You are here: silicon.com > Software > Malware

Malware

Shut down Sober-infected PCs, ISPs urged

'Clean up your users' act... '

Tags: sober, sober virus, virus, hate mail

By Tom Espiner

Published: 10 January 2006 08:45 GMT

ISPs were urged on Monday to check their user traffic patterns to locate and shut down machines infected with the mass-mailing Sober worm.

Although Sober is no longer trying to replicate, antivirus company F-Secure believes ISPs must warn infected customers so they can disinfect themselves.

Infected PCs were programmed to download new instructions from the internet last week, which would have heralded another attack. This update did not actually appear online but infected machines are still trying to download it.

F-Secure said on its blog: "ISPs: we urge you to check your user traffic patterns. Locate the users that produce an unlikely large amount of constant hits to people.freenet.de, scifi.pages.at, home.pages.at, free.pages.at and home.arcor.de. Contact these users and let them know they are likely to be infected with Sober and they should clean up their act."

Computers infected by Sober are likely to contain spyware, or could have been turned into zombie PCs and used to send spam or launch denial of service attacks. They could also download a Sober update in the future, sparking another mass-mailing attack.

F-Secure said ISPs should let customers know they have been infected automatically and redirect users to sites so they can disinfect their machines.

Mikko Hypponen, director of antivirus research at F-Secure, said: "Most affected computers belong to home users, who have no idea they've been infected. ISPs are in the best position to distinguish infected users.

"Service providers can automatically shut down a user connection, and specify that to get back online users have to follow certain steps, for example, by visiting the Microsoft site for the latest updates. ISPs can automatically shut down what they want and can still connect users to Microsoft."

ISPs have an economic motive to inform users their machines have been compromised, Hypponen argued.

He said: "It might be hard for ISPs to find the motivation to do it, because it's a lot of work and a thankless job as no one wants to hear they are infected. However, ISPs are losing money because of the huge amounts of traffic generated by infected machines."

But AOL said it would not be contacting consumers, as it put more emphasis on prevention of infection through email filtering and blocking links to certain websites. People who had been infected had access to McAfee antivirus services, AOL said.

Jonathan Lambeth, director of communications for AOL UK, said: "We have on occasion made outbound contact with members in specific situations, such as the Mydoom worm, but have no plans to do so in this instance as we focus our efforts on prevention."

Lambeth added: "Our anti-spam systems, which block more than 1.5 billion spam emails each day, block a large number of emails containing links to the Sober virus in the first place.

"Links are default-disabled on emails within AOL to prevent casual clicking on rogue links, requiring a more positive action to click through, although this setting can be switched off if the user prefers."

Tom Espiner writes for ZDNet UK

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Systems Administrator, Journalism Operations, Future Media and Technology

Apache, youll have extensive knowledge of HTML and cross-platform compatibility issues, and an understanding of the factors affecting download speeds ...

Senior Software Engineer (JAVA/J2EE)

In addition to our flagship site www.shopzilla.com.co.uk, .de, .fr) and well known BizRate brand (www.bizrate.com), Shopzilla also powers shopping ...

SAP Project Manager required for Global SAP rollout! 75k+!

We do also have some exclusive SAP roles which are not advertised on these boards so for more information contact Jodie Franklin on the number above ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: