All microsoft updates come through their update utility... you will never recieve a valid email from microsoft urging you to update your computer. My corporation has been a major target of this stuff lately, and my virus filter has caught at least a dozen of those sorts of viruses in the last couple weeks... and there was one that didn't get caught.
A safe option, and one that I personally employ, is to NEVER under ANY circumstances open ANY email attachments without verbal verification from the sender... EVER. I've got a form letter I send back that tells the user to either embed the text directly (in the case of those .eml files some people like to send), or don't bother sending it to me.
|