Virus Busters Home


The W32/Gibe@MM Virus Masquerades as Email From Microsoft

by Bruce P. Burrell (bpb@umich.edu)
for the U-M Virus Busters (virus.busters@umich.edu)
Last significant update: 14 March, 2002

This information can be freely reproduced in any medium, as long as the information is unmodified.

The W32/Gibe@MM virus attempts to spread by fooling its recipient into thinking that it is email from Microsoft. It purports to contain a "security update patch" in a file named q216309.exe. Of course, if the reader is careless enough to open the attachment, the virus will attempt to infect, and then send itself out to others from the new victim's computer.

If you have reason to think that you may have been infected by W32/Gibe@MM and you are a U-M member, contact us for assistance. If you may be infected but are not a U-M member, contact your internal support, or contact your antivirus vendor for assistance.

Here is the beginning of the text sent by the virus:

      From: "Microsoft Corporation Security Center" <rdquest12@microsoft.com>
      To: "Microsoft Customer" <'customer@yourdomain.com'>
      Subject: Internet Security Update
      Reply-To: <rdquest12@microsoft.com>
      Date: [whatever -BPB]

      Microsoft Customer,

            this is the latest version of security update, the
      known security vulnerabilities affecting Internet Explorer and
      MS Outlook/Express as well as six new vulnerabilities, and is
      discussed in Microsoft Security Bulletin MS02-005. Install now to
      protect your computer from these vulnerabilities, the most serious
      of which could allow an attacker to run code on your computer.

etc.

We have seen several cases where this message was not spread by the virus; instead, it was sent by well-meaning but misguided individuals, trying to be Good Samaritans. Please do not forward this -- or any other virus warning or hoax -- to all your friends.

Instead, you should

For this particular case, I suggest that you provide a pointer to this URL (http://www.umich.edu/~virus-busters/gibe.html)
For virus or hoax info, please see our main page (http://www.umich.edu/~virus-busters/) or go to another reputable site, like The Urban Legends Reference Pages (leaving our site).

   -BPB

Virus Busters Home


Last updated: Monday, 18-Mar-2002 11:54:16 EST.
University of Michigan Virus Busters - virus.busters@umich.edu

visits to this page since 14 March, 2002 17:30 EST