Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Computer Security News
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Computer Security News The Latest Computer Security News

Reply
 
LinkBack Thread Tools
Old 01-25-2007, 05:39 PM   #1 (permalink)
Registered User
 
SpySentinel's Avatar
 
Join Date: May 2006
Location: The United States
Posts: 378
OS: Windows XP SP2


New Trojan: "Storm Trojan - Trojan.Peacomm"

*** As of January 22 Symantec Security Response has increased the threat level of "Storm Trojan" from level 1 (low) to level 3 (moderate) ***

In order to help users better understand the relatively recent trojan horse named Trojan.Peacomm, Symantec Security Response is providing a summary of the issues as well as additional information that may be useful in helping users diminish the threat.

The first signs of "Storm Trojan" were seen January 17, 2007. Symantec Security Response has seen a large increase in the number of infections of this Trojan as well as new versions that have additional capabilities. The Trojan horse arrives as an attachment to an email claiming to contain a video of one of several different recent news stories. The email itself will have no message body, but will have one of the following subject lines:

* A killer at 11, he's free at 21 and kill again!
* U.S. Secretary of State Condoleezza Rice has kicked German Chancellor Angela Merkel
* British Muslims Genocide
* Naked teens attack home director.
* 230 dead as storm batters Europe.
* Re: Your text
* Radical Muslim drinking enemies's blood.
* Chinese missile shot down Russian satellite
* Chinese missile shot down Russian aircraft
* Chinese missile shot down USA aircraft
* Chinese missile shot down USA satellite
* Russian missile shot down USA aircraft
* Russian missile shot down USA satellite
* Russian missile shot down Chinese aircraft
* Russian missile shot down Chinese satellite
* Saddam Hussein safe and sound!
* Saddam Hussein alive!
* Venezuelan leader: "Let's the War beginning".
* Fidel Castro dead.

Symantec also strongly urges users to be cautious of any unsolicited email that contains attachments that claim to be legitimate or interesting. The technique of using interesting subject lines or attachment names in emails in order to distribute malicious code is known as "social engineering". This technique has been used by threat writers for many years and, unfortunately, is often successful against unprotected users. The usage of recent news events as part of the email is especially common among these techniques.

The file attachment will be one of the following:

* FullVideo.exe
* Full Story.exe
* Video.exe
* Read More.exe
* FullClip.exe
* GreetingPostcard.exe
* MoreHere.exe
* FlashPostcard.exe
* GreetingCard.exe
* ClickHere.exe
* ReadMore.exe
* FlashPostcard.exe
* FullNews.exe

Given the changing nature of this threat it is likely that additional subject lines or attachment names may appear. Users are encouraged to not open emails such as these.

The attachment is actually a trojan horse that will install itself on the computer as a system driver and then will download other malicious programs from various computers on the Internet. The attachment and the trojan horse it contains will be detected.

Once installed and running, this Trojan attempts to establish communication with other infected systems on the Internet. This network is used as the distribution source from which the other malicious programs are downloaded.

New versions of this threat have been discovered that use "rootkit techniques" that attempt to hide the presence of this threat. Symantec Security Response will be releasing updated virus detection signatures later in the day on January 22 (Pacific time zone) that will detect and remove the rootkit capable variants of this threat. All previous variants of this threat are already detected and removed with existing virus definition signatures.

More detailed information on this threat can be found on the Symantec Security Response Blog.

At this point in time, Symantec Security Response has increased the threat rating of Trojan.Peacomm to medium, carrying a current rating of risk level 3 (out of a possible 5).
__________________
Proud graduate of GeekU - Learn how to remove malware at GeekstoGo.com

UNITE
ASAP
SpySentinel is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 01-26-2007, 12:58 PM   #2 (permalink)
Roaming To Help
 
Join Date: Nov 2006
Posts: 5,642
OS: Many


Yes I received these 5 days ago for 2 days in a row despite all the security software and no spam assassin blocked it nor sent it to junk automatically even after being instructed to do so.
Quote:
* Chinese missile shot down Russian satellite
* Chinese missile shot down Russian aircraft
* Chinese missile shot down USA aircraft
They are sent as EXE files as video's to watch. DON'T open them. I had a nifty program to view its content before executing it and so could tell that it was rogue. Yahoo mail has been affected by it most as per my experience.

Thanks SpySentinel.
Kalim is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 01-27-2007, 04:37 PM   #3 (permalink)
Registered User
 
SpySentinel's Avatar
 
Join Date: May 2006
Location: The United States
Posts: 378
OS: Windows XP SP2


NP, Im just trying to keep everyone informaed even though most people knew about it already
__________________
Proud graduate of GeekU - Learn how to remove malware at GeekstoGo.com

UNITE
ASAP
SpySentinel is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 08:59 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85