»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Off Topic Community

Reply
 
LinkBack Thread Tools Display Modes
Old 09-19-2003, 06:35 AM   #1 (permalink)
Registered User
 
Join Date: Oct 2001
Location: Long Island, NY, USA
Posts: 20
MTAtech is on a distinguished road
Send a message via AIM to MTAtech Send a message via Yahoo to MTAtech
Virus masquerading as MS email

I got this as email today, allegedly from "Microsoft Network Security Department". In HTML it looked like a MS webpage. On the face it looks official but the sender's email (rmjpqkpmbp@confidence.microsoft.net) looked funny to me and I didn't think Microsoft emailed fixes. The attachment (install8.exe) had the Worm.Automat.AHB worm/virus.

This is the text of the message:
=======================================

Microsoft All Products | Support | Search | Microsoft.com Guide
Microsoft Home


Microsoft Consumer

this is the latest version of security update, the "September 2003, Cumulative Patch" update which resolves all known security vulnerabilities affecting MS Internet Explorer, MS Outlook and MS Outlook Express. Install now to help protect your computer from these vulnerabilities, the most serious of which could allow an malicious user to run executable on your system. This update includes the functionality of all previously released patches.


System requirements Windows 95/98/Me/2000/NT/XP
This update applies to MS Internet Explorer, version 4.01 and later
MS Outlook, version 8.00 and later
MS Outlook Express, version 4.01 and later
Recommendation Customers should install the patch at the earliest opportunity.
How to install Run attached file. Choose Yes on displayed dialog box.
How to use You don't need to do anything after installing this item.

Microsoft Product Support Services and Knowledge Base articles can be found on the Microsoft Technical Support web site. For security-related information about Microsoft products, please visit the Microsoft Security Advisor web site, or Contact Us.

Thank you for using Microsoft products.

Please do not reply to this message. It was sent from an unmonitored e-mail address and we are unable to respond to any replies.

--------------------------------------------------------------------------------
The names of the actual companies and products mentioned herein are the trademarks of their respective owners.

Contact Us | Legal | TRUSTe
©2003 Microsoft Corporation. All rights reserved. Terms of Use | Privacy Statement | Accessibility

__________________
MTAtech - 'Fare and Balanced'

Last edited by MTAtech; 09-19-2003 at 06:52 AM.
MTAtech is offline   Reply With Quote
Old 09-19-2003, 06:40 AM   #2 (permalink)
Registered User
 
muno's Avatar
 
Join Date: Oct 2001
Location: Finland
Posts: 3,838
muno is on a distinguished road
Send a message via Yahoo to muno
True, microsoft never emails fixes. They may email information to subscribed customers about fixes, but they do not email fixes.
-M
muno is offline   Reply With Quote
Old 09-19-2003, 06:44 AM   #3 (permalink)
Registered User
 
nomaxim's Avatar
 
Join Date: May 2002
Location: Stow, Ohio, Sol III
Posts: 2,211
nomaxim is on a distinguished road
Try Here was on Reuters last night.

Looks like an old virus from like two years ago has resurfaced. ??? This one was called Swen/Gibe maybe the same ?

Last edited by nomaxim; 09-19-2003 at 06:50 AM.
nomaxim is offline   Reply With Quote
Old 09-19-2003, 06:53 AM   #4 (permalink)
Registered User
 
Join Date: Oct 2001
Location: Long Island, NY, USA
Posts: 20
MTAtech is on a distinguished road
Send a message via AIM to MTAtech Send a message via Yahoo to MTAtech
nomaxim, doesn't look like the same thing. What makes this dangerous is how real the email looks. It will fool many people.
__________________
MTAtech - 'Fare and Balanced'
MTAtech is offline   Reply With Quote
Old 09-19-2003, 07:17 AM   #5 (permalink)
Registered User
 
nomaxim's Avatar
 
Join Date: May 2002
Location: Stow, Ohio, Sol III
Posts: 2,211
nomaxim is on a distinguished road
Yeah, your right. ON BOTH POINTS!

NAI has nothing on this one and Symantec doesn't give a whole lot of info either.
nomaxim is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 06:02 AM.