Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » Security Watch » Fake Windows Patch Is a Windows Killer.

Security Watch - Fake Windows Patch Is a Windows Killer. posted in the Security & Safety forums; Security Watch: Fake Windows Patch Is a Windows Killer What it does: Downloader.EJD is a Trojan horse program that uses an updated version of an old trick: It's a false ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 09-02-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default Fake Windows Patch Is a Windows Killer.



Security Watch: Fake Windows Patch Is a Windows Killer


What it does: Downloader.EJD is a Trojan horse program that uses an updated version of an old trick: It's a false Microsoft security patch.

The actual Trojan horse program is separate from the mass-mailing that has been used to spread it, and it's the mailing that is most interesting. The From: address is spoofed as update@microsoft.com. The subject is What You Need to Know About the Zotob.A Worm. This is the body:

What You Should Know About Zotob
Published: August 14, 2005 | Updated: August 19, 2005 Severity VirusGreen

What the levels mean

Supported Software Affected
Windows All Version
Microsoft Security Advisory 899588
Zotob.A
Zotob.B
Zotob.C
Zotob.D
Zotob.E
Bobax.O
Esbot.A
Rbot.MA
Rbot.MB
Rbot.MC
Zotob is a worm that targets All Windows computers and takes advantage of a security issue that was addressed by Microsoft Security Bulletin MS05-039. This worm and its variants install malicious software, and then search for other computers to infect.

Important If you have installed the update released with Security Bulletin MS05-039, you are already protected from Zotob and its variants. If you are using any supported version of Windows, you are not at risk from Zotob and its variants.

Use the Microsoft Windows Malicious Software Removal Tool to search for and remove the Zotob worm and its variants from your hard drive.

This tool checks for and removes infections from Zotob.A through Zotob.E as well as Bobax.O, Esbot.A, Rbot.MA, Rbot.MB, and Rbot.MC. It also checks for and removes all versions of malicious software that the tool has been updated to remove.
And, most importantly, the attachment is named MS05-039.EXE. It is 21,229 bytes and is compressed with the MEW program.

When the attachment is executed, it first downloads a second Trojan program, Agent.AII, and executes it. This program downloads additional malware which logs keystrokes and accesses multiple web sites. It also attempts to modify the settings of security programs on the user's computer.

None of these programs display anything that the user can look for, so this attack is difficult to recognize.

From:
http://www.pcmag.com/article2/0,1895,1853366,00.asp



__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #2  
Old 09-02-2005
ladygreenwitch's Avatar
Administrator
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 4,697
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default Re: Fake Windows Patch Is a Windows Killer.

thanks Joe,

Great info. Is this serious enough to need to pass it along to everyone?

TTFN

T


  #3  
Old 09-02-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default Re: Fake Windows Patch Is a Windows Killer.



There are alot of people fooled by email's like this , and its real so yes.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #4  
Old 09-03-2005
Spaceman3750's Avatar
Elite Member
My PC
 
Join Date: Jan 2004
Location: Riverton, IL, USA
Posts: 1,511
PC Experience: Very Experienced
Spaceman3750 - See this Members User comments on their Profile page
Send a message via AIM to Spaceman3750 Send a message via MSN to Spaceman3750 Send a message via Yahoo to Spaceman3750
Default Re: Fake Windows Patch Is a Windows Killer.

Just to give a tip to everyone:

As far as I know, Microsoft will never send out e-mails with patches... You have to get them via Windows Update. Even if you are subscribed to their early alert system, you will still have to go to Windows Update to get the patch...


__________________
- Ryan
http://www.spaceman3750.info
http://www.conglomerate-game.net

Cisco Academy - CCNA student
  #5  
Old 09-03-2005
ladygreenwitch's Avatar
Administrator
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 4,697
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default Re: Fake Windows Patch Is a Windows Killer.

Very true Mr. Space,

But tons of people still click on them anyway. :cry: Silly people

Tj



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 01:27 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top
News
Workwide news from the UK paper - the mirror.

Debt Consolidation
Get out of debt fast with a debt consolidation loan.

Bad Credit Loans
Apply online for bad credit loans