ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Xombe Trojan imitates Microsoft security warning

Munir Kotadia ZDNet.co.uk

Published: 12 Jan 2004 12:10 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

An email disguised as a message from Microsoft's security team contains a dangerous Trojan horse called Xombe.

Xombe, also known as Trojan.Xombe, Downloader-GJ and Troj/Dloader-L, was being distributed on Friday and poses as a critical update for Windows XP. When executed, it attempts to download a malicious backdoor component from the Web. It appears to be an imitation of one of last year's most successful worms, the mass-mailed Swen, which also masqueraded as a security warning from Microsoft. However, Xombe has yet to repeat the success of Swen. While the former failed to make the top ten threats intercepted by email-security firm Messagelabs on Monday morning, Swen was at number two, with some 7,000 instances captured in the past 24 hours.

Ken Dunham, director of malicious code at security company iDefense, said that the success of Swen has encouraged virus writers to create emails and Web sites that appear official in order to fool more people into executing malicious code.

The email, which appears to have been sent from windowsupdate@microsoft.com, has the subject line "Windows XP Service Pack 1 (Express) - Critical Update" and directs users to execute the attachment, called winxp_sp1.exe, in order to fix some vulnerabilities in Internet Explorer, Outlook and Outlook Express.

Dunham said that once executed, the attachment downloads a file called msvchost.exe that alters the Windows Registry and opens certain ports in order to listen out for commands from a hacker.

Most antivirus companies have already updated their signatures, but users without up-to-date antivirus applications could be infected, helping the Trojan's author to take control of large numbers of PCs. Dunham said that once a "large army of zombie computers" has been built up, attackers could use them for more serious crimes such as ID theft and banking fraud. Although Xombe is only likely to be opened by Windows XP users, it affects Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT and Windows Server 2003 systems, as well as Windows XP, according to Symantec.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
83 out of 164 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Systems Engineer - UNIX Oracle SQL - Manchester 30k

Knowledge of Symantec Enterprise Vault. Major pharmaceutical requires senior systems administrator due to expansion in services, must display ability ...

1st Line IT Support Opoortunity

You will be responsible for providing direct Help Desk support to clients: Logging all incoming calls, voicemails and emails. The key skills for this ...

Linux Redhat Systems Administrator - Windows XP, Network Connectivity

Linux Redhat Systems Administrator Windows XP, Network Connectivity, Backup, DR, Market Data (not essential Reuters / Icap). Fantastic opportunity ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment