V
vectra-a-x.de
Gast
Neuer Trojaner versteckt sich hinter Windows-Update
Ein neuer Trojaner ist im Umlauf, der sich per e-Mail verbreitet und den User auffordert ein neues Windows-Update zu installieren. Die e-Mail ist angeblich von Microsoft selbst.
Sobald man auf den Link klickt, kommt man auf eine realistische Nachahmung der Microsoft-Homepage, wo man die Datei Wupdate-20050401.exe herunterladen soll. Dahinter verbirgt sich aber ein Trojaner, der die Kontrolle über den PC übernimmt.
Martino Corbelli von SurfControl sagte, der Trojaner werde nicht von Antiviren-Programmen erkannt, da er keinen typischen Spyware-Code in der exe-Datei enthalte.
Dagegen behauptet 'Sophos' den Trojaner seit Monaten abzuwehren
Also ist da VORSICHT geboten !!!Phoney Microsoft mail causes concern
Trojan attack spreading
Iain Thomson, vnunet.com 08 Apr 2005
ADVERTISEMENTA phoney email purporting to come from Microsoft is installing Trojan software on computers around the world.
The mail was sent out by spammers and asks the reader to install a Microsoft update. It has a link to a realistic looking Microsoft update page but the file installed, named Wupdate-20050401.exe, turns control of the PC over to the spammer.
"The email won't be picked up through anti-spyware software because the .exe file does not contain spyware signatures that would be used to identify it as potentially harmful," commented Martino Corbelli from SurfControl, who first detected the email in Australia this morning.
"Anti-spyware software tends to scan URLs and attachments in suspicious emails, but because none of the recognised spyware signatures are present in the .exe here, there's no way this approach could identify the threat.?
But this is disputed by other vendors. Sophos for example claims to have been blocking the trojan for months.
Once installed the software will run, taking up 100 percent of the CPU power by forcing it to perform continuous processes. It also allows the PC to be turned into a spam server remotely.
Companies are advised to inform staff of the mail and lock down PCs to stop any files being installed for the time being. Internet filtering companies have been informed and are blocking the false site.
Quelle: vnunet.com