Browsers - Worm Posing as IE Beta Download - eWeek Security Watch

Worm Posing as IE Beta Download

Written By
Lisa Vaas
Lisa Vaas
Mar 30, 2007
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A widespread malicious attack is posing as a convincing invitation from Microsoft to download a beta version of Internet Explorer 7.0, security company Sophos reported.

The e-mails appear to come from admin@microsoft.com. The subject line is “Internet Explorer 7 Downloads.” The e-mail contains an image inviting users to download Beta 2 of IE 7. Those who click on the image will download a file called ie7.0, which carries the W32Grum-A worm.

“Worms like this are only succeeding in spreading because so many people have still not learned to be suspicious of unsolicited e-mails, even if they claim to come from well-known companies like Microsoft,” said Graham Cluley, senior technology consultant for Sophos, in a posting on Sophos’ site. “The problem is that to the casual observer the e-mail looks genuine, and the image displayed looks near-identical to the imagery that Microsoft is using on its Web site to promote Internet Explorer 7.0. Clicking on the image, however, doesn’t download the real beta – but malicious code straight from the hackers.”

Sophos says that the Grum worm is an appender virus—a virus that inserts a copy of its code at the end of its victim file. This virus infects executable files referenced by Run keys in the Windows Registry. When run, it copies itself to winlogon.exe and makes changes to the Registry. It also edits the HOSTS file, injecting a thread into system.dll, and attempts to patch the system files ntdll.dll and kernel32.dll.

Sophos points out that this isn’t the first time malware has posed as Microsoft communications. One example comes from two years ago, when the Swen—also known as Gibe-F—mass-mailing virus masqueraded as a security patch message from Microsoft.

Sophos is advising companies to automatically update their corporate virus protection.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.