Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

New Worm Comes Disguised As Windows Warning
Washington Post ^ | 09/19/03 | Brian Krebs

Posted on 09/19/2003 1:10:53 PM PDT by bedolido

Computers running Microsoft's Windows operating system are falling prey to a new Internet worm that disguises itself as an official virus warning from Microsoft Corp.

Spread via e-mail, the "Swen" worm appears to do little damage, but experts say the unknown author's painstaking attempt to make it look like a real security bulletin from Microsoft shows a level of trickery new to Internet virus and worm attacks.

"This is a level of creativity we've not seen before," said Tony Magallanez, a San Jose, Calif.-based systems engineer for F-Secure, a Finnish anti-virus company. "This is a very authentic looking message that definitely uses some sophisticated social engineering tactics."

The worm takes advantage of a flaw discovered almost two years ago in Microsoft's Internet Explorer Web browser that allows hackers to infiltrate people's computers. Users who have not downloaded and installed the patch against the flaw are infected immediately.

Even users who have downloaded the patch can be infected if they click on the attachment that comes with the e-mail. Once started, the virus launches a program that looks nearly identical to one that Microsoft uses to install Windows security updates.

The worm, disguised as the installation program, asks: "This will install Microsoft Security Update. Do you want to continue?" Users who click the "yes" button are greeted with a graphic that tracks the progress of the worm's installation. The worm infects the computer even if the user clicks "no."

(Excerpt) Read more at washingtonpost.com ...


TOPICS: Crime/Corruption; Front Page News; Miscellaneous; News/Current Events
KEYWORDS: disguised; lowqualitycrap; microsoft; warning; windows; worm

1 posted on 09/19/2003 1:10:54 PM PDT by bedolido
[ Post Reply | Private Reply | View Replies]

To: bedolido
have been getting "use this patch immediately"email from?? microsoft"" i have not opened it for fear of what it may be

is this what you are talking about??
2 posted on 09/19/2003 1:21:50 PM PDT by camas
[ Post Reply | Private Reply | To 1 | View Replies]

To: camas
it sounds like it. I don't know. sorry
3 posted on 09/19/2003 1:24:51 PM PDT by bedolido (I can forgive you for killing my sons, but I cannot forgive you for forcing me to kill your sons)
[ Post Reply | Private Reply | To 2 | View Replies]

To: bedolido
I received an e-mail claiming to be from Microsoft with all kinds of links in it. I deleted it.

Best bet is to go to microsoft.com and from there get your updates, at least you should get authentic ones.

And on a similar topic I am very pleased with an anti spam solution from SpamPal.org. And its free! Now at most 1 or 2 get thru per day and 100-200 get canned. It's working so well I won't have to by valium advertised at cut rates by spammers!

4 posted on 09/19/2003 1:44:45 PM PDT by Voltage
[ Post Reply | Private Reply | To 1 | View Replies]

To: Voltage
And on a similar topic I am very pleased with an anti spam solution from SpamPal.org. And its free! Now at most 1 or 2 get thru per day and 100-200 get canned. It's working so well I won't have to by valium advertised at cut rates by spammers!

Thanks for the info. I'll download it tonight. I have McAfee Spamkiller and it's pure crapolla (it wasn't free either).

5 posted on 09/19/2003 1:46:56 PM PDT by bedolido (I can forgive you for killing my sons, but I cannot forgive you for forcing me to kill your sons)
[ Post Reply | Private Reply | To 4 | View Replies]

To: camas
I got two of those "Microsoft" messages the other day.....but...if you notice they don't have any coding to indicate WHERE they are from.....I dumped them, and emailed friends and family to NOT open them either.
6 posted on 09/19/2003 1:47:50 PM PDT by goodnesswins (Offend a Liberal commie.....tell them you're a Conservative and proud of it.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: goodnesswins
It's a paradox. The sociopath smart enough to put together a worm like this, is inevitably far too stupid to write a convincing "official email from Microsoft."

Dear friend , use this Internet Explorer patch now! There are dangerous virus in the Internet now! More than 500.000 already infected!

Oh yes. Sure. Right. That's VERY convincing.

There are dangerous virus in the Internet now! Its hugh!very series!

7 posted on 09/19/2003 3:00:47 PM PDT by ChemistCat (I have two daughters. I know peacemaking. What we're doing in Israel ain't it.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: bedolido
experts say the unknown author's painstaking attempt to make it look like a real security bulletin from Microsoft shows a level of trickery new to Internet virus and worm attacks.

But there's just one catch. Microsoft doesn't send security patches by email.

8 posted on 09/19/2003 3:02:48 PM PDT by Alouette (The bombing begins in five minutes.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: camas
is this what you are talking about??

Yes - that's it.

9 posted on 09/19/2003 3:03:45 PM PDT by TomServo ("Upon further review, the refs find that Cody is dead. The play stands -- Cody is dead.")
[ Post Reply | Private Reply | To 2 | View Replies]

To: bedolido
Got two this morning, the first one was from "ms security section" and stated it was a security patch, however, the second was a "return message: user unknown" notice. Same virus though, both caught by Norton thankfully.
10 posted on 09/19/2003 3:27:20 PM PDT by agrace
[ Post Reply | Private Reply | To 1 | View Replies]

To: ChemistCat
It's Japinglish, you know, like:

"All your base are belong to us!"

11 posted on 09/19/2003 4:38:43 PM PDT by dmcnash
[ Post Reply | Private Reply | To 7 | View Replies]

To: camas
yep.

I got my first hit of this tonight. I sh!tcanned it immediately, unopened, unread, certainly without opening the attachment.

Rule of thumb: I NEVER open ANY e-mail with an attachment which comes unsolicited from any source. Period, paragraph, end of story.
12 posted on 09/19/2003 10:17:44 PM PDT by King Prout (people hear and do not listen, see and do not observe, speak without thought, post and not edit)
[ Post Reply | Private Reply | To 2 | View Replies]

To: bedolido
I checked a free internet email account that I have, and there were about six different spoof emails from MS Customer Support with the "latest cumulative patch." Also waiting for me was the Nigerian scam and a clone from South Africa.

-PJ

13 posted on 09/19/2003 10:27:22 PM PDT by Political Junkie Too (It's not safe yet to vote Democrat.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: All
Last August Microsoft kept saying over and over that they DON'T send out emails about their patches!
14 posted on 09/19/2003 10:55:21 PM PDT by WaterDragon (America the beautiful, I love this nation of (legal) immigrants.)
[ Post Reply | Private Reply | To 2 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson