Results 1 to 6 of 6
Like Tree5Likes
  • 1 Post By Bearcat
  • 1 Post By Bearcat
  • 1 Post By BigGuy
  • 1 Post By Bearcat
  • 1 Post By BigGuy

Thread: Fake Microsoft Office tool hides worm

  1. #1
    I'd rather be fishing!
    Overall activity: 0%

    Join Date
    Jan 2011
    Location
    Minnesota, USA
    Posts
    3,155
    Liked
    1543 times
    Points
    4,220

    Fake Microsoft Office tool hides worm

    If you use Microsoft Office, a sneaky and harmful worm may be out to infect your system.

    The security firm Bitdefender found a worm, identified as Win32.Worm.Coidung.B, that disguises itself as Office Genuine Advantage (OGA), a program Microsoft deployed in the past to validate customers' copies of Office and let them download files and updates from the Microsoft website. Microsoft retired OGA in December 2010, but that hasn't stopped the attackers from using it to ensnare victims a year later.

    The fraudulent OGA program, labeled "office_genuine.exe," is spreading via Yahoo Messenger, and once the attachment is downloaded, it opens a portal in people's computers for another infected file, Win32.Virtob, to do its damage.

    Bitdefender's Loredana Botezatu wrote of Coidung, "The worm operates fast, disables the Windows Firewall and opens a back door to allow a remote attacker to access and control the compromised computer."

    Adding insult to infection, Coidung makes copies of itself and hides them in multiple system folders under various names, Botezatu said. The worm prevents its multiple copies from being deleted, deactivated or removed.

    The Coidung worm even comes bundled with a virus, Win32.Virtob, which operates separately and infects Web application files on the compromised machines.

    This threat applies only to the Microsoft Office suite. The overall Windows Genuine Advantage (WGA) program, which validates copies of Windows 7 or Vista, is still in effect.

    Online scammers often piggyback on the legitimacy of anti-virus or threat-detecting software to launch attacks. Right around the time OGA was decommissioned last year, crooks began spreading malware by disguising it as a Microsoft Security Essentials update.

    The best advice to avoid falling victim to these types of threats is to avoid downloading suspicious attachments, especially if they come in unsolicited emails.

    Source: http://www.msnbc.msn.com/id/45339020...ence-security/
    Life isn't about waiting for the storm to pass, it's about learning to dance in the rain!

  2. #2
    Righteous Dude
    Overall activity: 50.0%

    Join Date
    Aug 2009
    Location
    Bay Area, California
    Posts
    1,902
    Liked
    784 times
    Points
    25,870
    Lol, was just going to post this. The Bear is quicker than the Guy

    A Guy

  3. #3
    I'd rather be fishing!
    Overall activity: 0%

    Join Date
    Jan 2011
    Location
    Minnesota, USA
    Posts
    3,155
    Liked
    1543 times
    Points
    4,220
    Quote Originally Posted by A Guy View Post
    Lol, was just going to post this. The Bear is quicker than the Guy

    A Guy
    Don't feel back A Guy, us bears have 4 wheel drive you know.

  4. #4
    Star
    Overall activity: 62.0%

    Join Date
    Nov 2009
    Location
    United States
    Posts
    1,016
    Liked
    862 times
    Points
    32,631
    Thanks for the news Uncle Bear. I will show my dad this article also.
    In loving memory of my Grandpa John and Great Uncle Barry.

  5. #5
    I'd rather be fishing!
    Overall activity: 0%

    Join Date
    Jan 2011
    Location
    Minnesota, USA
    Posts
    3,155
    Liked
    1543 times
    Points
    4,220
    Good idea Buddy. He does have MS Office on the home PC doesn't he.

  6. #6
    Star
    Overall activity: 62.0%

    Join Date
    Nov 2009
    Location
    United States
    Posts
    1,016
    Liked
    862 times
    Points
    32,631
    Quote Originally Posted by Bearcat View Post
    Good idea Buddy. He does have MS Office on the home PC doesn't he.
    Yes he does and I showed him this article last night.

 

 

Similar Threads

  1. Fake antivirus removal tool
    By Networx in forum Spyware/Viruses
    Replies: 7
    Last Post: 12-27-2011, 11:33 AM
  2. Fake Microsoft update : Malware disguise in it !!!!
    By INDRANIL in forum Spyware/Viruses
    Replies: 16
    Last Post: 05-28-2011, 10:42 AM
  3. Trend Micro Fake Antivirus Removal Tool v 1.0.1015 (BETA)
    By leofelix in forum Security Bulletin
    Replies: 3
    Last Post: 04-15-2011, 07:24 PM
  4. Fake Microsoft Security Essentials software
    By princeaniket in forum Spyware/Viruses
    Replies: 6
    Last Post: 10-29-2010, 04:35 AM
  5. Replies: 34
    Last Post: 01-16-2010, 04:01 PM
All times are GMT +8. The time now is 10:00 AM.