“Format before use”
Full article363 words · extracted from securelist.com · click to collapse
Some months ago I bought a HDD-based MP3 player from iRiver. When I plugged it into my computer I was hit with an unhappy surprise – a virus was detected.
I did some (re)search and it turned out that iRiver has shipped MP3 players containing the VBS.Saraci virus.
At first only the model I purchased seemed affected. However when I did some checking a few weeks later I saw reports concerning other models as well.
So why I am bringing up old news?
Because yesterday I got an e-mail from a person which stated that another brand of MP3 player named “Denver” also carries this malware, making this ‘old news’ new again. This person purchased the device as a Christmas present.
And what also makes the old news new: this concerns a Flash-based player instead of a HDD-based player.
VBS.Saraci utilizies a vulnerability not present in Windows 2000 or XP. The virus’s most important characteristic in this case is that VBS.Saraci copies itself into the root of every (network)drive as “folder.htt”, just as it was in the case with the above mentioned MP3 players.
This leads me to believe that the players have been tested on infected (pre XP) computer(s), which then in turn infected the MP3 players.
It’s not unlikely that we will see other, perhaps more destructive malware ‘pre installed’ on MP3 players. Therefore I would like to advise everyone to format your (just purchased) MP3 player before plugging it into the computer, as you otherwise might get infected.
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/format-before-use-wasnt-that-a-thing-for-floppies/29928/