Newest virus infects locals
Hundreds of local computer users have fallen victim to the latest virus wreaking havoc in cyberspace.
Local Internet Service Providers (ISP) and computer security companies yesterday warned customers to protect themselves against the `Sobig.F' virus, which is being credited with crippling Air Canada's passenger ticketing network and shutting down the New Zealand stock exchange.
The new virus, named `Sobig.F' by computer security companies, attacks Windows users via e-mail and file-sharing networks. It also deposits a Trojan horse, or hacker back door, that can be used to turn victims' PCs into senders of spam e-mail.
Last week's Blaster virus caused the Bermuda Hospital's Board (BHB) to turn off their external e-mail to stabilise the systems after their computer system was hit on Monday. BHB was hoping to have the system up and running by last evening but the presence of the `Sobig.F' virus now making the rounds the system could be susceptible.
Many local businesses are reeling from last week's Blaster worm virus and most companies are dealing with the "anti-blaster" Welchia or Nachi viruses that affected Island business systems running on Microsoft Windows, said Stephen Davidson, vice president of product development at QuoVadis, a computer security provider.
"I know there were quite a few businesses affected by viruses over the last week, but it looks like the Sobig virus will affect individuals," Mr. Davidson said.
`SoBig.F' comes up as an e-mail in inboxes with various subject lines including "Re: Details", "Re: Approved", "Re: Re: My details", "Re: Thank You!", "Re: That Movie", "Re: Wicked screensaver", "Re: Your application", "Thank you!" and "Your details". When the e-mail is opened the computer user is asked to "see the attached file for details". The attachment that is found in the body of the e-mail ends in .pif or .scr. The attachement must be opened for Sobig.F to infect the machine.
"Once it infects the computer Sobig includes a spam engine and the computer can then be used to send out mass mailings. It looks on that computer and uses e-mail addresses to send infected e-mails out," said Mr. Davidson.
Keith Forbes, who uses a local ISP, checked his e-mail twice and in a matter of one hour he said he had received 300 e-mails containing the virus-ridden attachment.
"The people who are sending these messages aren't even in my address book. I'm also getting messages sent to me from Logic and North Rock saying they've refused to send a message because it has a virus, yet I never sent the message in the first place. I've even received an e-mail from people I don't know with a Royal Gazette e-mail address, I feel like people must be stealing my addresses."
James Lapsley of ComputerWorks, a computer consulting firm and Royal Gazette columnist, said there were always new viruses and had received a few calls from customers affected by the virus that was detected in the US on Tuesday.
"This new virus is propagating through inboxes and people would think that e-mail users are being careless with their e-mail practices. But they aren't coming from that particular customer it's just that address books are being hijacked when people allow the virus to infect their computer."
Unlike Internet-based e-mail providers like Yahoo! and Hotmail, local ISPs do not currently have filtering devices to block out the unwanted spam that SoBig.F can generate.
"If you have anti-virus software on your computer it should be kept up-to-date in order to combat viruses because they are generally fast-moving."
Mr. Davidson recommended accessing Symantec's Norton Anti-Virus security response page at www.symantec.com or Trend Micro at www.trendmicro.com if the SoBig.F attachment has been downloaded onto the computer.
