The first Sobig virus appeared in January 2003, and was followed by many variants. Sobig.F was first detected on 19th August. It propagated by email, and caused massive disruption to corporate networks, but its real purpose was to take over computers.

Once infected by Sobig.F, a PC would periodically link to 20 Web servers that has been individually hacked by the virus author, and try to download a file. Some experts believe this downloaded code could have precipitated a massive denial-of-service attack, but this was foiled because the compromised servers were taken offline in time.

MessageLabs believes that this may have prevented some copies of Sobig.F from terminating themselves. "The plug was pulled on the target servers before the PCs that were infected by Sobig.F could download the final bit of code," said Paul Wood, principal information security analyst at MessageLabs. "Once that file had been downloaded and the PC was at the final stage, they would have stopped propagating more copies of Sobig.F to avoid anyone spotting the fact that they'd already been compromised." Instead, Wood believes, PCs infected with Sobig.F are still spreading the virus and aren't checking the date.

Because of the built-in shutoff mechanism, a PC receiving a copy of Sobig.F today should not try to forward it on. But another factor behind Sobig.F's longevity could be that some PCs are set to the incorrect date. While networked PCs will typically take their date and time from a central server, home PCs are reliant on their internal clock and the small battery that powers it.

If the battery runs down and isn't replaced, a computer will not know the correct date or time. According to MessageLabs, many such PCs are out there, connected to the Web, being infected with Sobig.F by computers that were compromised back in August and haven't switched their virus activity off. It is these PCs that are pumping out more copies.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
49 out of 145 people found this useful


Full Talkback thread

1 comment

  1. As George Krantz would have it, "din daa daa, din... Glenn Slawson

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Firewalls Engineer Lead

Good working knowledge of anti virus technologies. Desirable - Fully Securtiy cleared - if you do not posess SC clearance then this can be resolved ...

Infrastructure Manager - Leeds - 60000

You main objective will be to oversee the configuration and set-up of new systems and PCs, firewall administration, anti-virus and anti-spam systems, ...

IT SUPPORT ANALYST - 23,500 + 380 pcm car allowance

Based in North London, your main part of your role will be the provision of IT Support to the region and advice to a desktop population of around ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment