The Worm Has Turned

Written by Eric Olsen
Published August 24, 2003

Sobig.F shrivels and fizzles:

    The fast-spreading Sobig.F e-mail virus slowed on Sunday and failed for a second time to launch a remote data attack using thousands of infected personal computers, computer security experts said.

    Sobig.F, which first emerged on Aug. 18, was programmed by an unknown creator to unleash a data attack at noon PDT on Sunday.

    But with the trigger — a computer program unwittingly installed on 20 poorly defended computers mostly in the United States and Canada — deactivated on Friday, Sunday's attempt was a non-event, according to reports from technology security company Symantec Corp. and Craig Schmugar, virus research engineer at rival Network Associates Inc. .

    An initial automated barrage planned for Friday was averted after government and security industry experts raced to diffuse the digital trigger that could have taken control of more than 100,000 infected computers and possibly crippled the Internet.

    The number of infected computers worldwide fell dramatically from Saturday to Sunday, declining by one-third in the 24-hour period to 98,205 from 145,264, according to a virus map from anti-virus software maker Trend Micro. [Reuters]

With this mass infection forcing even casual Internet users to pay attention and learn to prevent or at least to clean up after an attack, maybe a critical mass has finally been reached regarding security that will prevent further wildfire outbreaks. But it's not over:
    "Now, it's a case of a big clean-up for (technicians) and learning a lesson for the next time there's an e-mail worm," said Graham Cluley, senior technology consultant at British-based Sophos Anti-Virus.

    The next time could be in weeks. SoBig.F is the sixth version of a virus that first appeared in January. Each one has been stronger than the previous, security officials said.

    SoBig.F is programmed to expire on Sept. 10.

    "We would expect to see the next one some time after September 10, not necessarily on September 11, but within the ensuing weeks," Cluley said.

Besides purchasing an anti-virus program, make sure you have the latest security patches from Windows, and just to make sure it would be a good idea to to run a removal tool on your computer like this free one from BitDefender.

Career media professional Eric Olsen is honored to be the founder and publisher of Blogcritics.org, which, quite frankly, rules - as do his wife and four children.
Keep reading for information and comments on this article, and add some feedback of your own!
The Worm Has Turned
Published: August 24, 2003
Type:
Section: Sci/Tech
Filed Under: Sci/Tech: Software, Sci/Tech: Internet
Writer: Eric Olsen
Eric Olsen's BC Writer page
Eric Olsen's personal site
Spread the Word
Like this article?
Email this
Submit to del.icio.us Save to del.icio.us
RSS Feeds
All RSS Feeds (240+)
Comments on this article
BC articles by Eric Olsen
Sci/Tech: Software
Sci/Tech: Internet
All Sci/Tech Articles
Eric Olsen's personal weblog
All BC articles
All BC Comments

Comments

#1 — August 24, 2003 @ 20:41PM — Cindy Collins Smith [URL]

Now, if only I'd quit getting virus infected emails! I deleted 39 of them this morning. (I deleted over 100 on Friday and a good number yesterday).

And the really disconcerting thing is that somebody is apparently spoofing my email address. My computer is clean, but I keep getting messages from computers that detected the virus in an email that I never sent but which is coming from my website's email contact address.

Spammers just love me. The feeling is not mutual.

#2 — August 24, 2003 @ 20:55PM — Eric Olsen

It sucks and continues to suck, but the tide has turned.

#3 — August 24, 2003 @ 21:44PM — Michael Croft [URL]

Cindy:
Sobig.f takes a random address from the infected machine and uses it as the "from:" header (and "envelope-sender:" as well). Anyone who writes or configures a mail server anti-virus package to send an error to the spoofed "sender" is a mouthbreathing homonculous. Anyone who writes or configures a mail server anti-virus package to forward the virus to the spoofed "sender" should be hanged, drawn, and quartered.

I'm so sick of these things.

#4 — August 24, 2003 @ 21:45PM — TDavid [URL]

What really sucks is when legitimate email with legitimate attachments gets caught in the combines. Maybe Pirillo is right, email is dead.

Want comments emailed to you? No spam, promise! Address:

Add your comment, speak your mind

(Or ping: http://blogcritics.org/mt/tb/7792)

Personal attacks are not allowed. Please read our comment policy.





Remember Name/URL?

Please preview your comment!

Fresh
Articles
Fresh
Comments