This thread's last reply is from September 16, 2010, 5:02 AM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
I've also been watching this situation very closely since Thursday evening,and I also received an advisory from McAfee this morning,I was looking for some samples of this worm yesterday to try to assist the good folks over at Malwarebytes and Safer Networking in anyway I could but have been unable to find any yet.I have read that so far McAfee,Symantec,Sophos,Trend Micro & Kaspersky have updated their definitions to protect their customers.If anyone hears of any new developments on this threat I'd like to know please keep me informed and I'll do the same.
This Information may need to be verified
Symantec's products detect it as W32.Imsolk.B@mm
McAfee detects it as “W32/VBMania@MM” in their 6101 DATs
McAfee-GW-Edition as Artemis!2BDE56D8FB2D
Sophos detects the malware as W32/Autorun-BHO
Trend Micro as WORM_MEYLME.B
Kaspersky detects it as Trojan.Win32.Swisyn.algm
that's what this thread in the News Desk is about
PLEASE READ! - Propagate like it's 1999!
there a some links in that thread with more info about this new threat including a link to the Virus Total report
Update:
There appears to be evidence this worm could be the work of a terrorist organization known as “Brigades of Tariq ibn Ziyad.” a self-proclaimed "cyber-jihad" organization.I've been researching this all day and everywhere I look suggest that this group is behind this.I read that although the virus was written in English, the writer’s computer was set to use an Arabic character set.Several underground forum communications have linked “iraq_resistance” to the malware creation as well as the terrorist (electronic jihad) organization “Brigades of Tariq ibn Ziyad.”
Much of the worm's code is identical to an earlier piece of malware that was released last month, and both worms refer to a Libyan hacker who uses the name Iraq_Resistance, who has been trying to form a hacking group called Brigades of Tariq ibn Ziyad, said Joe Stewart, director of malware research with SecureWorks....Stewart discovered a username of "Iraq_resistance" embedded in the binary of the malware that was similar to one sent out in August... Stewart says he can't be 100 percent sure that the malware is tied to this group, but there are several obvious connections besides the username in the binary code, including the fact that the backdoor downloads a Trojan that's set to connect to a server of a similar name of the organization, and that the password-stealing tool downloads used in the attack are all written with Arabic-language documentation.
http://blogs.forbes.com/andygreenberg/2010/09/10/here-you-have-virus-may-be-linked-to-libyan-hacker/?boxes=Homepagechannels
http://pandalabs.pandasecurity.com/here-you-have-worm-linked-to-electronic-jihadists/
http://www.darkreading.com/insiderthreat/security/attacks/showArticle.jhtml?articleID=227400137
http://www.computerworld.com/s/article/9184718/Cyber_jihad_group_linked_to_Here_you_have_worm?source=rss_news
http://www.hackinthebox.net/hacking/cyber-jihad-group-linked-to-%E2%80%98here-you-have%E2%80%99-worm.html
Detection of the first variant of “Here You Have” Email Worm
http://malwareresearchgroup.com/2010/09/detection-of-the-first-variant-of-here-you-have-email-worm/