FYI…from the Internet Storm Center:

…FAKE redirect…
- http://isc.sans.org/diary.html?date=2004-03-16
"Erik van Straten reported receiving a spoofed email that led to a spoofed Microsoft site that downloaded a trojan with instructions to run it to patch your system. The site name www.microsoft-security-updates.com is NOT a Microsoft site. This gets redirected to (a website which is) identified by Symantec/Norton AntiVirus beta definitions as "Trojan.Etsur".

Repeat after me: "Unless you subscribe to their email security notification service, Microsoft policy is not to send notification of vulnerabilities". They never send patches in email to users…"

.