Simple clear advice in plain English

New version of stration worm pretends to be security patch

Worming its way into your affections by pretending to be protection

The latest version of the Stration worm is posing as a firewall security patch and spreading rapidly via email systems.

The Stration worm attacks a PC in a variety of ways; it turns off anti-virus applications and allows others to access the computer. In addition is downloads other malicious code from the internet as well as intalling itself in the computer's registry.

The emails don't require any user intervention to mail itself out as it downloads its own email engine. The user therefore is often unaware that this worm is sending out email messages to email addresses found on the infected computer.

To cover its tracks even further, it forges the sender's email address. Security company Sophos warns that the latest version has been aggressively distributed by its author since the early hours of Monday morning.

The new version , spreads via email using a variety of disguises, which ironically poses as a warning that the recipient's computer has been determined to be infected by a worm.

Sophos experts believe that the worm is using the disguise of a security warning to play on concern about an unpatched vulnerability in Microsoft's software.

"Many Windows users are waiting anxiously for Microsoft to fix the VML flaw in its code, which has been exploited by hackers," said Graham Cluley, senior technology consultant for Sophos.

"It's possible that those behind the Stration worm are playing on the internet community's heightened concern over being left unprotected by Microsoft. As a result the perpetrators may be able to fool innocent users into rushing into running the malicious update.

"The lesson to learn is that you should only ever get your security patches from the vendors' official website, not from an unsolicited email."

"Anyone accessing their email [also] has to learn to resist the temptation of opening unsolicited attachments, and ensure their anti-malware protection is kept fully up-to-date."

An example of one of the messages in the infected emails is given below.

Subject line: Mail server report.

Message text:
Mail server report.

Our firewall determined the e-mails containing worm copies are being sent from your computer.

Nowadays it happens from many computers, because this is a new virus type (Network Worms).

Using the new bug in the Windows, these viruses infect the computer unnoticeably. After the penetrating into the computer the virus harvests all the e-mail addresses and sends the copies of itself to these e-mail addresses

Please install updates for worm elimination and your computer restoring.

Best regards,
Customers support service

Attached file: Update-KB7859-x86.zip which contains Update-KB7859-x86.exe

Reader Comments

   

Add your comment

All fields must be completed. Your email address will not be displayed or used to send marketing messages.

All messages will be checked by moderators before appearing on the site.

See our Privacy Policy for more information.

Related articles

screen-shot-2009-12-10-at-14

Users of porn site left exposed as names are published online

Sophos suggests password change after popular site is "caught with its pants down"

malware

Sophos warns fake Adobe upgrade contains Zeus Trojan

Attached ZIP file in emails could con people into downloading banking Trojan

Move files quickly screenshot

Move your files faster in Windows

Moving or copying files and folders in Windows can be extremely taxing. We show you how Richcopy, a free utility, allows you to copy more than one item at a time

Question & Answer

Q.Why are some of the keys on my keyboard doing strange...

> Read the answer

Q.Is my phone’s Bluetooth any use?

> Read the answer

Q.Can I switch boot drives so that I can work on older...

> Read the answer

Best deals on the web

img

Apple iMac 21.5" (MC309)

£926.40- Buy it now

img

Dell Inspiron 620 ST Intel Core i3-2100 3.10GHz / 3GB / 500GB / DVDRW / Win 7 Home Premium

£329.00- Buy it now

img

ZooStorm 7877-1023

£386.38- Buy it now

Latest issue & subscription deals

Poll

Are you concerned about viruses that target mobile phones?

Jargon Buster

Computing terms explained in plain English

Virtual drive

A set of files seen by Windows as a separate hard disk.

Great shopping deals from Computeractive