TECH.BLORGE.com
VISTA.BLORGE.com
MAC.BLORGE.com
GAMER.BLORGE.com

March 30, 2007 |

Internet Explorer 7 beta email is Grum worm in disguise

By John Pospisil





Internet Explorer beta email is Grum worm in disguise As I was working on my PC yesterday I received a number of odd emails from “admin@microsoft.com” inviting me to download Internet Explorer 7. I would never expect Microsoft to promote itself in this way, so I immediately suspected the emails were some kind of spam or a worm. Today Sophos has issued a warning about this very email: anyone who clicks on the embedded image contained in the email will download a file called ie7.0.exe which is infected by the W32/Grum-A worm.

“Worms like this are only succeeding in spreading because so many people have still not learnt to be suspicious of unsolicited emails, even if they claim to come from well-known companies like Microsoft,” said Graham Cluley, senior technology consultant for Sophos.

“The problem is that to the casual observer the email looks genuine, and the image displayed looks near-identical to the imagery that Microsoft is using on its website to promote Internet Explorer 7.0.”

The Grum worm is an appender virus which infects executable files referenced by Run keys in the Windows Registry. When run it copies itself to <Temp>\winlogon.exe and makes changes to the Registry. It also edits the HOSTS file, injecting a thread into system.dll and attempts to patch the system files ntdll.dll and kernel32.dll.

What always amazes me about these malicious email attacks is the massive scale on which they take place – in the space of just a few hours I received three of these emails to different email addresses that I use, and several friends also reported receiving the same email.

Beyond always running an integrated security package to protect your computer from viruses, spyware and spam, it’s also good practice to avoid clicking on links in emails.

Keep in mind that companies like Microsoft would never use SPAM email to promote their products. And even emails coming from friends could have been generated by viruses.

Related:

  • Blogger hit with a Storm Watch
  • Internet Explorer 8 beta 2 to be available August 20
  • Microsoft to release Internet Explorer 8 beta next year
  • Microsoft’s Internet Explorer 8 enters beta testing
  • IE7 Pro add-on plays nice with IE8 beta 1




  • Sign up for the BLORGE daily email newsletter

    One Response to “Internet Explorer 7 beta email is Grum worm in disguise”

    1. dvous:

      Many Win XP users would have been automatically updated to IE7 by the Windows update system that is enabled by default on most legitimate installations with Service Pack 2.

      Also, if obtained via another method, the genuine IE7 routine will check the legitimacy of your Windows installation before proceeding.

      That said, there’s still a percentage of people who will be caught by this attack.

    Leave a Reply:

    Copyright © 2008 Engaging and compelling blogs that entertain and inform