You are here: silicon.com > Software > Security Strategy

Security Strategy

Spam email hides 'fake Microsoft update' Trojan

Spreading fast and exploits recent vulnerability in Internet Explorer...

By Andy McCue

Published: 25 June 2003 15:55 GMT

A spam email that takes users to a fake Microsoft Windows update website and then infects their machine is spreading fast, according to anti-virus experts.

The email contains a link to a site purporting to be a Windows update page and then exploits a recent vulnerability in Internet Explorer to infect the user with a Trojan.

The fake URL is designed to fool people into clicking on it and is almost identical to the genuine Microsoft one apart from a hyphen.

Microsoft issued a patch it described as "critical" earlier this month. They included a buffer-overrun flaw that allows an attacker to run malicious code on a victim’s system and a problem that failed to stop a file-download dialogue box.

Jack Clark, product manager at McAfee, said his company had seen some activity around the email and warned users to get their patches up-to-date.

"Once again it is time to not only patch your anti-virus but your applications," he said.

Anti-virus company MessageLabs said it is currently detecting and stopping one of the rogue emails every minute.

Alex Shipp, senior anti-virus technologist at MessageLabs, said: "The attacker is obviously sending lots out and it's still ongoing. It is the typical activity of someone sending mass spam Trojans."

Shipp said although there are new components to the Trojan that would be downloaded onto a victim's PC, anti-virus software should detect and stop older code that allows it to run.

"As long as your anti-virus is up-to-date, even though you are going to miss the first two things because they are new, the things it ultimately downloads should be caught."

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Nick Heath Your top HR tech priorities for next year revealed How to make human resources IT work for you

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business


  • Jobs
3 rd line Wintel Support Engineer - Central London

Your responsibilities will include; Proactive Server Maintenance through monitoring and patch management and deployment Installation, configuration ...

Technical Support Rep- French

ZenWorks Asset Management (ZAM) -Symantec anti-virus -Symantec Console Management Using the correct call closure and activity action codes This is a ...

STORAGE ENGINEER EMC SAN NAS CAS CLARIION CENTERA CELERRA

Working knowledge of the MS Office suite; Remedy, MS Windows Server & Active Directory; UNIX Sun Solaris, IBM AIX, and any Linux o/s # Hardware: HP, ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: