• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

VIRUS WARNING!!! Do not open attachment claiming to be a Microsoft security update!

SubZeroX

Senior member
I've received this message from Microsoft 4 times. It comes with an attachment, which is supposed to be a security update. Of course I didn't open the attachment.

Virus info.


Microsoft Customer,

this is the latest version of security update, the
"12 Mar 2002 Cumulative Patch" update which eliminates all
known security vulnerabilities affecting Internet Explorer and
MS Outlook/Express as well as six new vulnerabilities, and is
discussed in Microsoft Security Bulletin MS02-005. Install now to
protect your computer from these vulnerabilities, the most serious of which
could allow an attacker to run code on your computer.


Description of several well-know vulnerabilities:

- "Incorrect MIME Header Can Cause IE to Execute E-mail Attachment" vulnerability. If a malicious user sends an affected HTML e-mail or hosts an affected
e-mail on a Web site, and a user opens the e-mail or visits the Web site,
Internet Explorer automatically runs the executable on the user's computer.

- A vulnerability that could allow an unauthorized user to learn the location of cached content on your computer. This could enable the unauthorized user to launch compiled HTML Help (.chm) files that contain shortcuts to executables, thereby enabling the unauthorized user to run the executables on your computer.

- A new variant of the "Frame Domain Verification" vulnerability could enable a
malicious Web site operator to open two browser windows, one in the Web site's
domain and the other on your local file system, and to pass information from
your computer to the Web site.

- CLSID extension vulnerability. Attachments which end with a CLSID file extension
do not show the actual full extension of the file when saved and viewed with
Windows Explorer. This allows dangerous file types to look as though they are simple,
harmless files - such as JPG or WAV files - that do not need to be blocked.


System requirements:
Versions of Windows no earlier than Windows 95.

This update applies to:
Versions of Internet Explorer no earlier than 4.01
Versions of MS Outlook no earlier than 8.00
Versions of MS Outlook Express no earlier than 4.01

How to install
Run attached file q216309.exe

How to use
You don't need to do anything after installing this item.


For more information about these issues, read Microsoft Security Bulletin MS02-005, or visit link below. http://www.microsoft.com/windows/ie/downloads/critical/default.asp
If you have some questions about this article contact us at rdquest12@microsoft.com

Thank you for using Microsoft products.

With friendly greetings,
MS Internet Security Center.
----------------------------------------
----------------------------------------
Microsoft is registered trademark of Microsoft Corporation. Windows and Outlook are trademarks of Microsoft Corporation.
 
hey Russ, you know that for sure? A lot of people will get tricked by this if it is a virus.

Something else I noticed is that the size of the attachment is different. One is 71 kb and another is 120 kb. This difinitely seems suspicious.
 


<< hey Russ, you know that for sure? A lot of people will get tricked by this if it is a virus.

Something else I noticed is that the size of the attachment is different. One is 71 kb and another is 120 kb. This difinitely seems suspicious.
>>

Yes it's a virus. Ironicly, your post is almost identical to one made on thursday or friday where someone had the same problem.
 
Virus, and also exposes you to a trojan.

Microsoft will NEVER send you an email with a file attachment
 
Info

"** W32.GIBE@mm WORM ** A worm is currently circulating that uses Microsoft Outlook and its own SMTP engine to spread. This worm arrives in an email message--which is disguised as a Microsoft Internet Security Update--as the attachment Q216309.exe. Check your anti-virus software vendors for updated virus definition files. (03/07/2002 - 11:45am PST)"
 
Thanks guys. I thought it was suspiscious as soon as I saw it coz I didn't think MS sends attachments.

I'll edit the title to warn others on AT.
 
Attachment = DELETE

No exceptions to that rule. If you can't put it in plain text, I don't want it. I will find files to download on my own thank you very much.

...and who thinks that Microsoft would take the time and bandwidth to email a file rather than post it on a server???

 


<< Attachment = DELETE

No exceptions to that rule. If you can't put it in plain text, I don't want it. I will find files to download on my own thank you very much.
>>



My policy exactly

unless I am expecting the attachment from someone I know
 
Back
Top