» Subscribe to Newsletter
» Switch to BizTech2.com
Home » News » Antivirus & Security Internet & Software » Worm Poses as IE Beta Download
Worm Poses as IE Beta Download
By: Sharon Khare   |   Apr 01,2007
Security Firm Sophos, is warning of a widespread malicious attack that poses as an invitation from Microsoft to download a beta version of Internet Explorer 7.0.

The emails, which claim to come from admin@microsoft.com and have the subject line "Internet Explorer 7 Downloads", display an image which invites users to download beta 2 of Internet Explorer 7. However, users who click on the image will download a file called ie7.0.exe which is infected by the W32/Grum-A worm.

"Worms like this are only succeeding in spreading because so many people have still not learnt to be suspicious of unsolicited emails, even if they claim to come from well-known companies like Microsoft," said Graham Cluley, senior technology consultant for Sophos. "The problem is that to the casual observer the email looks genuine, and the image displayed looks near-identical to the imagery that Microsoft is using on its website to promote Internet Explorer 7.0. Clicking on the image, however, doesn't download the real beta - but malicious code straight from the hackers."

The Grum worm is an appender virus which infects executable files referenced by Run keys in the Windows Registry. When run it copies itself to <Temp>winlogon.exe and makes changes to the Registry. It also edits the HOSTS file, injecting a thread into system.dll and attempts to patch the system files ntdll.dll and kernel32.dll.
 
Ads by Google 
Post a Comment on “Worm Poses as IE Beta Download”
Comment : 
Name : 
City : 
Email : 
There must be a source for the Grum worm other than the direct download. I was infected on Friday without opening such an email...and the infected computer is out of service. The logging on is impossible as the computer turns itself off again promptly before I can take any actions. I hope a solution will be found, as I am now using a borrowed computer while mine is out of service.
Arthur Holt @ Apr 01,2007
Ads by Google 
Ads by Google
Ads by Google
Products
Camcorders  |   Controllers  |   CPUs  |   Desktop PCs  |   Digital Cameras  |   Digital Video Recorders  |   DVD Players  |   Games  |   Gaming Consoles  |   General  |   GPS Systems  |   Handhelds / PDAs  |   Hard Drives  |   Headphones & Headsets  |   HiFi Audio Systems  |   Home Theater Systems  |   Input Devices  |   Internet  |   Laptops  |   Low Level Components  |   Mac Systems  |   Mobile Phone Accessories  |   Mobile Phones  |   Monitors  |   Motherboards  |   MP3 / Audio Players  |   Multi-Function Devices  |   Networking  |   Optical Drives  |   PC Accessories  |   PC Add-on Cards  |   PC Cabinets  |   PC Games  |   Printers  |   Projectors  |   RAM Modules  |   Scanners  |   Software  |   Speakers  |   Telecom  |   TVs  |   Video Players  |  
Careers | About Us | Ad Inventory | Site Profile | Feedback | Copyright © 2007, Tech2.com India - A Network 18 India Venture