Can I trust it ???

  • Thread starter Thread starter BoazBoaz
  • Start date Start date
BoazBoaz said:
I get lots of mail such these
http://img100.imageshack.us/img100/5733/micro4bb.gif can I trust it ???


Note: See the attachment warning !!!

No, it's most definitely not to be trusted.

What you're receiving is most likely the output of a computer
infected by one of several widely publicized, wide-spread, mass emailing
worms. The virus' authors have deliberately spoofed the Microsoft
information in the hopes of garnering more victims. This sort of email
has been very common for past few years. Some of the most widely-known are:

W32.Swen.A_mm
http://securityresponse.symantec.com/avcenter/venc/data/[email protected]

W32.Dumaru_mm
http://securityresponse.symantec.com/avcenter/venc/data/[email protected]

W32.Gibe_mm
http://securityresponse.symantec.com/avcenter/venc/data/[email protected]

Trojan.Xombe
http://www.symantec.com/avcenter/venc/data/trojan.xombe.html

Microsoft never has, does not currently, and very probably never
will email unsolicited security patches. At the most, if -- and only if
-- you subscribe to their security notification newsletter, they will
send you an email informing you that a new patch is available for
downloading.

Microsoft Policies on Software Distribution
http://www.microsoft.com/technet/treeview/?url=/technet/security/policy/swdist.asp

Information on Bogus Microsoft Security Bulletin Emails
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/news/patch_hoax.asp

How to Tell If a Microsoft Security-Related Message Is Genuine
http://www.microsoft.com/security/antivirus/authenticate_mail.asp

Remember, any and all legitimate patches and updates are readily
available at http://windowsupdate.microsoft.com/, and no where else.
You should develop the habit of checking this site at least once a month
to keep your computer up-to-date. (Notice that this is the true URL,
rather than the bogus one that may have been contained in the email you
received.) Any messages that point to any other source(s) or claim to
have the patch attached are bogus.

You're receiving these emails because your email address is in
the address book of someone infected with a worm, and/or because you
posted your real email address somewhere on-line, either in a forum
accessible to the public and spambots, such as Usenet, or on an
untrustworthy web site that subsequently sold your address as part of a
mailing list. One thing you can do is notify _everyone_ with whom
you've ever corresponded via email that one or more of them may be
infected with a mass emailing worm, and should take the appropriate
steps. You can also ask your ISP to take steps to preclude their mail
server from passing on such emails. Many ISPs have such filtering
capabilities.



--

Bruce Chambers

Help us help you:



They that can give up essential liberty to obtain a little temporary
safety deserve neither liberty nor safety. -Benjamin Franklin
 
From: "BoazBoaz" <[email protected]>

| I get lots of mail such these
| http://img100.imageshack.us/img100/5733/micro4bb.gif can I trust it ???
|
| Note: See the attachment warning !!!
|

If you post to UseNet with your TRUE, not a munged, email address then you have invited the
swen Internet worm [aka; W32/Gibe-F] to visit you.

The Swen is news spelled backwards. The reason it is called this is because the Swen worm
harvests email addresses from UseNet News Groups. It has an engine that allows it to post
itself to UseNet News Groups and well as it has its own email engine. From the list of
email addresses that it has harvested, it will then email itself to those addresses.

W32/Swen@MM - http://vil.nai.com/vil/content/v_100662.htm

W32.Swen.A@mm - http://securityresponse.symantec.com/avcenter/venc/data/[email protected]

There are several Internet worms that masquerade as patches from Microsoft. The most common
are; Swen, Dumaru, Gibe and Torvil. All AV companies and Microsoft are fully aware of this
problem.

All you can do is...

1. Keep your AV package up-to-date
2. Create email "rules" to auto-delete the offending messages
3. Petition your ISP to install AV software on their respective email servers.
4. Install all MS Critical Updates via the Windows Update web site.
5. Always munge your email address when posting to UseNet
6. If all else fails, Change your email address.
 
Included the mail header:


Code:
Return-Path: <[email protected]>
Received: from mr8.bezeqint.net (mr8.bezeqint.net [192.115.104.78])
by mas28.bezeqint.net (MOS 3.7.4b-GA)
with ESMTP id ABX40096;
Sun, 16 Apr 2006 11:41:36 +0300 (IDT)
Received: from smtp3.vol.cz (smtp3.vol.cz [195.250.128.83])
by mr8.bezeqint.net (MOS 3.7.2-GA)
with ESMTP id AES39723;
Sun, 16 Apr 2006 11:43:05 +0300 (IDT)
Received: from loaytsws (a4prg-57.dialup.vol.cz [83.148.19.57])
by smtp3.vol.cz (Postfix) with SMTP id D983459235;
Sun, 16 Apr 2006 10:42:15 +0200 (CEST)
FROM: "Technical Bulletin" <[email protected]>
TO: "Consumer" <[email protected]>
SUBJECT: New Security Update
Mime-Version: 1.0
Content-Type: multipart/mixed; boundary="daiochinde"
Message-Id: <[email protected]>
Date: Sun, 16 Apr 2006 10:42:15 +0200 (CEST)



I'v added the (e-mail address removed) to my blocked sender list.

BoazBoaz said:
Thank you Very much

David H. Lipman said:
From: "BoazBoaz" <[email protected]>

| I get lots of mail such these
| http://img100.imageshack.us/img100/5733/micro4bb.gif can I trust it ???
|
| Note: See the attachment warning !!!
|

If you post to UseNet with your TRUE, not a munged, email address then
you have invited the
swen Internet worm [aka; W32/Gibe-F] to visit you.

The Swen is news spelled backwards. The reason it is called this is
because the Swen worm
harvests email addresses from UseNet News Groups. It has an engine that
allows it to post
itself to UseNet News Groups and well as it has its own email engine.
From the list of
email addresses that it has harvested, it will then email itself to those
addresses.

W32/Swen@MM - http://vil.nai.com/vil/content/v_100662.htm

W32.Swen.A@mm -
http://securityresponse.symantec.com/avcenter/venc/data/[email protected]

There are several Internet worms that masquerade as patches from
Microsoft. The most common
are; Swen, Dumaru, Gibe and Torvil. All AV companies and Microsoft are
fully aware of this
problem.

All you can do is...

1. Keep your AV package up-to-date
2. Create email "rules" to auto-delete the offending messages
3. Petition your ISP to install AV software on their respective email
servers.
4. Install all MS Critical Updates via the Windows Update web site.
5. Always munge your email address when posting to UseNet
6. If all else fails, Change your email address.
 
From: "BoazBoaz" <[email protected]>

< snip >

|
| I'v added the (e-mail address removed) to my blocked sender list.

I doubt that is enough. Next time it comes, it will come from a different fake name.
 
Back
Top