Zitat
Upon clicking the included URL they are directed to a fraudulent website hosted in Canada, which was up and running at the time of this alert. The site uses screenshots of the real Microsoft security update site. Included is a link to the patch which is a program called "plugandplayfix.exe". The website URL is hosted on a machine which appears to have been compromised and simply has an IP address followed by:
http://<IP address removed>/update.microsoft.com/windowsupdate/v6/plugandplayfix.exe
Upon execution the Trojan Horse opens a backdoor on the machine, connects to an IRC channel, and modifies several system variables.
Source -> Email Body;Web site Screenshot
http://www.websensesecuritylabs.com/alerts...php?AlertID=330
So können Sie feststellen ob eine Sicherheitsbenachrichtigung von Microsoft stammt
http://www.microsoft.com/austria/technet/a...s/fakemail.mspx
Dieser Beitrag wurde von Genc bearbeitet: 08. November 2005 - 21:03

Hilfe
Neues Thema
Antworten
Nach oben





