Spam Carrying Trojan Viruses Hitting Everyone this Month   1/22/2007 - 1,620 views, 4 Comments

Summary: Spam laden with trojan viruses are running high this month - primarily the Small.DAM Trojan - so be extra careful. Common subject lines include those about "Storm Batters Europe", updates on Condoleeza Rice, and claims that Putin is dead and Hussein is alive. The subject lines vary, but the Trojan payload remains the same: executable files surreptitiously installed on your computer, with file names such as "Full Story.exe", "Full Text.exe", "Full Video.exe", "Video.exe", "Full Clip.exe" or "Read More.exe", or such.

Previous Article « “We Didn’t Start the Fire” claims Nokia as Cell Phone Blamed for Starting Fire and Critically Burning Man
Read Next Article » Meet ModBook - the Apple Mac Tablet Computer

Spam laden with trojan viruses are running high this month - primarily the Small.DAM Trojan - so be extra careful. The spam, masquerading as news flashes such as CNN updates and other news bulletins, carries compelling headlines such as death counts from storms battering Europe, or updates on Condoleeza Rice’s run-ins with foreign dignitaries.

The subject lines vary, but the Trojan payload remains the same: executable files surreptitiously installed on your computer, with file names such as “Full Story.exe”, “Full Text.exe”, “Full Video.exe”, “Video.exe”, “Full Clip.exe” or “Read More.exe”, or such.

Explains Graham Cluley of Sophos, “You think you’re reading a news report or you’re watching a movie. It’s the age-old technique that we’ve seen since the mid-1990s: Here’s something you want to look at. Look here!”

Unfortunately, it still works, and Cluley estimates that at least one in every 200 email messages worldwide includes this Trojan. That’s one out of ever 200 emails total, including all legitimate mail. Factor out legitimate email, and the percentage of spam carrying this Trojan is even higher. Factor in all other Trojans being delivered by spam and the odds start to get truly frightening.

Says Mikko Hypponen of F-Secure, “Trojan assaults of this scale are an unfortunate and increasingly common event.”

The point here is, whenever you receive any email with any attachment, don’t open the attachment. Don’t even save it to your computer, unless you are sure that the attachment genuinely came from someone you know.

Get FREE email alerts of new Internet Patrol stories!
    *We never share your email address with anyone

Email Address:
Date of first visit:
How you found us:

Subscribe
to The Internet Patrol on your cell phone    Email the link for this page to a friend!

Read more:

»  New Virus Scam Exploits London Bombings

»  Trojan Postcard Targets Windows Users

»  Top Ten Viruses and Hoaxes Reported to Sophos in May 2005 (News Release)

»  Worldwide Trojan Attacks in Progress

For additional similar stories check out our archives on Around the World, Spam, Virus & AntiVirus

 

4 Comments »

  1. Hi Anne,
    You say, “The point here is, whenever you receive any email with any attachment, don’t open the attachment. Don’t even save it to your computer.”

    Do your really mean that? What about a business associate sending me a document (e.g. a pdf file) and I’m aware of what he’s sending me and that he practices safe internet?

    Frank

    Comment by Frank Fleischer — 1/23/2007 @ 10:55 am

  2. Fortunately experienced computer users won’t take your recommendation (to not open any attachments) seriously. Otherwise they might as well stop using email altogether.
    I think it serves no useful purpose to overscare people. You should have said not to open executable files and told people waht the filename extensions for those are.

    Comment by Walter — 1/23/2007 @ 5:30 pm

  3. Actually, as someone who works regularly in tech support, you wouldn’t believe the calls we get. Most people aren’t “experienced computer users”, and those who are don’t need such simplistic cautions - but as a general rule, this is good advice. Especially as many viruses send themselves out as attachments “from” someone you know because they have compromised that person’s address book.

    Comment by Anonymous Cowherd — 1/23/2007 @ 5:39 pm

  4. Once you have it, tell us how to remove it.
    Andy

    Comment by Andy — 1/23/2007 @ 8:44 pm

RSS feed for comments on this post.

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


We apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day!

 
The Internet Patrol
Patrolling the Internet for You!