Urgent Security Alert – “VBMania” Email Worm

Watchguard LiveSecurity has released an urgent security alert for an email worm. It generally arrives with one of the following subject lines:

  • “Here you have”
  • “Just for you”
  • “This is the Free Dowload Sex Movies, you can find it Here”

The email contains a link to what appears to be a PDF document or WMV video, but is actually a link to a malicious Windows screen saver (.SCR) file. If you run the malicious .SCR file, it…

  • Copies itself to your Windows directory as CSRSS.EXE (the legitimate CSRSS.EXE is actually in your WindowsSystem directory), and modifies the Windows registry so it can restart after a system reboot
  • Sends itself to your email and IM contacts
  • Copies itself to mapped drives and removable USB media
  • Tries to disable popular security applications
  • Downloads and installs various other pieces of malware
  • Steals sensitive information (including passwords cached in your Web browser)

This worm does not appear to use any new techniques, and should be detected by most major antivirus vendors, so it is not cause for panic. You should, however, make sure you have the latest AV signature updates installed on your systems. Also, remind your users never to open unexpected attachments or click on unexpected Web links, even if they appear to come from friends, co-workers, or other trusted parties. The bad guys appear to be spamming this very aggressively, and it only takes one user to cause you a lot of headaches.

0 replies

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.