1. Home
  2. Computing & Technology
  3. Antivirus Software

Opt-In for Infection

By , About.com Guide

The "opt-out" link contained in many spam messages has long been used as a ploy to confirm whether recipients' email addresses are valid. By clicking the link (which may be displayed as "Click here to unsubscribe") to presumably "opt-out" of future mailings, the recipient is simply verifying that the email has reached a live person. Unfortunately, thanks to the drag-and-drop vulnerability first patched in MS04-004, spammers are now using the opt-out link to direct users to infected websites.

Once on the page, the user is instructed to scroll to the end of the page to remove their email address. If the mouse is used for scrolling, this will trigger the drag-and-drop exploit which then automatically downloads and executes a malicious executable.

Examples seen in the Fall of 2004 are downloading a file named windows-update.exe which has been found to be the Backdoor.Win32.Agent.ce trojan. Of course, the actual trojan downloaded - as well as the filename used - may and likely will vary. Additionally, infection cannot be diagnosed based on filename alone; there may well be instances of perfectly legitimate, non-infected files bearing the name windows-update.exe.

In summary, in addition to validating an active email address and thus increasing the amount of spam received, the opt-out link may also be a ploy for enticing users to visit booby-trapped websites. Of course, this pertains to unidentifiable and unsolicited spam. Mailing lists and other email correspondence to which the user has intentionally subscribed would not be considered at risk.

If you feel you may have been the victim of the 'opt-out' ruse, use up-to-date antivirus software to scan your system and remove any infections found.

Explore Antivirus Software
About.com Special Features

Holiday Central

What to eat, where to go, fun things to do and how to save money on the perfect gifts. More >

Family Tech Center

Stay connected and entertained with reviews on tips on the latest HDTVs, cellphones and more. More >

  1. Home
  2. Computing & Technology
  3. Antivirus Software
  4. Security Tips
  5. Opt-In for Infection

©2009 About.com, a part of The New York Times Company.

All rights reserved.