...BLOCKED}4.94.88/~denirulz/2/2.exeIt then executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.Trend Micro detects the dowloaded file as: WORM_VB.MAF
...from a personal contact. What is noteworthy in this spam run is that the mail attachment is disguised as a 'virus killer' and is supposed to counter the virus W32.HEULAR. This executable file is currently detected as WORM_VB.GAW.
...critical update from Microsoft, the spam sample also comes with an attached executable file that claims to be the update patch and bug fixes for Windows XP Service Pack 2 and 3. The executable file has a detection name of WORM_VB.GAW
Alias:Email-Worm.VBS.Arica.a (Kaspersky), MIRC/Generic (McAfee), VBS.Winx.intd (Symantec), HEUR/Worm.IRCScript (Avira), Bat/Grade-A (Sophos),Description:This is a File Infector virus. It is detected by the latest pattern file.
Alias:Email-Worm.VBS.SSIWG.c (Kaspersky), VBA/Generic.src (McAfee), VBS.SSIWG.B@mm (Symantec), Worm/SSIWG.C (Avira), VBS/Ssiwg-C (Sophos),Description:This is a malicious VBScript. It is detected by the latest pattern file.
Alias:Email-Worm.VBS.SSIWG.d (Kaspersky), VBS.SSIWG.B@mm (Symantec), Worm/SSIWG.C (Avira), VBS/Ssiwg-D (Sophos), Virus:VBS/SSIWG.D (Microsoft)Description:This is a malicious VBScript. It is detected by the latest pattern file.