This post originated from an RSS feed registered with .NET Buzz
by Anand M.
Original Post: Another Worm is out there...
Feed Title: .NET From India
Feed URL: http://www.dotnetindia.com/index.rss
Feed Description: Your daily dose of .NET From India
Just got an alert on a new Worm making the rounds..
Below is a "low" risk worm alert for "Wallon".
Microsoft is aware of reports of a new mass mailer worm named Wallon that attempts to entice users into visiting a spoofed web site. If visited, a malicious Windows Media Player file, "wmplayer.exe" is downloaded into the user's machine which overwrites a user's existing Windows Media Player file. The PC becomes infected and the malicious Windows Media Player executable file is immediately launched. This allows the worm to then send itself to all contacts in a computer's address book. Customers running Windows Media Player 7.1, Windows Media Player for XP and Windows Media Player 9 Series on any version of Windows that have not installed MS04-013 are impacted by Wallon if they have received the email and visited the malicious website which appears to users as www.security-warning.biz.
This worm exploits the vulnerability fixed in Microsoft Security Update MS04-013 on April 13, 2004.
Customers who have applied MS04-013 are protected from infection by Wallon. The MS04-013 security update is available at www.microsoft.com/technet/security/bulletin/ms04-013.mspx or through Windows Update.