Hang bao mat Sophos vua dua ra
canh bao voi nhung nguoi su dung thu dien tu ve mot loai virus may tinh moi co
toc do lay lan nhanh voi hinh thuc phat tan kha tinh vi. No duoc nguy trang duoi
dang mot email gui vao hop thu nguoi dung voi noi dung thong bao cung cap mot
ban trinh duyet Internet Explorer 7 tu Microsoft de tai ve.
Theo mot chuyen gia cua hang nay cho biet, nhung thu dien tu do co dia chi nguoi
gui tu admin@microsoft.com va dong tieu de "Internet Explorer 7 Downloads",
trong phan noi dung co hien thi mot buc anh moi goi nguoi su dung tai ve ban
beta 2 cua Internet Explorer 7. Neu nguoi dung nhe da click nham vao do, duong
dan cua thong diep se lap tuc mo duong cho sau W32/Grum-A tan cong cho may tinh
bi nhiem.
"Sau
may tinh nay duong nhu la thanh cong duy nhat boi nhieu nguoi khong may nghi ngo
ve nhung thu dien tu mang tinh tu nguyen, dac biet la khi no tuyen bo la tu mot
cong ty danh tieng gui den. Khong nhung the, no con lam gioi quan sat bat ngo ve
cac su dung nhung hinh anh do hoa het nhu cua Microsoft dung cho quang ba ve
Internet Explorer 7.0 tren website cua ho. Nhan chuot vao do, thay vi tai ve ban
beta do, nhung doan ma nguy hiem theo kich ban cua hacker dot nhap vao he thong
phan mem", nhan xet cua chuyen gia cong Graham Cluley, hang Sophos.
Grum la mot loat sau co kha nang tu gan ghep vao nhung tep tin thi hanh nhu
Windows Registry. Khi da kich hoat, no tu tim den va sao chep mot doan ma vao \winlogon.exe
va tao ra su thay doi trong Registry. No con chinh sua lai nhung tep HOSTS, bo
sung them mot so dong vao system.dll va tim cach ket dinh tiep vao nhung file he
thong khac.
Co van Cluley nhan manh day la mot manh khoe da xuat hien tu lau cua cac hacker
mao danh thong diep cua Microsoft. Lan thu nhat vao nam 2003, sau Gibe-F hay con
co ten goi khac la Swen da cai trang ban sua loi khan cap cua Microsoft, va nam
2005 cac hacker da dieu khien nguoi su dung may tinh truy cap vao mot trang web
gia dang cung cap dich vu nang cap cua hang nay.
Theo InformationWeek, VTC
Article source http://w4rum.com/1155.t
|