Advertisement
Promo

Security threats Toolkit

Trojan masquerades as Windows patch

Published: 27 Jan 2005 08:55 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft's patch process has spawned an attempt to fool Windows users into downloading and installing a Trojan horse.

A fake email message, sent to ZDNet UK sister site CNET News.com, purports to be a Microsoft security notification about problems with the Windows operating system. The message, which carries the subject line "MS Windows/Critical Error", attempts to fool PC users into downloading and installing an attached program. However, numerous spelling and grammar errors in the message could tip people off to the danger.

"In the libraries of OS Windows(r) critical errors have been found," reads the email message that contains the Trojan horse attachment. "This errors lead to destruction of the system files from your computer without an opportunity on restoration."

The attached executable file, named Windowsupdate.rar, appears to be a Windows archive file, a format used to install code on PCs. Antivirus company Symantec said the file is not listed in the virus database, so it's unclear whether the file is a virus, a prank or any other kind of attack.

"Microsoft is aware of a possible threat by which a person sends an email claiming to be from Microsoft and enticing users to download Windows updates in the form of an attachment in the email," Debby Fry Wilson, director of Microsoft's security response centre, said in a statement. "Initial investigations from Microsoft and third parties have found that there is no malicious payload associated with this attachment at this time, and Microsoft is not aware of any customer impact."

The scam is common enough that the software giant has created a Web page to answer Windows' users questions. The company notes on that Web site that it never sends updates as attachments to email messages.

"We never attach software updates to our security email notifications," the software giant stated on its site. "Rather, we refer customers to our Web site for complete information on the software update or security incident."

The software maker typically delivers patches through its Windows Update service, or through downloads from its Web site.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
142 out of 279 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

INIFiles: Getting those legacy files i...

Handling INI files can be a little tricky these days when you have to consider new security restrictions, virtualized environment restrictions (App-V and Citrix) and legacy applications... More

Post a comment

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters