Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


January 09, 2004

New Trojan Claims to be Microsoft Patch

RSS
Subscribe to Windows IT Pro | See More Antivirus Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

A new Trojan, “Xombe,” was released into the wild on Friday, January 9, which claims to be a critical patch from Microsoft. According to iDefense, the Trojan was purposely coded to try to avoid detection by anti-virus software.

The Trojan has a message subject that reads, “Windows XP Service Pack 1 (Express) - Critical Update” with a sender email address of “Windowsupdate@microsoft.com”. The message contains a file attachment and the message body urges users to run the attached file to eliminate all known vulnerabilities in Internet Explorer, Outlook, and Outlook Express. When run the Trojan attempts to download software from a remote site and if successful installs a backdoor into the user's computer.

As you know, Microsoft said that it will never send patches or updates via email. So users should become aware that any such message and related file attachment is probably an attempt to compromise the security of their systems.

End of Article



Reader Comments
please tell me more about this it is installed on my machine but I guess i am not noticing it because my machine is highly secured and the programming languages havent complained thanx

Mark January 10, 2004


Do we not know any filenames this thing (xombe) might leave? Or any way of stopping it?

pfg.

Peter F. Goddard January 14, 2004


I have WinXP Pro with auto-update enabled. I don't update via email. So this shouldn't be an issue.

Anthony January 14, 2004


I don't do any email updates either. but sure got something from somewhere. It shuts down computer in 60 seconds with NT authority\system. Also Remote Procedure Call{RPC} Service Terminated can't stay on line long enough to download any kind of a fix. This is the longest I've been on line for.

terry January 15, 2004


Yeah i had the RPC error too once. I fixed the problem by reformatting my hard-drive and reinstalling WinXP. then i found two other friends with the same problem, and did the same to their computers. if you need to stay on your computer, you should be able to abort the 60 second shutdown procedure by going to Start, Run, then type "cmd" (no quotes) to go to Command Prompt.. from there, type "shutdown -a" i hope this helped! if so, get back to me and i'll post this info on other forums to help other people.
Nathan - iamsocanadian_eh@hotmail.com

Nathan January 20, 2004


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

WinInfo Short Takes: Week of November 9, 2009

An often irreverent look at some of the week's other news, including some more Windows 7 sales momentum, some Sophos stupidity, Microsoft's cloud computing self-loathing, more whining from the browser makers, Zoho's "Fake Office," and much, much more ...

Understanding File-Size Limits on NTFS and FAT

A general confusion about files sizes on FAT seems to stem from FAT32's file-size limit of 4GB and partition-size limit of 2TB. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events WinConnections and Microsoft® Exchange Connections

Introduction to Identity Lifecycle Manager "2"

SQL Server Security: How to Secure, Monitor & Audit Your Databases

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement