26 Email Worm Variants Use Blank Subjects to Spread All Over Asia
The family of WORM_RONTKBR.GEN (including WORM_RONTOKBRO and WORM_BRONTOK) discovered at the end of 2005 continues their spread this year. The scale of infection has expanded in Asia, while both the damage potential and distribution potential of these worms has been adjusted to High Risk by Trend Micro. This worm family is mainly spread through emails that contain blank subject lines, and using a fake Windows icon folder to trick users into activating the malware. Once clicked, the My Documents folder is also opened in order to hide the malware's execution.
Trend Micro Senior Antivirus Researcher Jamz Yaneza explained, "The BRONTOK/ RONTOKBR malware family is particularly hard to deal with. They immediately restart the computer system once any change to the registry are detected, preventing the normal operation of manual deletion commands, antivirus software and even personal firewalls. In addition, these worms also alter HOSTS files, preventing users from getting help from antivirus websites by redirecting them to other webpages."