Bogus Microsoft bulletin spreads virus

A fake Microsoft security alert is being used to spread the latest version of a worm over the Internet.

The W32.Leave.B.Worm is a variant of the W32-Leave.worm reported recently, and according to Symantec's Web site, the virus is sent via email with the Subject: Microsoft Security Bulletin MS01-037 and Message: The following is a Security Bulletin from the Microsoft Product Security Notification Service.

The bogus bulletin dramatically declares that -the Internet has seen one of the first of its downfalls" and goes on to mention the virus which has -the complexity to destroy data like none seen before".

Users are encouraged to protect their systems by downloading and installing an attached "security patch" from a linked Web site, which resembles that of Microsoft - the patch has since been removed from the hosted site.

-This fake Microsoft security bulletin uses 'tricks' similar to a trojan virus - that is, it tries to pretend to be an authentic security bulletin in order to trick you into running the attached virus," Trend Micro's Andy Liou told ZDNet.

The "trojan" tactic has been used widely, with varied success, Liou said.

-Previously trojans have even pretended to be 'antivirus updates', telling readers to run the attached file to update their antivirus protection. Obviously once the reader executes the attached file, their system is infected."

This is apparently the first time that a virus or worm has been distributed using a faked Microsoft security bulletin.

-Users should always check that the information they have received is authentic before taking any action," Liou advised.

Microsoft has been contacted for comment.

Advertisement

Talkback 4 comments

    Is anyone going to ever get ar ...Rob Hughes -- 21/07/01

    Is anyone going to ever get around to mentioning that there is a newer version using MS01-139 as the subject and using a newer varient of Leave, namely Leave.G or .H, depending on who you ask? This was all reported 5 days ago on bugtraq. One of the important bits is that since it uses a new varient, virus scanners won't pick it up until they're updated.

    Thanks for the heads-up!! Richard D. Retzke -- 22/07/01

    Thanks for the heads-up!!

    hi i was told that i have a vi ...Anonymous -- 23/07/01

    hi i was told that i have a virus thats called chok. and its on my msn messenger service. is there a way that i can get rid of it or something. because it says " George W. Bush@Whithouse.com is talking" everytime i start to chat with some on my msn messenger.

    There is a pop-up box with I.E ...Anonymous -- 24/07/01

    There is a pop-up box with I.E. saying something like "You have one message." The yellow triangle is blinking. You are not in any programs, just on-line because your dsl is on. It looks like a real IE product until you open it (especially if you are sleep deprived). I had a screen up long enough to see the word, "colonize" and turned everything off. Hope I can save some people. I'm not sure what "this" is doing, but I'm sure I will find out.

Add your opinion

Latest Videos

Blogs

  • Darren Greenwood Telecom NZ savings damage prospects
    If Telecom NZ wants to have any of the NZ$1.5 billion the government intends to spend on its new broadband network, it had better think long and hard before offshoring 1500 jobs.
  • Array iiNet: The whys and what nows
    Last week the Federal Court ruled that internet service providers are not responsible for copyright violation by their customers. This is an important decision not just for iiNet, which spent around $4 million defending the case, but for all ISPs in Australia and, indeed, globally.
  • Array Govt, hurry up with releasing data
    A programmer scraped data from the My School website to make some really cool heat maps showing regions of smart schools — no thanks to the government, which didn't supply the data in any useful kind of format.
  • More blogs »

Tags

Back to top

Featured