Fake patch. Fake worm removal. It's a Storm Worm malware (not all malware scanner can detect it)
ISC is alerting users on e-mails that attempt recipients to download an patch.exe and of course, users MUST not click on them to avoid being infected by "Storm Worm".
I personally received 3 today (click to enlarge) :
Most antivirus should detect in case a user mistakenly clicks. To test my resident AV:
Still, don't click on links in your email to download a patch that is not a patch or malware removal tool. Always download any patch via vendors website e.g. Security Updates for Microsoft products should be taken from Windows Update website.
See article by ISC at http://isc.sans.org/diary.html?storyid=3117 and they also linked to AustCERT alert on the above http://www.auscert.org.au/render.html?it=7813
Edit/Update: There's another 1 few minutes ago:
Too bad, not all AV can detect the malware on it so EVERYONE MUST NOT simply download... really:
http://www.virustotal.com/vt/en/resultadof?9fda95540945d9e4b6b5f4bc9101e591
See also discussion at Calendar of Updates
2nd Edit/Update: Another one arrived today and what is interesting is this new patch.exe very small in size.. compare to above:
When I test my resident AV, it again detected the file as infected:
But hhhmmm VirusTotal shows that Symantec do NOT detect it? Impossible because as you can see with the above screenshot, Norton detected it:
http://www.virustotal.com/vt/en/resultadof?7d0fd63437c86796b24d476c844e0973
Anyway, it seems not all variants of storm worm is detected by all scanners *unless* the Virustotal scan engines has problem in scanning uploaded files.