You are here: silicon.com > Software > Malware

Malware

'Windows Update' hides nasty Trojan

Users may think they're protecting their machine...

By Will Sturgeon

Published: 8 April 2005 17:55 GMT

Security firms are warning about a spam email which purports to be a Windows Update from Microsoft. However, when launched recipients will infect their machine with malicious code.

The email appears as though it is from Microsoft, coming from the spoofed address update@microsoft.com with subject lines such as 'Update your Windows machine', and links through to a website which mirrors the design of a proper Windows Update page but as the page opens it will download a malicious .exe into a Windows directory and install a Trojan horse (DSNX-05).

While running, the application will consume 100 per cent of CPU power by forcing the CPU to perform continuous processes, according to a report from SurfControl.

SurfControl first intercepted the email in Australia. As is often the case it then followed the sun west as different time zones came online.

Graham Cluley, senior technology consultant for Sophos, said: "We have long recommended that computer users keep up-to-date with the latest security patches, as Microsoft vulnerabilities are often exploited by viruses, worms and hackers. But users must be very careful to be sure they are going to the official update websites, rather than just following links in emails which have been sent by hackers."

Cluley added that Microsoft does not issue security warnings in this way.

"Users should be on their guard whenever they receive an email like this," he added.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Network Administrator

In-depth experience of web applications, web portal technologies and security, advanced understanding of web vulnerabilities and countermeasures ...

Automotive Jigs & Tools Machine Designer

A key client of mine based in the Thames Valley is looking for an Automotive Jigs and Tooling, machine designer. This will involve Jigs, Fixtures ...

Network Technical Specialist - CIsoc, CCNA / CCNP

Maintain a sufficient level of network security in compliance with the security baselines and policies * Ensuring that the network infrastructure is ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: