Advertisement
Promo

Emerging tech Toolkit

Bogus Microsoft bulletins closed down

Wendy McAuliffe ZDNet.co.uk

Published: 18 Jul 2001 16:38 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Web sites of two bogus Microsoft security bulletins were closed down on Wednesday after they were discovered to contain malicious code that could cripple infected computers.

The two bogus bulletins -- complete with software patches and links to a hoax Web site -- were discovered on 10 July. Both contained potentially damaging viruses. The first virus, nicknamed W32.Pet_Tick.G, arrives as an email with the message, "This is a fix against I-Worm.Magistr." It also contains an executable file attachment entitled "MSVA.EXE." The other phony bulletin, dubbed W32.Leave.B.Worm, claims to contain the patch for a serious virus, but instead is itself malicious code.

"This is a cunning piece of psychology to get past the most suspicious PC user," said Graham Cluley, senior technology consultant at anti-virus firm Sophos. "You receive a message that at first glance looks like a Microsoft bulletin, but once executed takes you to the virus distributor's Web site and downloads the malicious component."

Security experts are satisfied that the bogus Web sites have now been removed, and claim it is unlikely that more PCs will be infected with the viruses. Microsoft issued a statement explaining that the Pet Tick worm is easy to spot by its lack of digital signature, and the direct link that it contains to the phony patch instead of the complete bulletin.

But Cluley is less optimistic about the IT competence of individuals to spot emails that don't contain digital signatures. "It's a unfortunate case that most people are suffering from a bug in their brain rather than a bug in their PC -- they need to be more suspicious about email and not trust everything that they receive," he said.

Phony security alerts represent the latest social engineering trick for hackers, but virus experts predict that the pornographic trap as exploited in the Anna Kournikova virus earlier this year is still the most popular. "There's an unlimited demand for porn and Russian tennis players, and there will be for some time," said Cluley. "But the two viruses that have recently posed as Microsoft bulletins could give others the same idea."

Is your PC safe? Find out in ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
43 out of 76 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:











Discussions

juicecultus juicecultus

The link provided is not working

Sunday 6 December 2009, 5:13 PM

1 comment
lezlow lezlow

when it comes with power supply you,ll...

Saturday 5 December 2009, 9:42 PM

3 comments
lezlow lezlow

yer

Saturday 5 December 2009, 9:40 PM

1 comment
lezlow lezlow

HP workers set dates for strikes

Saturday 5 December 2009, 9:39 PM

2 comments

Blog Posts

Avatar David Meyer

Nokia halves smartphone portfolio

Friday 4 December 2009, 5:03 PM

1 comment
Avatar First Take

Windows Home Server Power Pack 3

Friday 4 December 2009, 10:18 AM

0 comments
Video icon

Video


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters