Bogus MS emails

R

rippinchikkin

Has anyone else been getting these bogus Microsoft emails? I have
gotten like 4 today already, claiming to be from the MS security
division, with a .exe file. All looked very offical and all had the MS
patch number i.e. #Q4327blabla.....
get the picture. but all sacaned with norton and were virus loaded..
If you wanna download any new patches or updates do it from their
site.
Just though I would put my 2 cents worth out there.
 
M

Mike Brannigan [MSFT]

rippinchikkin said:
Has anyone else been getting these bogus Microsoft emails? I have
gotten like 4 today already, claiming to be from the MS security
division, with a .exe file. All looked very offical and all had the MS
patch number i.e. #Q4327blabla.....
get the picture. but all sacaned with norton and were virus loaded..
If you wanna download any new patches or updates do it from their
site.
Just though I would put my 2 cents worth out there.

Yes Millions of them are sent everyday to millions of users.
Any one that contains an attachment is not from us.
We will never send you an attachment - we always include a link to the file
for download.
see
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/policy/swdist.asp

--
Regards,

Mike
--
Mike Brannigan [Microsoft]

This posting is provided "AS IS" with no warranties, and confers no
rights

Please note I cannot respond to e-mailed questions, please use these
newsgroups
 
W

Will Denny

Mike Brannigan said:
Yes Millions of them are sent everyday to millions of users.
Any one that contains an attachment is not from us.
We will never send you an attachment - we always include a link to the file
for download.
see
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/policy/swdist.asp

Hi Mike

It seems as though more and more people are falling for these hoaxes and installing these 'updates' - there have been several instances today. The only way round it - so far as I can see - is to perform a 'clean' install as .EXE files are affected and can't be started. Several people have said that they can access their data files, which can be backed up prior to the re-install.

Will
 
L

Larry Samuels MS-MVP XP \(Shell/User\)

PSS Security Response Team Alert - New E-Mail Worm: W32/Swen@MM

SEVERITY: MODERATE
DATE: September 18, 2003
PRODUCTS AFFECTED: Microsoft Outlook, Microsoft Outlook Express, and
Web-based e-mail

**********************************************************************

WHAT IS IT?
W32/Swen@MM spreads via e-mail and network shares. The Microsoft
Product Support Services Security Team is issuing this alert to advise
customers to be on the alert for this virus as it spreads in the wild.
Customers are advised to review the information and take the appropriate
action for their environments.

IMPACT OF ATTACK: Mass Mailing, disabling processes related to security
software such as antivirus and firewall software

TECHNICAL DETAILS:
For additional details on this worm from anti-virus software vendors
participating in the Microsoft Virus Information Alliance (VIA) please
visit the following links:

Network Associates:

http://vil.nai.com/vil/content/v_100662.htm

Trend Micro:

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SWE
N.A

Symantec

http://securityresponse.symantec.com/avcenter/venc/data/[email protected]
ml

Computer Associates:

http://www3.ca.com/virusinfo/virus.aspx?ID=36939

For more information on Microsoft's Virus Information Alliance please
visit this link: http://www.microsoft.com/technet/security/virus/via.asp


Please contact your Antivirus Vendor for additional details on this
virus.


PREVENTION:

1. This worm is exploiting a previously patched vulnerability. The
vulnerability exploited is related to the following Microsoft Security
Bulletin:
http://www.microsoft.com/technet/security/bulletin/ms01-020.asp

As always, customers are advised to install the latest security patch
for Internet Explorer. Information on the latest cumulative security
patch for
Internet Explorer can be found here:
http://www.microsoft.com/technet/security/bulletin/MS03-032.asp

2. Outlook 2000 post SP2 and Outlook XP SP1 include the most recent
updates to improve the security in Outlook and other Office programs.
This includes the functionality to block potentially harmful attachment
types. If you are running either of these versions, they will (by
default) block the attachment, and you will be unable to open it.

To ensure you are using the latest version of Office click here:
http://office.microsoft.com/ProductUpdates/default.aspx

By default, Outlook 2000 pre SR1 and Outlook 98 did not include this
functionality, but it can be obtained by installing the Outlook E-mail
Security Update. More information about the Outlook E-mail Security
Update can be found here:

http://office.microsoft.com/Downloads/2000/Out2ksec.aspx

Outlook Express 6 can be configured to block access to
potentially-damaging attachments. Information about how to configure
this can be found here:

http://support.microsoft.com/default.aspx?scid=kb;en-us;Q291387

Outlook Express all other versions: Previous versions of Outlook Express
do not contain attachment-blocking functionality. Please exercise
extreme caution when opening unsolicited e-mail messages with
attachments.

Web-based e-mail programs: Use of a program-level firewall can protect
you from being infected with this virus through Web-based e-mail
programs.

RECOVERY:
If your computer has been infected with this virus, please contact your
preferred antivirus vendor or Microsoft Product Support Services for
assistance with removing it.

TECHNET SECURITY LINK:
http://www.microsoft.com/technet/security/virus/alerts/swen.asp

As always please make sure to use the latest Anti-Virus detection from
your Anti-Virus vendor to detect new viruses and their variants.

If you have any questions regarding this alert please contact your
Microsoft representative or 1-866-727-2338 (1-866-PCSafety) within the
US, outside of the US please contact your local Microsoft Subsidiary.
Support for virus related issues can also be obtained from the Microsoft
Virus Support Newsgroup which can be located by clicking on the
following link
news://msnews.microsoft.com/microsoft.public.security.virus.

PSS Security Response Team

--
Larry Samuels MS-MVP (Windows-Shell/User)
Associate Expert
Unofficial FAQ for Windows Server 2003 at
http://home.earthlink.net/~larrysamuels/WS2003FAQ.htm
Expert Zone -
 
R

rippinchikkin

Thanks for the response, no I haven't fallen for these. it just
concerned me because the email that I have been getting these on is a
private email address. It is only in my MCSE profile, at MS. It is not
an email that i give too friends or use for anything other than
official communication with Microsoft. I have 6 or 7 email address
that I use for various reasons. This is the only one that gets these.
This is why I think they came through you guys one way or another. I
know that they are a hoax and have never had a problem with them other
than having to delete so 400+ email from the last two days. so its
more of an annoyance than anything else

thanks

David
 
R

rippinchikkin

Thanks for the response, no I haven't fallen for these. it just
concerned me because the email that I have been getting these on is a
private email address. It is only in my MCSE profile, at MS. It is not
an email that i give too friends or use for anything other than
official communication with Microsoft. I have 6 or 7 email address
that I use for various reasons. This is the only one that gets these.
This is why I think they came through you guys one way or another. I
know that they are a hoax and have never had a problem with them other
than having to delete so 400+ email from the last two days. so its
more of an annoyance than anything else

thanks

David
 
G

Gordon Burgess-Parker

rippinchikkin said:
Thanks for the response, no I haven't fallen for these. it just
concerned me because the email that I have been getting these on is a
private email address. It is only in my MCSE profile, at MS. It is not
an email that i give too friends or use for anything other than
official communication with Microsoft.

I've had them on an email address that likewise I keep very private!
 
R

rippinchikkin

Ok my bad, they were coming in on another adderss. thanks for the
links. havent been affected, but the shear numbers of them is what
gets are annoying. I mean they coming in at the rate of one a minute
now, when I check my mail again there will be 20 new ones. However I
did get the root address out of one of the emails, since I dont know
the email I can only assume that it was not from there infected
addresdbook since they should not have my address. 8 more in the time
it took me to write this message.
these are two of the address that i pulled from the emails
(e-mail address removed)
(e-mail address removed)
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top