NOD32 and Antivirus News
Threat and Security News

Dangerous Malware E-Mail Making the Rounds


Have you received an e-mail message today with a subject like "White house hit by lightning, catches fire", "Saddam Hussein found dead," or "Paris Hilton found to be gay!"? Don't touch it; it's evil!

The body of the e-mails contains another off-the-wall statement like "US Soldier throws boy off cliff, villagers enraged" or "Bad press surrounds US Army as renegade soldiers open fire on civilians" along with a link that typically ends in ….de/r.html.

Clicking the link opens a page claiming to be "PornTube," a YouTube-like site specializing in porn movies. However, the site's entire objective is to install an ActiveX control and run a file named video.exe on your system, thereby installing a Trojan that will download additional malware. Sorry, guys, the YouTube-like videos and thumbnails are just static images; any click launches the malware file. According to MX Lab the Trojan is a variant of Trojan.Downloader.Win32Agent.tyw.

At the moment the malicious attack doesn't seem to be functional. I tried letting it run under the watchful eye of PC Tools's ThreatFire 3.5 and of Norton Internet Security 2008. I clicked links and tried to allow installation of the "necessary" ActiveX control, but only got 404 "Not Found" error messages, some in German.

There's no way to close the browser or use it as a browser at this point, so I had to kill it using Task Manager. And of course this exploit might be fixed so it does successfully download malicious software to your computer. If you get one of these outrageous messages, delete it immediately and do NOT click the link contained therein.

By Neil J. Rubenking

Original Story



NOD32 AntiVirus Products    Products    NOD32 FAQs    FAQs    Buy NOD32 AntiVirus Online    NOD32 4 Students    NOD32 Student and non-profit Discounts    NOD32 4 Non-Profit    NOD32 online purchase    Buy NOD32 Online    nod32 anti-virus

BETTERANTIVIRUS.COM℠ is a US based reseller of Eset Software's NOD32 Solutions
BETTERANTIVIRUS.COM℠ and it's contents is Copyright © - Web Your Business Inc.
BETTERANTIVIRUS.COM℠ & Web Your Business™ are trademarks of Web Your Business Inc.
ESET®, NOD32, ESET Antivirus, Smart Security® Trademark of ESET, LLC
All rights reserved by their respective owners.