10 Sep 2003
SoBig.F is due to deactivate today, but experts are already waiting for the next variant of the virus to start spreading.
There have been six variants on the SoBig virus since it was first detected in January. Each successive version has displayed improved code and more adept social engineering, and future versions are expected to be developed along similar lines.
"To be honest I'm surprised we haven't seen one yet," said Professor Neil Barrett, technical director at security consultant IRM.
And Graham Cluley, senior analyst at antivirus specialist Sophos said: "Previous versions of the virus took two or three weeks to surface. We?re keeping an eye out for new versions and advising all IT managers to do everything to protect their systems by blocking .PIF attachments."
The ease in creating variants has led some to question the value of identity-based antivirus protection and move to alternative methods.
Heuristic analysis, which identifies suspicious activity rather than actual malware, is looking the most promising alternative.
Once activated, SoBig copies itself to Windows and edits the registry to ensure that it starts whenever the computer boots. All Windows operating systems from 95 to XP are affected.
All email addresses on the PC are collected and are then sent copies of the worm using the worm's own SMTP engine.
Email headers are spoofed to hide the location of infected machines, and the virus can also be spread using network shares.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Sneak peek at the forthcoming glass-based machine
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Project Manager – Retail / eCommerce / Prince 2 – City...
Project Manager - Business Change - Financial Services...
My client a leading IT Service Provider requires an AIX...
As a key UK and worldwide brand, we are constantly looking...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?