ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/reg/register.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    Grum worm poses as IE7 beta

Hackers con users into downloading malware with fake IE7 file, despite full version being out several months.

By Rene Millman, 2 Apr 2007 at 20:11

Hackers are trying to trick users to download malware posing as a beta version of Microsoft's Internet Explorer 7 despite the full version being released last October.

Emails delivered to unsuspecting users pretend to come from admin@microsoft.com with a subject line such as "Internet Explorer 7 Downloads". On the email is an image of the IE7 icon, clicking on the image downloads a file called ie7.0.exe which contains the Grum worm.

The Grum worm is an appender malware which infects executable files referenced by the Windows registry. When the worm starts, it copies itself to winlogon.exe and then changes registry keys. It also adds entries to the OS's hosts file, injects a thread into the system.dll file and and alters the ntdll.dll and kernel32.dll.

According to Graham Cluley, senior technology consultant at anti-virus firm Sophos posing as a download from Microsoft is a common trick up the hacker's sleeve.

"There have been many occasions when virus writers have coded attacks that have presented themselves as communications from Microsoft," he said. "In 2003 the Gibe-F worm posed as a critical security update from the software giant, and two years ago hackers directed internet users to a bogus website masquerading as Microsoft's update page."

Email to a friend

Print this page

< Previous   Security : News Next >

Be the first to comment on this article

You need to Login or Register to comment.

    You may also like...

 Sponsored Links

advertisement

    You may also like...

advertisement

    Register for IT PRO

You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Sponsored Links
Advertisement