Oh, and the Trojan is called Trojan.Peacomm (Norton Internet Security still recognizes virus and trojans even though it's expired). On the Norton webbie, it says this. Discovered: January 19, 2007 Updated: January 23, 2007 12:05:43 PM GMT Also Known As: CME-711 [Common Malware Enumeration], TROJ_SMALL.EDW [Trend Micro], Small.DAM [F-Secure], Downloader-BAI [McAfee], Troj/Dorf-Fam [Sophos] Type: Trojan Horse Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Trojan.Peacomm is a Trojan horse that drops a driver program file to download additional security threats.
Trojan.Peacomm reportedly arrives as an attachment to a spammed email with the following characteristics:
Subject: One of the following:
A killer at 11, he's free at 21 and kill again! U.S. Secretary of State Condoleezza Rice has kicked German Chancellor Angela Merkel British Muslims Genocide Naked teens attack home director. 230 dead as storm batters Europe. Re: Your text Radical Muslim drinking enemies's blood. Chinese missile shot down Russian satellite Chinese missile shot down Russian aircraft Chinese missile shot down USA aircraft Chinese missile shot down USA satellite Russian missile shot down USA aircraft Russian missile shot down USA satellite Russian missile shot down Chinese aircraft Russian missile shot down Chinese satellite Saddam Hussein safe and sound! Saddam Hussein alive! Venezuelan leader: "Let's the War beginning". Fidel Castro dead.
Note: Due to a substantial increase in activity, Symantec Security Response raised this threat to category 3 on January 22, 2007.
Further reading: Trojan.Peacomm: Building a Peer-to-Peer Botnet
ProtectionVirus Definitions (LiveUpdate™ Daily) January 19, 2007 Virus Definitions (LiveUpdate™ Weekly) January 22, 2007 Virus Definitions (Intelligent Updater) January 19, 2007 Virus Definitions (LiveUpdate™ Plus) January 19, 2007 Threat AssessmentWildWild Level: High Number of Infections: More than 1000 Number of Sites: More than 10 Geographical Distribution: Medium Threat Containment: Easy Removal: Moderate DamageDamage Level: High Payload: Downloads additional security threats. Degrades Performance: Sent UDP packets may degrade performance. DistributionDistribution Level: Low Ports: UDP port 4000, UDP port 7871
Writeup By: Masaki Suenaga
Oh, and Trogdor, you recieved one of those emails on your gaggle account. I suggest you do NOT open it. I'm not even sure I recieved one of those emails, but I somehow got the virus-trojan anyway. >
Oh, I already opened it on one of the schools computers. Oh well, not mine
You would be surprised... You're not 30 feet in the air on CLIFFS. You mess up a trick and decide to bail out, YOU CAN'T. NON-RELEASABLE FOOTLOCKS. Skating, most of the time you're ground level up to 4 feet, maybe 5. Wanna bail? Jump off.
Yay! Jump of onto rock hard cement! Anyway, my favorite is either underwater basket weaving, or free fall ironing.