Sign in to follow this  
Itchygomba69

Fake microsoft update is a Trojan

Recommended Posts

Fake Microsoft Security Trojan on the Loose, Antivirus Firm Says

 

Fri Apr 8, 6:00 PM ET

 

 

 

Paul Roberts, IDG News Service

 

A new campaign by malicious hackers uses a Web site designed to look like Microsoft's Windows Update page to trick unwitting Internet users into infecting their computers with a Trojan horse remote access program, according to antivirus experts at Sophos.

 

• Antivirus Company Warns of New Smart Phone Trojan

• Web Postcards Hide Trojan Horse Programs

• New Bagle Variant Combines Spam, Trojan Horses

• Trojan Horses Take Aim at Mobile Phones

• Police Nab Creator of Webcam Trojan

 

 

 

The scam uses e-mail messages that appear to come from Microsoft to get recipients to visit a Web page that uploads the malicious program. Using the promise of Windows software patches to distribute malicious code isn't new. However, the latest attacks show that scammers are adopting strategies used by phishers to evade detection by gateway and desktop antivirus programs, says Graham Cluley, senior technology consultant at Sophos.

 

The attack was first detected on Thursday in Sophos's Vancouver, Canada, lab after it was distributed in a spam campaign. The messages have subject lines like "Update your windows machine" or "Urgent Windows Update," Cluley says.

What Happens

 

A link in the body of the e-mail message appears to take users to the Microsoft Windows Update Web site, but would actually forward them to a Web site operated by the attackers and install a Trojan horse program called DSNX-05, according to Sophos.

 

The Web site run by the hackers was registered to an Internet service provider in Toronto, but it has since been shut down. The site looked very much like the actual Microsoft Windows Update page and displayed Microsoft's corporate logo. One clue that something was amiss: The URL displayed in the Web browser address bar showed only the IP (Internet Protocol) address of the site, instead of the Windows Update address, Cluley says. Sophos does not know how many Internet users may have fallen for the ruse, he adds.

 

The method of attack is similar to the phishing identity theft attacks that have become common in the last year. As with many phishing attacks, gateway antivirus software does not detect the scam, because there is no malicious code in the e-mail. Desktop antivirus software with spam detection could spot the e-mail, but only if an antispam definition for the attack had been created and the user had updated the antispam definitions for their product, according to Cluley.

Real Update Coming April 12

 

Those behind the attack may have been trying to capitalize on anticipation of Microsoft's upcoming software security patch release next Tuesday, Cluley suggests. On Thursday, the Redmond, Washington, company said it intends to put out a number of security patches for its software.

 

"It's such a shame that, just as we're beginning to teach people more about security updates, cybercriminals are exploiting that," Cluley laments.

 

Sophos points out that Microsoft does not issue security warnings in the manner used by this attack. E-mail users should be on guard when receiving an unsolicited e-mail that contains an attachment or asks the reader to click a link to a Web page, Cluley says.

 

Although the Web page used in the latest attack has been disabled, those behind the scam could post the content in a new location and restart the attack, he warns, adding, "It's hard being an average Internet user. You just can't trust anyone."

Share this post


Link to post
Share on other sites

Isn't every thing that Micfosoft sends out a virus, or is that just the O.S. it self?

Share this post


Link to post
Share on other sites

This is why I get my critical updates directly from Microsoft and ignore the others that come in the mail.

 

If you don't trust that, then go to their site once a week to check on updates for your comp.

Share this post


Link to post
Share on other sites
Isn't every thing that Micfosoft sends out a virus, or is that just the O.S. it self?

316859[/snapback]

 

Did you not read the entire thing? It was hackers that sent out the virus, not microsoft. And, none of the stuff that microsoft sends out has Trojans in it, bill gates is a little smarter then that(if MS did send out tojans, then everyone would stop buying WINDOWS, and switch to MAC's or LINUX) and, there are some glitches with OS's, but no viruses.

 

oh i've updated my microsoft windows just  :flowers:  i hope it hasn't affected!!!  :inlove:

316861[/snapback]

 

If you updated right from the Microsoft Website/from a little yellow shield icon(it should say: Updates from microsoft.com ready to download or something like that), then your OK. If you still feel unsafe, then go to (AND THIS IS NOT A TROJAN, I DON'T DO THAT TO PEOPLE) http://v5.windowsupdate.microsoft.com/v5co...t.aspx?ln=en-us

That is Service Pack 2, and if you DL(download) it, it will help you keep your computer protected.You need Internet Explorer to download it, BTW.

Edited by LordOfTheBorg

Share this post


Link to post
Share on other sites
Isn't every thing that Micfosoft sends out a virus, or is that just the O.S. it self?

316859[/snapback]

 

Did you not read the entire thing? It was hackers that sent out the virus, not microsoft. And, none of the stuff that microsoft sends out has Trojans in it, bill gates is a little smarter then that(if MS did send out tojans, then everyone would stop buying WINDOWS, and switch to MAC's or LINUX) and, there are some glitches with OS's, but no viruses.

 

oh i've updated my microsoft windows just  :lol:  i hope it hasn't affected!!!  :dude:

316861[/snapback]

 

If you updated right from the Microsoft Website/from a little yellow shield icon(it should say: Updates from microsoft.com ready to download or something like that), then your OK. If you still feel unsafe, then go to (AND THIS IS NOT A TROJAN, I DON'T DO THAT TO PEOPLE) http://v5.windowsupdate.microsoft.com/v5co...t.aspx?ln=en-us

That is Service Pack 2, and if you DL(download) it, it will help you keep your computer protected.You need Internet Explorer to download it, BTW.

316905[/snapback]

 

Oh I must be safe then it's from microsoft directly and we already have service pack 2 which we updated last week *Breathes a sigh of releif*

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
Sign in to follow this