Feeds

Y2k fix email contains its own bug

Virus hidden in message that claims to come from MS

  • alert
  • submit to reddit

Internet Security Threat Report 2014

Email users are being warned to watch out for a sneaky virus that masquerades as a Y2k fix from the mighty Microsoft. Hackers have latched onto people's fears about the millennium bug, and created a selection of email messages that promise a free Y2k fix. But on opening, the email's attachment -- which claims to come from support@microsoft.com -- the user activates the virus, called Y2KCount. The next time they log on, the virus scans for their user name and password, and sends it back to the creators of the virus. Or at least that's the theory. These fraudsters can supposedly use the ISP account without the user's knowledge for free -- and send emails as if they were that person, according to Paul Brettal, product consultant at Data Fellows. "It is a clever virus because the anyone would be able to send emails and look like they work at that company. They would also get free access to the ISP account -- more of an issue in the US than the UK, where more ISPs make monthly charges." Brettal said the virus was under control, and had not yet surfaced in the UK. What's more, Jason Holloway, Data Fellows country manager, said the virus itself seemed to have a fault that would prevent it from wreaking havoc. "The Y2KCount virus seems to have a fault in the coding -- a problem in the activation routing. As far as we are aware, this means it has been unsuccessful in sending any user names and passwords back the creators of the virus. "This is similar to around 75 per cent of the viruses we see because they are largely made be amateurs." However, Holloway warned that the Y2KCount did show the dire possibilities of such a virus. Similarly, Microsoft is not taking any chances. Earlier this week, Don Jones, Microsoft's director of Year 2000 readiness, issued a warning: "The Y2k-related email message that claims to come from Microsoft is a hoax. Consumers should not open the attachment but rather delete it immediately." ®

Providing a secure and efficient Helpdesk

More from The Register

next story
Scrapping the Human Rights Act: What about privacy and freedom of expression?
Justice minister's attack to destroy ability to challenge state
WHY did Sunday Mirror stoop to slurping selfies for smut sting?
Tabloid splashes, MP resigns - but there's a BIG copyright issue here
Google hits back at 'Dear Rupert' over search dominance claims
Choc Factory sniffs: 'We're not pirate-lovers - also, you publish The Sun'
EU to accuse Ireland of giving Apple an overly peachy tax deal – report
Probe expected to say single-digit rate was unlawful
Inequality increasing? BOLLOCKS! You heard me: 'Screw the 1%'
There's morality and then there's economics ...
Hey Brit taxpayers. You just spent £4m on Central London ‘innovation playground’
Catapult me a Mojito, I feel an Digital Innovation coming on
While you queued for an iPhone 6, Apple's Cook sold shares worth $35m
Right before the stock took a 3.8% dive amid bent and broken mobe drama
EU probes Google’s Android omerta again: Talk now, or else
Spill those Android secrets, or we’ll fine you
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.