Bogus Microsoft bulletin spreads virus

A fake Microsoft security alert is being used to spread the latest version of a worm over the Internet.

The W32.Leave.B.Worm is a variant of the W32-Leave.worm reported recently, and according to Symantec's Web site, the virus is sent via email with the Subject: Microsoft Security Bulletin MS01-037 and Message: The following is a Security Bulletin from the Microsoft Product Security Notification Service.

The bogus bulletin dramatically declares that -the Internet has seen one of the first of its downfalls" and goes on to mention the virus which has -the complexity to destroy data like none seen before".

Users are encouraged to protect their systems by downloading and installing an attached "security patch" from a linked Web site, which resembles that of Microsoft - the patch has since been removed from the hosted site.

-This fake Microsoft security bulletin uses 'tricks' similar to a trojan virus - that is, it tries to pretend to be an authentic security bulletin in order to trick you into running the attached virus," Trend Micro's Andy Liou told ZDNet.

The "trojan" tactic has been used widely, with varied success, Liou said.

-Previously trojans have even pretended to be 'antivirus updates', telling readers to run the attached file to update their antivirus protection. Obviously once the reader executes the attached file, their system is infected."

This is apparently the first time that a virus or worm has been distributed using a faked Microsoft security bulletin.

-Users should always check that the information they have received is authentic before taking any action," Liou advised.

Microsoft has been contacted for comment.

Advertisement

Talkback 4 comments

    Is anyone going to ever get ar ...Rob Hughes -- 21/07/01

    Is anyone going to ever get around to mentioning that there is a newer version using MS01-139 as the subject and using a newer varient of Leave, namely Leave.G or .H, depending on who you ask? This was all reported 5 days ago on bugtraq. One of the important bits is that since it uses a new varient, virus scanners won't pick it up until they're updated.

    Thanks for the heads-up!! Richard D. Retzke -- 22/07/01

    Thanks for the heads-up!!

    hi i was told that i have a vi ...Anonymous -- 23/07/01

    hi i was told that i have a virus thats called chok. and its on my msn messenger service. is there a way that i can get rid of it or something. because it says " George W. Bush@Whithouse.com is talking" everytime i start to chat with some on my msn messenger.

    There is a pop-up box with I.E ...Anonymous -- 24/07/01

    There is a pop-up box with I.E. saying something like "You have one message." The yellow triangle is blinking. You are not in any programs, just on-line because your dsl is on. It looks like a real IE product until you open it (especially if you are sleep deprived). I had a screen up long enough to see the word, "colonize" and turned everything off. Hope I can save some people. I'm not sure what "this" is doing, but I'm sure I will find out.

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured