'Here you have' e-mail worm spreads quickly

The worm links to a malicious screensaver file

Security experts warned Thursday of a fast-spreading e-mail worm, the first large outbreak of this type in nearly a decade.

The worm appears in e-mail messages with the subject "Here you have," and contains what seems to be a link to an Adobe PDF file. In fact the link takes the victim to a Web page hosted on the members.multimania.co.uk domain that then tries to download a screensaver (.scr) file. If the user agrees to installing that file, he is then infected by the worm, which mails itself to his e-mail contacts.

It bogged down corporate e-mail systems on Thursday morning as victims ended up inadvertently spamming their coworkers, overwhelming some servers. The SANS Internet Storm Center, a volunteer-run security intelligence organization, received numerous reports of networks being overwhelmed by the worm, according to said Marcus Sachs, a director with the group. "It seems to be in the category of extremely widespread," he said.

ABC News reported that NASA (the National Aeronautics and Space Administration), Comcast, AIG, Disney, Proctor & Gamble, and others had been hit by the outbreak, and several system administrators contacted by the IDG News Service reported significant headaches.

As of Thursday afternoon, the worm was undetected by most antivirus programs, according to the VirusTotal Web site.

The worm is similar to the ILoveYou and Anna Kournikova worms, which spread in 2000 and 2001, and is a type of malware that has not been a major problem since around 2002, according to David Cowings, a senior manager with Symantec Security Response. "It looks like we've had a resurgence of mass-mailing worms," he said.

In fact, "Here you have" is the same subject line used by the Anna Kournikova worm.

This latest worm seems to do nothing more than send itself out, using the victim's contact list, Cowings said. "It appears to be mailing itself to all of the mailing lists that are in someone's contacts. It may also go to individuals," he said. The worm appeared to be affecting Outlook e-mail users, but it's not clear if it is also affecting users of other mail programs.

The worm also spreads by copying itself to the computers' local drives, (C: and H:) as well as well as drives that are shared over the network, Microsoft said in an analysis of the infection, posted Thursday.

The body of the e-mail typically says something like, "Hello... this is the document I told you about, you can find it here." Because the worm is spreading via contact lists, the e-mail often comes from someone the victim knows.

Symantec started blocking the worm at around 10:30 a.m. Pacific Time Thursday and quickly stopped 65,000 messages, according to Cowings. The number soon ballooned beyond that, but the worm may now have a hard time spreading, because the malicious file on multimania.co.uk appears to have been taken down, Cowings said.

Multimania.co.uk is a free website hosting service run by Lycos.

In an alert sent out to customers Thursday, McAfee recommended blocking .scr files at the Internet gateway. "McAfee has received confirmation that some customers have received large volumes of spam containing a link to malware, a mass-mailing worm identified as VBMania," the note reads. "The symptom reported thus far is that the spam volume is overwhelming the email infrastructure."

Robert McMillan covers computer security and general technology breaking news for The IDG News Service. Follow Robert on Twitter at @bobmcmillan. Robert's e-mail address is robert_mcmillan@idg.com

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags securityMicrosoftinternetmalwaresymantecmcafee

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Robert McMillan

IDG News Service
Show Comments

Cool Tech

Breitling Superocean Heritage Chronographe 44

Learn more >

SanDisk MicroSDXC™ for Nintendo® Switch™

Learn more >

Toys for Boys

Family Friendly

Panasonic 4K UHD Blu-Ray Player and Full HD Recorder with Netflix - UBT1GL-K

Learn more >

Stocking Stuffer

Razer DeathAdder Expert Ergonomic Gaming Mouse

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?