Sobig.F prevention and cure

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

COMMENT
Sobig.F (w32.sobig.f@mm) spreads via email and shared network files and could slow email servers with excessive traffic, so it rates a 7 on the ZDNet Virus Meter.

This worm affects only Windows computers, not Mac, Linux, or Unix systems. Like its siblings, Sobig.F has a built-in termination date, 10 September, 2003, and can attempt to retrieve, download, and finally execute a Trojan to steal credit card numbers and other personal account information. But Sobig.F differs in that it appends garbage characters to the end of the infected file, making it harder for antivirus products to recognise Sobig.F.

How it works
Sobig.F arrives as an email with the following characteristics: The From and To addresses are collected from infected PCs, from files ending with the extensions .dbx, .eml, .htm, .html, .txt, and .wab.

The Sobig.F subject line reads:

  • Re: Details
  • Re: Approved
  • Re: Re: My details
  • Re: Thank you!
  • Re: That movie
  • Re: Wicked screensaver
  • Re: Your application
  • Thank you!
  • Your details

Its body text reads:

  • See the attached file for details
  • Please see the attached file for details.
The file attached to Sobig.F is:
  • application.pif
  • details.pif
  • document_9446.pif
  • document_all.pif
  • movie0045.pif
  • thank_you.pif
  • your_details.pif
  • your_document.pif
  • wicked_scr.scr

When executed, the worm will add the following to the system registry:

[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TrayX" = %windir%\winppr32.exe /sinc
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TrayX" = %windir%\winppr32.exe /sinc

Prevention
In general, do not open email attachments without first saving them to hard disk and scanning them with updated antivirus software. If you do not have automatic antivirus signature file updates, contact your antivirus vendor to obtain the most-current antivirus signature files that include Sobig.F.

Removal Most antivirus-software companies have updated their signature files to include this worm. The updates will stop the infection upon contact and, in some cases, will remove an active infection from your system. For more information, see Central Command, Computer Associates, F-Secure, McAfee, MessageLabs, Norman, Panda, Sophos, Symantec, and Trend Micro.

Talkback

We Silver Surfers haven't a clue what you are talking about! We rely on Norton Antivirus at $38.00 a year (real money £25!!) and hope they are on the ball! Whilst we are talking to the industry it would be great if the whole of the computer industry had a translation service from geek talk. When we submit a query to AOL helpline, and this probably applies to others, the answer might as well be in Chinese (probably better if it was, as we worked there for two years!!)

via Facebook 21 August, 2003 21:11
Reply

I still get emails from postmaster like everytime I check my email at yahoo saying that a message containing a virus was intercepted. I am kinda of paranoid that this worm is sending emails to emails in my address book.

is there a way to stop these emails from coming to my inbox??

via Facebook 21 August, 2003 21:43
Reply

I have a new computer with windows xp, today I was sent around 40 e-mails with th`re-details` and `wicked screensaver` . I didn't attempt to see any `attatchments` I just opened a few e-mails until I cottoned on.
Does that mean I have still been infected?
I don't have any anti-virus programs.

via Facebook 21 August, 2003 22:20
Reply

I found over 140 e-mails from Sobig in my in-tray this morning. Is there a patch available to deter the virus?

via Facebook 22 August, 2003 00:29
Reply

We were completely unaffected byt the Sobig virus.

However, the rapid spread of this virus should be a wakup call to the Internet community. It doesn't take a rocket scientist to prepare for such an outbreak. Keep your virus definitions and patches up-to-date.

Our company was completely unaffected by the Sobig strain of viruses. We use Merak Mail Server ( http://www.MerakMailServer.com ) which has an integrated Antivirus that is capable of scanning 2000+ messages per second.

In addition, it has what is called an "Active Update" service which ensures that our virus definitions are always up-to-the-minute, up-to-date by queueing our server to download the latest virus definitions the minute it a new definition is released.

via Facebook 22 August, 2003 02:10
Reply

Contrary to your report, my Mac is infected with this virus. I received 85 messages in less than an hour and several more from other servers asking me to stop sending spam!

via Facebook 22 August, 2003 13:14
Reply

Yes, get Norton Anti-Virus and make sure you have all of the updates. Also use Aol as your Service Provider they have built in email anti-virus protection.

via Facebook 22 August, 2003 14:18
Reply

Sounds like you work for them. Or are you on commission?

My computers also haven't being attacked by a virus. But I don't need any virus software to protect it. Just a proper operating system that doesn't allow them in the first place.

via Facebook 22 August, 2003 15:39
Reply

I'd just stay away from all attachements, and delete unnnecessary emails til this is over.

via Facebook 22 August, 2003 19:20
Reply

as long as u realise that aol technical support is pretty useless, and they only work from set scripts then you might feel a little happier............. yes i too use aol :-( though i have to admit i am pretty clued up about pcs)

via Facebook 23 August, 2003 12:00
Reply

if you have an attachement in an email from someone you dont know, delete it!
if its from someone you know, email them and ask if they sent it.

stevan

via Facebook 23 August, 2003 13:47
Reply

I have a mac system and I opened this Re:thank you email. it was adressed from a friend!! Ever since my mail box has been full of undeliverable message errors. Everything I have read says it shouldn't effect my system, but there is something weird going on!

via Facebook 24 August, 2003 02:53
Reply

hi i have had this for a few day xp has an anti virus progrom on one of thier disks norman anti virus load it onto your system and bingo bye bye virus

via Facebook 25 August, 2003 16:17
Reply

I am working with Linux but I have an email account at www.web.de. Apparently, SoBig.F manages to send mails in my name although I never opened any attachment., and it is Linux anyway. My email is boris.hennig(a)web.de; I am getting enough sopam so I didn't want to give the real one in the form :-)

via Facebook 25 August, 2003 21:14
Reply

Was Sent Email to today. with RE Thankyou but did not open attachment or it did not have one . is it a hoax. Is computer safe I deleted staright away also have norton security but still worried.

via Facebook 25 August, 2003 22:00
Reply

having been on the internet for 6 years now and not being and adherent of anti-virus software, (i don't use the stuff) here are a few tips that might help home users.

use a firewall. preferably one that utilizes stateful packet filtering techniques.

uninstall windows visual basic scripting host.

check the file attributes for wsock and winsock files in windows directory/s and uncheck the archive box and check the read-only box instead. these files to not have to be written to for the socket to operate properly.

empty your address books and keep your email addresses in a text file. use copy and paste from the text file to your email client.

stay apprised of current "threats" and familiarize yourself with pertinent details such as subject lines, file sizes and other information involving current worms, trojans and viruses.

don't open email from people you don't know.
treat it the same way you would if it arrived in your snail-mail box. return to sender or delete. definitely do not open attachments forwarded from unknown senders.

use web based email that provides anti-virus filtering for both inbound and outbound messages.

learn how to create filters and use them in your email client.

when using isp-based email, truncate your incoming email to say 2kb. that way you can "look it over" and inspect the headers before downloading the entire contents from your server.

knowledge only constitutes power when it is put into practical application.

via Facebook 25 August, 2003 23:27
Reply

If you're on a Mac, you cannot be infected. But if you read the report, you'll see that the virus fakes the sender address when sending out emails. So if a friend of yours has an infected machine, and you're in their address book, you could be the recipient of the bounces and complaints. This is unfortunate, but does NOT mean that your machine is infected.

via Facebook 26 August, 2003 09:02
Reply

My suggestion as an IT Manager is to configure your Mail Server or email client to remove all attachments that can contain executable instructions, i.e. .EXE .SCR .VBS .COM .BAT .PIF etc

If you virus scan all the attachments you recieve you should be okay, as long as you keep the definitions up-to-date!

I have received hundreds of emails this morning (obviously without attachments) and I can see that this is a huge worm!

via Facebook 26 August, 2003 15:40
Reply

If you don't know yet that your pc is infected and say your anti virus software hasn't picked it up, are there any commands that you can run that will show it is present??

via Facebook 26 August, 2003 21:03
Reply

this sobig virus poses a worldwide threat to every one, does it affect aircraft as well

via Facebook 26 August, 2003 21:35
Reply

Avoid Norton AV, McAfee, and F-Protect. They all let in virus's even though they were fully updated. Norton let in and refused to recognize the SDbot trojan virus, causing me to lose around 3 gig of data overnight. F-protect let in and refused to recognise the w32 virus allowing me to spread it to friends and family and McAfee let in another trojan (can't remember the name). So far Sophos AV hasn't let me down.

via Facebook 27 August, 2003 13:50
Reply

I have stopped the postmasters by setting up the email filter to delete emails containing the words used by this virus.

via Facebook 28 August, 2003 01:15
Reply

Macs' were affected to by this worm. But I can't seem to find a solution for this.

via Facebook 2 September, 2003 09:06
Reply

So easy to prevent all these viruses go to www.grisoft.com and get free anti virus software with regular free updates Sorry folks its you own fault !

via Facebook 3 September, 2003 08:39
Reply

I have yahoo mail and have been getting slammed w/ SoBig since yesterday september 4th. Some of the emails have my addy listed as sender and receiver! I have scanned w/ eanthology and microtrend and my system shows clean for now

Ldovey

via Facebook 5 September, 2003 15:25
Reply

i use a web based e-mail account and that has been overrun with returned e-mail messages all with the sobig attatched files.
i traced the original connection to where they came from and it was someone using a static ip address (adsl/broadband/cable) i contacted the isp responsible for maintaining this connection several times but with no response ,until i started returning the disabled virused e-mail to them ,then i got a email saying they would contact the person responsible .and sort it but they havent yet

via Facebook 10 September, 2003 13:18
Reply

KEV - TECHIE ,I HAVE JUST GOT NEW COMPUTER WITH WINDOWS OFFICE XP 2000. SUBSCRIBED TO BROADBAND AOL. THE POP - US SHOCKED ME AND NOW IM REALLY WORRIED ABOUT VIRUSES . CANT REALLY AFFORD TO SPEND ANY MORE MONEY AND WAS INTERESTED TO READ THAT YOU DONT NEED ANY VIRUS SOFTWARE PROTECTION JUST 'A PROPER OPERATING SYSTEM.' HOW DOES THIS WORK ? IN EASY TERMS HOW DO I SET THIS UP ON MY COMPUTER ? ANY HELP APPRECIATED

via Facebook 5 October, 2003 12:49
Reply

i had norton virus & utilitys they are just quick fixes get rid & get zone alarm & use big fix no problems on the net then best thing i did (be safe peeps)

via Facebook 14 October, 2003 20:45
Reply

After being virused earlier this year by the Sobig.f virus, and noticing bouncebacks in my email. my Norton couldn't detect it, and the easiest way to get rid of a virus is to format your hard disk drive., but then you lose all your data if you didn't have it backed up.

via Facebook 15 October, 2003 20:16
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

1 hour ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

3 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

4 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

4 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

5 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

6 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

7 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

13 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

15 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

15 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

17 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

17 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

18 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

19 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

19 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

19 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

20 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

20 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

20 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

20 hours ago by Moley on ACTA: Facts, misconceptions and questions