Article ID: 319652 - View products that this article applies to.
This article was previously published under Q319652
This article has been archived. It is offered "as is" and will no longer be updated.
This article discusses the W32.Gibe@mm virus that may affect the operation of your computer. The information in this article is provided as-is without warranty of any kind. Microsoft does not provide software to stop virus infections or to cure infected computers. You may want to contact an antivirus software manufacturer for more information about how to remove a virus from your computer and about how to prevent future infections. If your computer has been infected, it may be open to additional forms of attack. Microsoft recommends that you rebuild infected Internet-facing servers (servers that function without a firewall or other protection) by following the guidelines that are published on the CERT
(http://www.cert.org/)Web site. Microsoft also recommends that you rebuild any other computers that are at risk because of their proximity to infected computers before you place them back in service.
The W32.Gibe@mm virus is a mass-mailing e-mail worm program that uses Microsoft Outlook as well as a built-in Simple Mail Transport Protocol (SMTP) engine to spread.
IMPORTANT: Microsoft does not distribute programs or updates by using e-mail messages.
The W32.Gibe@mm virus affects Outlook, Microsoft Outlook Express, and Web-based e-mail programs. This virus arrives in an e-mail message with the following characteristics:
From: Microsoft Corporation Security Center <firstname.lastname@example.org>In addition, the message contains an attached file that is named q216309.exe. The virus starts when you run this file.
To: Microsoft Customer <'email@example.com'>
Subject: Internet Security Update
This is the latest version of security update, the "7 Mar 2002 Cumulative Patch" update which eliminates all known security vulnerabilities affecting Internet Explorer and MS Outlook/Express as well as six new vulnerabilities, and is discussed in Microsoft Security Bulletin MS02-005. Install now to protect your computer from these vulnerabilities, the most serious of which could allow an attacker to run code on your computer.
Description of several well-know vulnerabilities:
- "Incorrect MIME Header Can Cause IE to Execute E-mail Attachment" vulnerability. If a malicious user sends an affected HTML e-mail or hosts an affected e-mail on a Web site, and a user opens the e-mail or visits the Web site, Internet Explorer automatically runs the executable on the user's computer.
- A vulnerability that could allow an unauthorized user to learn the location of cached content on your computer. This could enable the unauthorized user to launch compiled HTML Help (.chm) files that contain shortcuts to executables, thereby enabling the unauthorized user to run the executables on your computer.
- A new variant of the "Frame Domain Verification" vulnerability could enable a malicious Web site operator to open two browser windows, one in the Web site's domain and the other on your local file system, and to pass information from your computer to the Web site.
- CLSID extension vulnerability. Attachments which end with a CLSID file extension do not show the actual full extension of the file when saved and viewed with Windows Explorer. This allows dangerous file types to look as though they are simple, harmless files - such as JPG or WAV files - that do not need to be blocked.
Versions of Windows no earlier than Windows 95.
This update applies to:
Versions of Internet Explorer no earlier than 4.01
Versions of MS Outlook no earlier than 8.00
Versions of MS Outlook Express no earlier than 4.01
How to install
Run attached file q216309.exe
How to use
You don't need to do anything after installing this item.
For more information about these issues, read Microsoft Security Bulletin MS02-005, or visit link below.
If you have some questions about this article contact us at firstname.lastname@example.org
Thank you for using Microsoft products.
With friendly greetings,
MS Internet Security Center.
Microsoft is registered trademark of Microsoft Corporation.
Windows and Outlook are trademarks of Microsoft Corporation.
Technical DetailsQ216309.exe is a Microsoft Visual Basic program that completes the following operations when you start it:
PreventionOutlook 2002 and Outlook 2000 Service Pack 1 (SP1) include the functionality to block harmful e-mail attachments. By default, these programs are configured to block the opening of this file attachment.
If Outlook 98 and Outlook 2000 are not updated to SP1, they are vulnerable to this virus. However, the opening of harmful e-mail attachments can be blocked by installing the Outlook e-mail security update. For additional information about how to obtain and install this update, please visit the following Microsoft Web site:
RecoveryMicrosoft does not provide software that can detect or remove computer viruses. If you suspect or confirm that your computer is infected with a virus, obtain current antivirus software. For a list of antivirus software manufacturers, click the following article number to see the article in the Microsoft Knowledge Base:
(http://support.microsoft.com/kb/49500/EN-US/ )List of Antivirus Software Vendors
Article ID: 319652 - Last Review: February 27, 2014 - Revision: 4.2
Contact us for more help
Connect with Answer Desk for expert help.