1. Home
  2. Computing & Technology
  3. Antivirus Software
photo of Mary Landesman
Mary's Antivirus Software Blog

By Mary Landesman, About.com Guide to Antivirus Software since 2000

Malware Reunion

Tuesday January 6, 2009

The new year is upon us and for some that means a walk down memory lane, reminiscing about college or high school friends and perhaps anticipating a reunion with your former classmates. Scammers are taking advantage of this season of nostalgia, sending out bogus email invites disguised as a classmates reunion notice. One such email reads:

Your Classmates request the Pleasure of your Company at the Celebretion of our 2009 year Reunion.
Registration, Hosted Bar, and Reception at six o'clock Savoy Room.
You have received new messages to your classmates inbox centre.

Hopefully the obvious misspellings and strange capitalization are enough to tip off the recipient that it's a scam. If not, the link should be a dead giveaway. Instead of classmates.com, it points to flashplayerforwindows.com. According to ThreatExpert, the downloaded malware consists of a rootkit-enabled backdoor that also acts as a trojan downloader.

Firefox users (particularly those who use the NoScript addon) should be aware that a visit to the site will initiate the download of a malicious executable. That's because attackers are taking advantage of too-forgiving behavior in Firefox which allows even poorly formed instructions in the http header to be acted upon. In the classmates reunion scam, attackers are simply specifying the binary as part of a meta http-equiv="REFRESH" tag, which Firefox merrily accepts. At least Firefox 3 does allow you to change this behavior, (previous versions did not so this is a good reason to upgrade). Here's how to disable http header refresh in Firefox.

Comments
January 8, 2009 at 12:29 pm
(1) Jeffrey Bradshaw says:

Your instructions on disabling HTTP were all wrong. In the most recent Firefox Browser there is indeed a tools>options route but no such thing as a General tab! Pleas re-instruct this procedure on your page.

January 8, 2009 at 12:38 pm
(2) Mary Landesman says:

Actually, there is a General tab. Look carefully under Advanced and you will see it.

Leave a Comment

Line and paragraph breaks are automatic. Some HTML allowed: <a href="" title="">, <b>, <i>, <strike>

Explore Antivirus Software
About.com Special Features

Stay connected and entertained with reviews on tips on the latest HDTVs, cellphones and more. More >

Easy ways to connect two computers for networking purposes. More >

  1. Home
  2. Computing & Technology
  3. Antivirus Software

©2009 About.com, a part of The New York Times Company.

All rights reserved.