Virus Alert 'New Net Critical Pack'



On 6/13/2007 8:24:29 PM (CDT=GMT-5) I received an e-mail virus which was
caught and cleaned by my ISP.
Because I use SpamGourmet addresses ( http://spamgourmet.com ) in the
Reply-To: header on all usenet postings, I can tell that it was sent to
the address that I only use for postings in the genealogy newsgroups. As
far as I can tell, the only postings I have made with this particular
address were to soc.genealogy.computing on 2007-04-12 and to
alt.talk.royalty on 2007-04-16 and 2007-04-30.

The subject of the e-mail was 'New Net Critical Pack'
Text in the message includes:

MS Consumer

this is the latest version of security update, the "June 2007,
Cumulative Patch" update which eliminates all known security
vulnerabilities affecting MS Internet Explorer, MS Outlook and MS
Outlook Express as well as three newly discovered vulnerabilities.
Install now to protect your computer from these vulnerabilities, the
most serious of which could allow an attacker to run executable on your
computer. This update includes the functionality of all previously
released patches.
[SNIP]
It 'looks like' it came from Microsoft and includes links to the MS
Knowledge Database, etc.

The alert from my ISP states:
file attachment: Installer6.exe
The file attached to this email was removed because it is infected with
the W32.Swen.A@mm virus.

If you get something similar, DON'T OPEN THE ATTACHMENT!!!

Microsoft has never actually sent me an e-mail for an update. All of
it's many updates (for my WinXP) are automatically downloaded by the OS.
--
Bill the Turnipman
'Reply To:' address is valid
.



Relevant Pages

  • Virus Alert New Net Critical Pack
    ... caught and cleaned by my ISP. ... the address that I only use for postings in the genealogy newsgroups. ... Outlook Express as well as three newly discovered vulnerabilities. ... file attachment: Installer6.exe ...
    (alt.talk.royalty)
  • Re: New Trailer!!!
    ... complaining to my ISP regarding some of my postings. ... I also now also understand that all of the meaningless postings you ... I believe NETKNOW is a franchaise sold out of the UK. ... Merry CHRISTmas 2007 and Happy New Year 2008! ...
    (rec.arts.drwho)
  • Re: New Trailer!!!
    ... Bazza wrote: ... In retaliation I decided to do some digging on your own ISP. ... I also now also understand that all of the meaningless postings you ... Merry CHRISTmas 2007 and Happy New Year 2008! ...
    (rec.arts.drwho)
  • Re: New Trailer!!!
    ... Bazza wrote: ... In retaliation I decided to do some digging on your own ISP. ... I also now also understand that all of the meaningless postings you keep ... I would recommend you don't file any more abuse reports. ...
    (rec.arts.drwho)
  • Re: Mandrake & CERT advisories
    ... They are very proactive in announcing vulnerabilities and patches to ... Updated sendmail packages fix remotely exploitable buffer overflow ... I see Red Hat in those postings, ...
    (comp.os.linux.security)