About this blog

Bob Sullivan

Corporate sneakiness. Government waste. Technology run amok. Outright scams. The Red Tape Chronicles is MSNBC.com's effort to unmask these 21st Century headaches and offer real solutions that save you time and money.

Bob Sullivan covers Internet scams and consumer fraud for MSNBC.com. He is the winner of multiple journalism awards for his coverage of online crime and author of Gotcha Capitalism: How Hidden Fees Rip You Off Every Day and What You Can Do About It. and Your Evil Twin: Behind the Identity Theft Epidemic.

Got some red tape you want Bob to untangle? Write BobSullivan@
feedback.msnbc.com.

Beware unexpected e-Valentines, FBI says

Posted: Wednesday, February 13 at 05:33 pm CT by Bob Sullivan

When the FBI issues a press release about Valentine's Day, you can guess it’s not good news.

The feds are warning Internet users about electronic Valentines that are booby-trapped with a computer virus. Computer security firms confirm that they have seen many variations of the virus, which often arrives in e-mail bearing loving subject lines like ‘You Stay In My Heart" and "Hugs And Kisses." The e-mail instructs users to follow a link and pick up an electronic greeting card.

Kaspersky Lab, an anti-virus firm, said Valentine's-related spam had spiked in the past 24 hours and currently represents 5 percent of all spam traffic.

Sadly for those hoping for flowery notes from secret admirers, security experts advise users to delete any electronic Valentine's cards if they don’t recognize the sender.

Users who fall for the trick end up being infected with the Storm worm, according to the FBI. Infected computers then become part of a “botnet,” a network of computers controlled by criminals and used to spread spam. For months, the FBI has been trying to stem the spread of such botnets.

"Virus writers are increasingly using psychological temptations such as love, money and lust to encourage innocent users to activate malicious code," security firm Sophos said in a statement. Other subject lines to watch for, the company said, are:

"I Like You," "Powerful Love," "Tower of Love," "Val-ANT-ines," "Just You," "What is Love?" "The Love Train," "My Heart," "You're My Valentine," "Just You," "My Love For You," "Love Rose," "World Love," "You Stay In My Heart," "A Rose To Say...," "I Love You," "Valentine Friends," "Love Rose," "Thinking Of U All Day," "Valentine Invitation," and "Happy Valentine's Day!"

The criminal gang behind the Storm worm has repeatedly used holidays and electronic greetings to entice Net users into infections, the FBI said in its note.

Tom Bowers, a virus researcher at Kaspersky, said the Valentine's spam surge began in Russia but quickly spread around the globe.
Courtesy: Kaspersky Labs
Valentine_spam4_3

"We are seeing a vast increase in the amount of spam," he said. It was not immediately clear if the increase was directly related to the Storm worm, or other virus writers were also jumping on the occasion, he said.

One particularly effective form of treachery, he said, was that the spam messages contain rotating images that appear to be personalized. One contains popular Winnie the Pooh; others contain hearts with inscribed messages. The images make the e-mails more enticing to recipients, he said.

"I know the attack sounds like something you'd see in 2000 or 2001. But we know people are falling for it," he said. "When our researchers tried to get onto the sites hosting the (viruses), they had trouble because the sites were getting so much traffic."


MAIN PAGE NEXT POST A lost laptop, a $54 million lawsuit: part 2

Email this EMAIL THIS

82 COMMENTS

I wish these people would get a life and stop trying to harm people.

Well, seems I now have an advantage in being an old, cranky, suspicious, mistrustful old woman who knows there is absolutely no one who likes her enough to send her a Valentine, and that if one showed up in my email, I'd delete it so fast your head would swim. lol!

I have been on the Net since it began for us mere mortals [1994.]

What I do to avoid SPAM and viruses is to log on to my Internet Service Provider's [ISP] webpage for e-mail. [Similar to how you log on to Yahoo or GMAIL]. I then check all mail in my in-box and mail that has been tossed into the SPAM or Junk folders.

In the In-Box I check the mail "From" box to see who it is.

If it is someone I know or have done business with, I then open the mail. If I see from the content that it is a "generic" e-mail, such as "Look at this" or "Click this link" then I delete the e-mail without opening the link.

Same goes for attachments. If the e-mail appears not to be genuine, but from someone I know, then I do not click or download the attachment.

I also mark as SPAM any obvious SPAMS that made it into my in-box.

ONLY AFTER CHECKING MY MAIL ON THE ISP WEBPAGE DO I THEN OPEN OUTLOOK AND DOWNLOAD THE E-MAILS.

Using the above technique has prevented me from ever getting a virus or Trojan in 14 years of getting e-mail. And yes, I have seen many of the type of attacks mentioned in this article. And those attacks have appeared in my in-box over the years.

Attackers have become more creative over the years but it seems that the attacks have patterns on whatever seems to work at the time. Currently, at least over the past six months, those online cards, greetings and e-vites have been the rage.

Unfortunately, that's not likely to happen, as there's big money to be made in this activity, which is largely driven by organized crime.

Please! If this, my third computer in 2 years, crashes because of some random virus I will completely give up on the internet. So much for nortons!

Sad thing is, Nickola...this is their life. Pretty sad.

Keep 'em coming! It's just what an information technology services company such as mine needs to rack up those billable $$$ hours.

Too bad they don't permanently harm their own computers with their viruses....

As a network consultant, I have to say the primary reason for viruses is to create open relay zombies to send out spam, and less often, to launch denial of service attacks. I hate to say it, but I think that the anti-spam movement has failed miserably and has created more problems than it has solved. (You can read some of my suggestions on how to avoid spam in a recent Red Tape article: http://redtape.msnbc.com/2008/02/new-cyber-trick.html#posts)

Here is what I mean by causing bigger problems: Because virtually every spammer is driven underground since they can't get an Internet provider (and website host) that does not have a spam prohibition, they need to find a way to hide the origin, and that way is to introduce virii so they can realy the mail through Mr. homeowner's unprotected PC.

The ultimate solution is a redesign of the way that the SMTP (the protocol used to send e-mail) works to ensure you can determine the origin, but that is still years off. This will eliminate the biggest reason that virii exist.

In the meantime, rather than all the money we spend to block spam, we should be spending that money on education. Educate people how to protect their e-mail address from exploitation and you have gone a long way to solving both spam and virus problems.

The problem is they have a VERY profitable life farming bots to rent to spammers

Try hitting "forward" an send to spam@uce.gov. It's an FTC site, from what I read on another blog and my spam has decreased since I started forwarding it there.

I wish people would learn how to keep themselves protected.

As in all crime the people that do this will be caught coming soon now

I think one way to stop these criminals is to get the best spyware protction available another to stop this is don,t open e-mails from people you do not know i,am a crimnal justice major and i know alot about cyber terror this is a federal crime so if you,re thnking about sending a virus be my guest you will eventually be caught

Allowing everybody whose computer was compromised to more easily obtain class-action status against the perpetrators personally in lawsuits would go far as well. And if they don't have money, simply jail them for 1 year for each victim. These criminals wouldn't be so eager to inflict these virii on Internet users if it hurt them in the pocketbook or meant that they ended up in jail for the rest of their lives.

If these guys would spend as much time inventing something good as they do bad could you imagine how successful they would be.

Much as I despise the pieces of filth who are spreading this refuse, I'm dumbfounded by the ignorance of those who actually click on these transparently artificial messages. Are we really so pathetic that this tactic *works*?

@Nickola - Thts like saying, i wish people don't ever do bad things, don't do anything unethical, don't harm others etc. We can only dream of an ideal world. I am an IT guy and am concerned whats going to happen in the near future with the advance of botnets and increasingly dangerous viruses and other kinds of malware. The most scary thing is the privacy aspect. What if they hack into personal systems and steal all your personal information. The security companies need to come up with heuristics rather than just patching up systems every time new security issues arise.

This story was reported 2/12/08 by MSN and attributed to Agence France-Presse. http://news.id.msn.com/lifestyle/article.aspx?cp-documentid=1239753

Since the original FBI press release was at least 2 days ago maybe more & the story has already been published on MSN what took you so long to warn your readers given the time sensitive nature of the material?

Although Russ from Texas said it best regarding these criminals, as the old saying goes, "hit them where it hurts, in the pocket!" The criminals unable to pay should pay with whatever the cost suffered by those people affected by their viruses, in prison time.

I regard the Internet as almost redeeming humanity for the loss of the Library of Alexandria. Though this may sound extreme, when I consider the damage to infrastructure, commerce, and user/consumer confidence, I further regard those who prey upon the the Internet as being guilty of Crimes Against Humanity. If people will accept and insist upon that position and make the penalties for Internet predation too severe...even extreme...to warrant the risk, OUR resurrected "Library of Alexandria" will be safe...well, except from RepubliNazis and DemoFacists. Maybe being a RepubliNazi or DemoFacist should be considered crimes against humanity.

It's very simple. Don't open what you don't know.

People need to realize that when they see an email and they do not recognize the sender, they should delete. Absolutely NEVER use a link within an email to access a web site. Never provide information online that you would not give in real time.

There is usually an option in all email programs, that allows you to limit the size of incoming emails. If this is set, then emails bigger than you specify (I set mine to 10 KB) will not be downloaded fully to your computer. You do have the option, however, of downloading the rest of an email if it is from someone you know sending a photo, (for example), or from a trusted website. (Amazon and Dell emails fall into this category for me.) This helps to keep large, potentially dangerous files off your computer in the first place, and also gives you the secondary advantage of making getting your email a whole lot faster.

The one thing I've never understood about human societies, is why any society bothers with warehousing criminals like merchandise... virus writers and identity thieves included. People like this are not stealing a loaf of bread so they can avoid starving to death, they are choosing not to "play nice" by intentionally victimizing other people, in many cases, thousands of people. I'd just as soon have a "3-strikes-you're-dead" law, instead of wasting money paying for their room and board in a prison.

Another reason why I left Windows behind and switched to Linux. The only time I see virus's now are when I am being paid to fix other people's computers. I will say though if you are going to run Microsoft's Windows operating system you want Kaspersky anti-virus.... I have yet to see a machine with it come into my shop with a virus or spyware problem.

Aw, I like ya, Nancy T. Happy Valentine's Day.

It's interesting that when I received my e-mail this morning I had a "Valentine" from someone I didn't know. In it was just a link very similar to your example. I thought something was up and deleted it. Then I read this blog, I knew I did the right thing! All I can say is: BEWARE! This is the best Valentine I can give to all net users out there!

So have a REAL Happy Valentines Day!

It amazes me how moronic some people still are. With all the warnings out there from websites, newspapers, etc., there are still people stupid enough to open an email from a sender they do not recognize. Please pay attention, people!!! If less people opened these emails, these internet thugs wouldn't have so much to laugh about as they make your computer worthless in a matter of seconds.

to Donna in Greenville - Norton is not the best anti-virus program. I have been using "Nod32" for 2 yrs. It doesn't slow down your computer and does a better job of screening viruses.

I DON'T EVEN OWN A COMPUTER BECAUSE OF THIS STUFF. I GAVE UP A LONG TIME AGO

This goes to show ya that some people in this world have nothing better to do than try to ruin decent people's lives. God only knows why these human viruses need to get their rocks off in this way. Not only do they need to get a real life, if there's any justice in this world the Man Upstairs will see that they never lack for a light in the afterlife. Personally, I think the psychiatric diagnosis of antisocial personality disorder applies here, but in a theological sense these untermensch are just plain evil and I am glad we have law enforcement to give these scum what they truly deserve. Unfortunately our criminal justice system is often too lenient with these types, especially if they have money and good (?) attorneys. I would hate to be them in 100 years. Caveat emptor and good luck.

Like anything else these days - education is the key!

Lets get tougher on people who instigate these viruses. Surely a stiff prison term will be a detriment to these losers. And surely they can easily be caught with out technology today.

Years ago it was very simple viruses like letters falling down, spider webs, fake cracked screens, and roaches running across the screen. It was thought then that it was the software companies writing the virsus to stop hackers and those who only use one license on many machines. I think it's now that so many software companies over price their software such as Adobie & Microsoft that the virus writer think they diserve a virus for the prices they charge for their software. I myself fell victum to the e-card software last year but got rid of it thanks to Kaspersky. There use to be companies who offered some very good software for free and now all you get is a "free download" but no free program and even if it was free many times it wasn't fully functional. I think the virus writers have become criminal for their viruses can damage hardware and lets face it there are many out there who have no idea about keeping good reliable anti-virus programs on there computers. I think now its a case that some techs write viruses to keep their $69 to over $200.00 per hour charge to fix PC's with viruses going.

So, so sad that the masses must watch out for the bad deeds for the few. I wonder though, could there be any truth to the thought that it could be the large corporations who have a stake in internet security that may be creating some of these virus's? After all, it the threat is not constant, there's no need to pay them for thier security services. And, they do make a hell of a lot of money when we, as users, pay them to keep the bad bugs away.

Caveat Emptor!

Only self protection will help here. Sure, prosecution would be great, but how do you even find the real people behind a Russian gang, much less punish them internationally?

Here is an eye opener for everyone. This problem won't go away. But there is help. One is: to only accept email from people you know to the Inbox. The rest should be treated as Junk and will so end up in the Junkbox. Here you have a fair chance to scroll through all incoming emails and decide whether to keep it or not. Since we are on the subject: Ttop clicking on those Popup windows too as they may contain viruses as well. Happy Valentine's Day! :-)

Where does God come in the picture? :-)

Best Practices: Tune up your PC with tools/utilities from(reputable sites/Companies)to ensure you are always protected. ALWAYS keep your Virus protection/spamware/windows updates to date. Never open, click on or download something you don't know.
One other NOTE: If you are one of those folks who is using these shady download sites for music, movies, etc, you have a higher risk of being infected or infecting others with the information you are downloading/sharing.
There is no magic button, we have to protect our valuables from these nuisances.

For all of those here recommending everything form prison to death for the makers of these virus’s you need to remember that the www in URLs means World Wide Web.
Most of this kind of spam and virus activity starts over seas where there are little or no laws against making and spreading them.
You need to protect yourselves and learn not to except un-solicited email.

To those who say to get the criminals who send these messages:
Realize that they are mostly based in other countries, where the authorities don't cooperate, largely Eastern Bloc and China.
That makes it much harder to catch them.

Just another reason to hate valentine's day!

I want to see increased efforts to catch the people behind spam and Internet threats. I think public hangings are in order.

I wish these people who GET A LIFE and STOP THIS FULLISHNESS!!!

I honestly believe that microsoft has purposely allowed these loop holes so they can continue to get money. think about it, why does windows have the most viruses. they want your money. I wouldnt be surprised if someone who works for those companies starts up all this crap. i love my mac!!!!

Yes! Jail time is fitting. Hacking, in my opinion, is just the same as breaking and entering.

Symantec Norton Internet Security™ 2007. Retail Price: $454.99 , Our Price: $59.95
[b][u]FREE DOWNLOAD ADOBE ACROBAT 8 pdf capacity density[/b][/u]
[b][u]FREE DOWNLOAD ADOBE ACROBAT 8 update[/b][/u]
[url=http://www.4softsite.info]DOWNLOAD CHEAP ADOBE illustrator CS2[/url] - DOWNLOAD CHEAP ADOBE reader download
[b][u]3rd DOWNLOAD CHEAP ADOBE edition matter PHOTO[/b][/u]
[url=http://www.4softsite.info/manufacturer-Adobe.html?session=146011198080532]DOWNLOAD CHEAP ADOBE camera CS2 PHOTO raw real SHOP[/url] - 8.0 DOWNLOAD CHEAP ADOBE after effects studio technique
[url=http://217.23.49.238/phpBB2/profile.php?mode=viewprofile&u=9151&sid]FREE DOWNLOAD ADOBE ACROBAT 8 crack[/url] - FREE DOWNLOAD ADOBE ACROBAT 8 fill-in
[url=http://www.coresoftware.es/foro/viewtopic.php?p=17008#17008]quite a box
- FREE DOWNLOAD ADOBE ACROBAT 8 60 pro crack
of tricks for FREE DOWNLOAD ADOBE ACROBAT 8[/url] - FREE DOWNLOAD ADOBE ACROBAT 8 PROFESSIONAL 7

Not so easy sparky hence the botnet is the way they operate anonymously. Nancy T I love you !!!! you rock!!!! The original Sparkster!

As with any romantic interlude (be it real or cyber), one must use the appropriate prophylactic to avoid crotch crickets and other nasties.
Your Mom

I believe that all these criminals would be out either killing some one or robbing a bank, etc. if they where not doing this. Yes it is sad that we have to live with these kind of people, I only say that because they look like people, I doubt if they are the humans that we would like to know.

I've heard that MacIntosh owners don't suffer these problems. Maybe PC manufacturers and Microsoft could take a lesson in more intelligent designs.

I've heard that MacIntosh owners don't suffer these problems. Maybe PC manufacturers and Microsoft could take a lesson in more intelligent designs.

I've heard that MacIntosh owners don't suffer these problems. Maybe PC manufacturers and Microsoft could take a lesson in more intelligent designs.

These idiots don't scare me.. Nor do their coding languages and harmful programs... I have this thing called a filter, and everything and anything that isn't something else goes to that folder.. Never to be seen again..

I use PC-Cillin from Trend Micro. I have used Nod32 and have found that they both work very well for keeping my computer in squeaky clean.

Forget Nortons try AVAST

2 word: viruses suck. ive met multiple hackers who mess around w/ ppl's computers, and wen i ask why, they usually say its either for fun or for vengeance. umm... okaay..? why screw up a piece of hardware thats worth between 800 and 2000 dollars... for FUN?! like the commercials, WADDAFXUPWIT?!

I am a 50 yr,old vet. and got my first PC for Christmas.I was dumb enough to fill-out a "short survey" I was told it would take only a few minutes.An hour later, I still was not finished. I later learned that this was a huge mistake. I now get about 200 spams a day. Now that I know, I DELETE FOREVER all of this nonsense but, it is still something I do two or three times a day and it makes me very angry. I got this PC to feel like I belong, to learn, to communicate with my fellow human beings. I forgot that some of these fellow human beings can be mean, evil, unfair, and cruel.

Uh...for all those of you who keep sniping about prosecuting these people, how are you going to prosecute someone doing their hacking from Kenya Africa, or Korea, or India, or South America, or... Sorry, but the US legal system doesn't stretch that far!

This is another classic example of how Children Under New Technology are taking advantage of people because they are too lazy to go out and get a real job themselves. Justice Is Zig-Zagging and if something doesn't happen soon spam is just going to get worse and worse unitl virtually every computer has some sort of hack or virus on it.

Great comments all - but hey don't you know that some of these things sneak in by virtue of the fact that they seem like they come from someone you know. That really burns because by using a "likeness" they also trick you into opening it in the first palce - they really have gotten sophisticated. What's a person to do? One way to avoid (it is expensive) is to go to fully id encripted emails. Nancy T you are the best, lol.

preach it brotha Frank! owning a computer is equivelent to having a child. you have to know what you are doing. or it grows up evil and you will both hate each other. if you believe you shouldnt have to do research and keep up with the times, well the old folks home is right over there.

I think its a shame that these nuts get their kicks off of hurting inoccent people with these viruses. So lets get tougher and get them. But also be smart and know not to open any emails unless you know who they are from. Good luck and Happy Valentines Day to all the good people online.

Thanks all for the tips on why nortons doesn't work for me. Will def look into new software.

Being in Remote Canada the internet is the only source of contact I have with much of my family in the USA and Europe.. I just dont understand when most viruses are written by kids.. why cant they take there tallents and use them for GOOD not BAD.. take glitchy programs and mediocar workable programs and make them work and run properly and work well.. let them use there tallents for the GOOD OF ALL.. JMHO for what its worth.. ~Caso

*starts to laugh* Wow, these idiots that send the virus and all are actually pretty clever. I mean, sending "Valentines cards" on V-day...to people who usually are desperate or love cards. That's....really clever and tricky. ^^ Hope no one falls for it though...

How about this scam? I received an Email supposedly from the I.R.S. with the subject: Important notification - Tax Refund. It claimed that I was eligible to receive a tax refund of $109.23. They instructed me to CLICK HERE to access the form for my tax refund. Of course, I DID NOT and called my tax preparer who informed me that it was a scam. The giveaway for me was that they signed the notice...........Regards,
Internal Revenue Service

I need a lot of info about best bill consolidation. Were can I find more?

it amazes me that these internet abuser have nothing better to do then to make someone life miserable, at the same time though, beware peple do not open anything that you're not familiar with
to all a happy valentines

it amazes me that these internet abuser have nothing better to do then to make someone life miserable, at the same time though, beware peple do not open anything that you're not familiar with
to all a happy valentines

Maybe everyone should just switch to a Mac. and stop worrying about all of this stuff. They're fantastic!

get a mac

take it as a junk mail throw it into the recycle bin

It seems that more that half of responders have missed the vital clue. This IS an attack by Russia on the West. The objective is to create havoc for western businesses and demoralise their populations. Oh, and it's working.

I experienced terrible and horrible similar computer issue from the "So-called Geek Squad" of Best Buy. They could not deliver the services promised, my home PC is ruined by the Geek Squad. The issue is currently being investigated by my credit card company. I lost everything on my computer. As a result of this, I was forced to buy another computer.
I made several efforts by making three trips to the store complaining that my PC was worse than it was; I became a joking material despite the fustration and the anger on my face, they could careless.
I may follow it up accordingly.

I experienced terrible and horrible similar computer issue from the "So-called Geek Squad" of Best Buy. They could not deliver the services promised, my home PC is ruined by the Geek Squad. The issue is currently being investigated by my credit card company. I lost everything on my computer. As a result of this, I was forced to buy another computer.
I made several efforts by making three trips to the store complaining that my PC was worse than it was; I became a joking material despite the fustration and the anger on my face, they could careless.
I may follow it up accordingly.

Hello my name is John Russo from Lincoln RI. and I could not beleive it when I saw the story this morning on your show about the woman suing Best Buy Inc. The same thing ALMOST happened to me. I brought my under warranty computer to Best buy, where I purchased it, they took my name and all other necessary information and gave me a print out of proof of drop off. When the customer service agent handed me the print out I asked him if I needed to bring the print out back with me to pick up my computer, he replied... NO, we have all the information in our system. When it was ready for pick up after 35 days, I went to pick it up without the print out, they told me they had no record that I ever dropped it off there. They had no idea where it was. Well, you can understand my frustration when I caused a scene and was told to calm down or they would have me REMOVED from the store. I had to go home and find that print out. Lucky for them I found it. Went back and they had to replace it. Lucky for me and them, I didnt have any volitile information on it that would be of concern for any kind of threat. They gave me a new CPU minus the moniter, key board, etc. I can feel for that woman on your show this morning. Needless to say, I will NEVER EVER shop at a Besy Buy AGAIN!!!!!

jail time and education would be a good thing and on the computer an auto resend of spam and junk email to would be great.This way they will get a some of there on virus back.Let just call that an eye for an eye.

some website are loaded with virus and ready to attack some one computer, when click open . It happen to me two times . NO website surfing anymore. I have norton anti-virus solfware and spybot-searchand destroy.

donna greenville sc: "Please! If this, my third computer in 2 years, crashes because of some random virus I will completely give up on the internet. So much for nortons!"

Donna,
If your computer crashes it will be your fault and your fault alone.

I've had the same PC for 8 years and it still performs as well as it did from day one.
Of course it's possible to accidentally get a virus, but the majority of "victims" are just plain ignorant. And that's why you've gone through so many computers.

Imagine this: For every email delivered, a charge of 1 cent against an escrowed account. To send emails you must have an amount on escrow (1c). When you are the recipient, you receive 1 cent. Spammers would go broke, and all traceable -- at least as far as the cash in the escrow account. (That's where you're headed anyway == traceable mail). Now some would argue that the internet is 'free' -- not so, if you are spending time and $ fighting off the bad guys and gals -- not quite free at all.

For a cent, you might not mind opening all that spam, but the flood would drop to a trickle very fast.


SEND A COMMENT

PLEASE READ: All comments must be approved before appearing in the thread; time and space constraints prevent all comments from appearing. We will only approve comments that are directly related to the blog, use appropriate language and are not attacking the comments of others. Firms mentioned in our comment area are welcome to add their own comments.

Message (please, no HTML tags. Web addresses will be hyperlinked):

TRACKBACKS

Trackbacks are links to weblogs that reference this post. Like comments, trackbacks do no appear until approved by us. The trackback URL for this post is: http://www.typepad.com/t/trackback/454638/26103838

BUY BOB SULLIVAN'S NEW BOOK

Cover_crunched_by_media Bob Sullivan's new book unmasks hundreds of hidden fees and offers step-by-step instructions on how to fight back. Order it here.

Syndicate this site

RSS is an easy way to get the news you want as it is updated even if you are not on MSNBC.com. More information about MSNBC.com's RSS feeds.

XML