My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets


Back to the news list

July`07 virus and spam review by Doctor Web, Ltd.

August 1, 2007

Virus Monitoring Service of Doctor Web, Ltd. reports on virus events in July 2007.

July turned to have witnessed not one outbreak of virus events. The first among them to be mentioned is a widespread spam-distribution of congratulating messages headlined as “You've got an e-card from a Class-mate! (or a Neighbor etc)”. The messages' body comprised a link to the postcard. A careless click might bring to disaster, i.e. infection by a new modification of the notorious BackDoor.Groan. The malware installs a special driver to conceal its files on the disk, it's able to operate in P2P networks and launch spam distribution from the infected PC. BackDoor.Groan disguised itself for a while to announce virus events and offering users to download a corresponding curing utility to avoid IP ban. But the authors switched back to the conventional headlines pretty soon. It's worth noting that the first BackDoor.Groan mail distribution was detected in January this year when it was marked by political issues in the headlines.

Mail worm Win32.HLLM.Limar was less noticeable this month than it used to be. It went beyond the limits only once taking up 35% of the whole infected mail traffic and this outbreak didn't last for long as the scheme below shows:

The mail worm Win32.HLLM.Graz came up with its new modifications. It covered 35-40% of the infected traffic now and then, resulting in removal of anti-virus tools on personal computers and preventing their re-installation.

Cyber extortionists became more active too. There were detected a few modifications of a dangerous Trojan disabling computers - Trojan.Plastix. If your machine has been infected by Trojan.Plastix, you're welcome to contact Technical Support service of Doctor Web, Ltd. to recover your computer.

Another Trojan on the list is Trojan.Encoder newly upgraded to Trojan.Encoder.11 and Trojan.Encoder.12 versions, extorting from their victims a sound sum to recover the encoded data.

Trojan.Winlock silently takes over the latter by keeping in the shadow while a PC is on. But after re-installation it springs up announcing that the user runs an unlicensed OS copy and offers to make a corresponding payment through Yandex.Money.

Russian phishing message alerting to an alleged block of the account by Yandex.Money is one more event to be noted. Such messages have been detected by Dr.WEB as Trojan.Bankfraud.402 .

July 2007 spam-review

An outbreak of unwanted messages with PDF attachments was detected in addition to the spam events above. Their volume increased by 30% in comparison to the previous month.

The share of the so called “cultural spam” announcing opera galas, exhibitions, different tours etc. increased as well. Yet, the bulk of the Russian spam still comprises commercial spam including invitations to seminars, accounting matters and the likes.

In July 16 577 entries were added to Dr.Web virus database.

Below goes the summary table of the online scan results for July:

Virus name Quantity
VBS.Psyme.239 758
Trojan.Packed.142 501
VBS.PackFor 397
Trojan.Virtumod 188
Win32.HLLW.Autoruner 105
Win32.HLLM.Limar 96
BackDoor.Bulknet 87
Trojan.Spambot 82
Win32.HLLM.Beagle 66
Win32.HLLM.Wukill 65

One more summary table shows the viruses prevailed at mail servers in July, 2007:

Virus name % of the total quantity
Win32.HLLM.Netsky.35328 19.14
Win32.HLLM.Graz 15.01
Win32.HLLM.MyDoom.based 8.28
Win32.HLLP.Sector 8.12
Win32.HLLM.Beagle 7.76
Win32.HLLM.Limar.based 6.44
Win32.HLLM.Netsky.based 5.74
Win32.HLLM.Limar 5.13
Win32.HLLM.Netsky 3.88
Win32.HLLM.Perf 2.65
Win32.Hazafi.30720 1.75
Exploit.MS05-053 1.44
Win32.HLLM.Beagle.pswzip 1.11
Win32.HLLM.Oder 1.08
Win32.HLLM.MyDoom.33808 1.05
Win32.HLLM.MyDoom.49 0.94
BackDoor.Bulknet 0.88
Win32.HLLM.Netsky.24064 0.80
Win32.HLLM.Generic.391 0.80
Trojan.MulDrop.7173 0.75
Прочие вредоносные программы 7,25

Tell us what you think

To ask Doctor Web’s site administration about a news item, enter @admin at the beginning of your comment. If your question is for the author of one of the comments, put @ before their names.

Other comments