極楽せきゅあブログ

ときどきセキュリティ

Security Update for OS Microsoft Windowsというウイルス付メール来た

最近流行ってるもんなあ>ウイルスメール

ヘッダ:
Return-Path:
Received: (qmail 5801 invoked from network);
13 Oct 2008 17:48:41 +0900
Received: from unknown (HELO pepsis-66ea76d6.dokeda.lt) (88.222.98.102)
by ほげほげ
with SMTP;
13 Oct 2008 17:48:41 +0900
Received: from [88.222.98.102]
by mx3.hotmail.com;
Mon, 13 Oct 2008 10:49:07 +0200
Message-ID: <01c92d21$50d3d380$6662de58@C677BG>
From: "Microsoft Software"
To: <ふがふが>
Subject: Security Update for OS Microsoft Windows
Date: Mon, 13 Oct 2008 10:49:07 +0200
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_NextPart_000_0006_01C92D21.50D3D380"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.00.2919.6700
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6700
X-Text-Classification: work
件名:Security Update for OS Microsoft Windows
本文:
Dear Microsoft Customer,

Please notice that Microsoft company has recently issued a Security Update for OS Microsoft Windows. The update applies to the following OS versions: Microsoft Windows 98, Microsoft Windows 2000, Microsoft Windows Millenium, Microsoft Windows XP, Microsoft Windows Vista.

Please notice, that present update applies to high-priority updates category. In order to help protect your computer against security threats and performance problems, we strongly recommend you to install this update.

Since public distribution of this Update through the official website http://www.microsoft.com would have result in efficient creation of a malicious software, we made a decision to issue an experimental private version of an update for all Microsoft Windows OS users.

As your computer is set to receive notifications when new updates are available, you have received this notice.

In order to start the update, please follow the step-by-step instruction:
1. Run the file, that you have received along with this message.
2. Carefully follow all the instructions you see on the screen.

If nothing changes after you have run the file, probably in the settings of your OS you have an indication to run all the updates at a background routine. In that case, at this point the upgrade of your OS will be finished.

We apologize for any inconvenience this back order may be causing you.


Thank you,

Steve Lipner
Director of Security Assurance
Microsoft Corp.

          • BEGIN PGP SIGNATURE-----

Version: PGP 7.1

F4DO3O8T00FIKLA7YR77NKH1SMGYS001JXVYBP2BLMN00FV9MNKYD6X0195HSEI5Q
PP7V9M1AW6J8962K19BGA0WGB173ZN50SUNU25TIAFM3WW6PPRX5HXC3FFJ97AVH6
TBYML8XM3QYD4RWRQ4BIVAA26IKQA4ATNAC8HN4S528BB1XXUL18O1K8B82CHJ3X5
6G69PLYR7X5C3UB5KLL7GOIIP89WLBE2629KC2U9VKDP7985T9EVF9POKVI55PO1E
0ONR8RLKVD8ZEPL663Y36LA9GZ8W0LKEDMT==

          • END PGP SIGNATURE-----

添付されていたファイルの名前はKB601922.exe。
VirusTotalでの分析結果はhttp://www.virustotal.com/jp/analisis/4221d433844d2e16118ffd45db93f57e