Published on Maximum PC (http://www.maximumpc.com)


Fake Microsoft Update Email Can Ruin Your Evening - Stop It Now!
Created 01/22/2008 - 7:25pm

Maximum IT
    • Microsoft Revamps Pricing for Online Business Suite
    • Blue Coat Security Firm Trims Staff, Buys Services Company
    • Microsoft to Issue Six Patches Next Week, Ties Most Ever in Month of November

    Sponsored
SEE MORE MAXIMUM IT
News
  • Zune HD v4.3 Firmware Update Brings Several New Improvements
  • Managed Copy Enabled Blu-Rays Coming Soon
  • ECS Becomes Latest Company to Offer USB 3.0, SATA 6Gb/s Cards
  • John Carmack: RAGE Probably Won’t Support Dedicated Servers
  • Warhammer Online’s Endless Trial Begins
SEE MORE NEWS
News

Fake Microsoft Update Email Can Ruin Your Evening - Stop It Now!

Posted 01/22/08 at 09:25:52 PM  by Mark Soper

comment Commentsprint Printemail EmailDeliciousDiggStumbleUponRedditFacebookSlashdot

Heed This "Warning" - And You'll Be Sorry

Security vendor Sunbelt Software's blog reports that a fake warning to "update your P.C. in maximum 12 hours otherwise your Windows will be Expired" is making the email rounds. While the message (visible here) has all of the earmarks of a fake (including broken English), it might convince some technical novices that they'd better get clicking. If they do click, what happens? They download IRC.Backdoor.Trojan, an old threat that can still take over a system. It's disguised as updateWindows.exe. You can learn more about how it works by reading PacketShack.org's analysis.

Removing IRC.Backdoor.Trojan

There are a large number of variants of this nasty bit of malware, as this Tek-Tips thread suggests. It also goes by many different names depending upon the antivirus vendor, including Win32.HackTool (eSafe), Backdoor.IRC.Zapchast (F-Secure and Kaspersky), Riskware.HideWindow.B (Webwasher-Gateway), and many others (link requries a PDF reader). Some antivirus programs may have difficulty removing it.

If you're working on an infected computer and can't get rid of it, one Tek-Tips poster recommends using the free F-Secure online scanner. You must use IE6 or IE7 with ActiveX enabled to use the F-Secure scanner, and it runs on Windows XP or 2000 (a beta version is available for Windows Vista users).

What Not to Click

Tired of fixing virus and malware infections? Remind your family, friends, co-workers (and anybody else who thinks you're a technology genius) of the rules for staying out of trouble online:

  • Don't click links purporting to come from PayPal, eBay, or your local bank or credit union
  • Always log into Windows Update, e-commerce and similar sites manually
  • Hover the mouse over links in an email or web page to find out where it will really take you
  • Ignore logos and artwork when attempting to determine if an email or website is legit - they're easily stolen and reused

These can be summarized in one rule: Think before you click!

COMMENTS:0
TAGS: windows, Software, news, virus, malware, antivirus, XSS, antimalware, Trojan Horse, fake email, sunbelt
COMMENTS
  • Login or register to post comments
  • Technology News

  • Computer Cooling Fans

  • Computer Cases

  • PC Game Controllers

  • PC Games

  • Computer Hardware

  • Headphones

  • MP3 Players

  • Stream Video

  • Computer Mouse

  • Monitors

  • Motherboards

  • NAS Storage

  • Networking

  • Laptop Computers

  • DVD Burner

  • Digital Cameras

  • Portable Storage

  • Computer Accessories

  • Smartphone

  • Antivirus Software

  • Sound Cards

  • Speakers

  • Computer Systems

  • Thumb Drives

  • Video Cameras

  • Video Card Reviews

  • Water Cooling

  • Gadgets

  • Keyboards
  • Contact Us
  • Advertising
  • Privacy Policy
  • Terms & Conditions
  • RSS Feeds
  • TechBlips
  • PCHardwareBlips
  • Site Map
  • Customer Service
Future © 2009 Future US, Inc. All Rights Reserved.

Source URL: http://www.maximumpc.com/article/fake_microsoft_update_email_can_ruin_your_evening_stop_it_now

Links:
[1] http://www.maximumpc.com/user/marcus_soperus
[2] http://sunbeltblog.blogspot.com/2008/01/fake-ms-update.html
[3] http://research.sunbelt-software.com/threatdisplay.aspx?name=IRC.Backdoor.Trojan&threatid=45277
[4] http://www.packetshack.org/index.php?page=fDDoS
[5] http://www.tek-tips.com/viewthread.cfm?qid=1431507&page=1
[6] http://www.sunbelt-software.com/ihs/alex/vt21888123888.pdf
[7] http://support.f-secure.com/enu/home/ols.shtml
[8] http://www.maximumpc.com/article/safer_browsing
[9] http://www.maximumpc.com/article/googles_in_the_xss_crosshairs_and_so_are_you
[10] http://www.maximumpc.com/article/How-To--Protect-Yourself-from-Phishing-and-Pharming
[11] http://www.maximumpc.com/article/smart_new_malware_targets_e_banking_are_you_ready