Processo de modernização
Circula pela Internet um falso remédio para o Nimda, praga virtual que já infectou milhões de computadores em todo o mundo. Ele chega por e-mail e utiliza os nomes de empresas de segurança de dados como SecurityFocus e Trend Micro para dar credibilidade à mentira. Ao clicar no arquivo anexado Fix_Nimda.exe (mesmo nome utilizado pela ferramenta autentica da Trend Micro para acabar com o Nimda), o usuário estará, na verdade, instalando um programa que parece ser um cavalo de Tróia. No momento, as empresas investigam o arquivo para saber o que ele faz.
As companhias aconselham o internauta a não executar o arquivo e ressaltam que não faz parte de sua política enviar mensagens eletrônicas com executáveis em anexo. "A não ser que um cliente solicite um programa específico", afirma o comunicado publicado no site da Trend Micro.
Veja o texto do e-mail abaixo:
Hello,
This mail is from the ARIS Analyzer Service (Attack Registry and = Intelligence=20 Service) from SecurityFocus in cooperation with Trend Micro = Incorporated. =20
As you are probably aware from the media, the Nimda worm started = spreading. It has come to our attention that your system(s), listed below have been identified as being compromised by the Nimda = Worm. =20
The Nimda Worm is rapidly spreading across the Internet.=20
The addresses identified as belonging to you are as follows:
Teraton@sbline.net=20
Teraton@bulinfo.net ktzenov@hotmail.com
You can find up to date information on the Nimda Worm at:
http://aris.securityfocus.com
It is very important that you are checking your Systems that have used = with the identified addresses with the special Anti Nimda Software that we send you with this mail. = (FIX_NIMDA.EXE) <
It is also important that you are updating all your systems. For this please show at the following URL
http://www.microsoft.com/technet/security/bulletin/MS01-020.asp1-26.html
The SecurityFocus ARIS Analyst Team
aris-report@securityfocus.com
As companhias aconselham o internauta a não executar o arquivo e ressaltam que não faz parte de sua política enviar mensagens eletrônicas com executáveis em anexo. "A não ser que um cliente solicite um programa específico", afirma o comunicado publicado no site da Trend Micro.
Veja o texto do e-mail abaixo:
Hello,
This mail is from the ARIS Analyzer Service (Attack Registry and = Intelligence=20 Service) from SecurityFocus in cooperation with Trend Micro = Incorporated. =20
As you are probably aware from the media, the Nimda worm started = spreading. It has come to our attention that your system(s), listed below have been identified as being compromised by the Nimda = Worm. =20
The Nimda Worm is rapidly spreading across the Internet.=20
The addresses identified as belonging to you are as follows:
Teraton@sbline.net=20
Teraton@bulinfo.net ktzenov@hotmail.com
You can find up to date information on the Nimda Worm at:
http://aris.securityfocus.com
It is very important that you are checking your Systems that have used = with the identified addresses with the special Anti Nimda Software that we send you with this mail. = (FIX_NIMDA.EXE) <
It is also important that you are updating all your systems. For this please show at the following URL
http://www.microsoft.com/technet/security/bulletin/MS01-020.asp1-26.html
The SecurityFocus ARIS Analyst Team
aris-report@securityfocus.com