ScoobyNet.com - Subaru Enthusiast Forum

ScoobyNet.com - Subaru Enthusiast Forum (https://www.scoobynet.com/)
-   Non Scooby Related (https://www.scoobynet.com/non-scooby-related-4/)
-   -   SN Users - watch out for an MSN worm (https://www.scoobynet.com/non-scooby-related-4/652640-sn-users-watch-out-for-an-msn-worm.html)

Luminous 08 December 2007 11:17 PM

SN Users - watch out for an MSN worm
 
There is a worm going around some of our members who like to use MSN.

If you get this worm, it will try to pass it on to all other members in your address book. You will be unaware that you machine is sending messages to your friends, pretending to be you.

The text will be random, but will invite you to look at some pictures. I was caught out as the text just happened to be plausible. The file you will receive will be a .zip file.

Inside the zip will be a "picture". It will be called something along the lines of 420.jpg."your hotmail username".com. So its not really a .jpg. Don't run this file. Nasty things happen if you do.

I do not know what the virus is called, no current virus/malware scanner can detect it to my knowledge. I have been analysing a sample of this file for most of the afternoon. I have tried more than 20 AV scanners, and none currently detect the infection. Scanners I have tried include AVG, Norton, McAfee, NOD32 and a whole bunch of spyware/malware scanners.

Mods: I know this is computer related, however there are many members who use MSN but don't look in our computer related area.


If you do get infected, there are means to remove the infection. They are not easy, and there is no way at the current time to know if you have totally removed it. For me, after playing with it, I just rolled back to an image of my machine from y'day.

Each time the virus attempts to send the virus it changes many things. It changes the name of the .zip and the name of the .com. It also changes the names of the registry keys it hides under, and the names of the files it copies onto your machine.

I used a previous registry backup to compare and contrast while examining things (Winpatrol, it detects and informs of changes). First time the virus tried to hide as a print server, second time a video driver, last time a virus scanner. Shame it decided to call itself norton...I kill files like that on sight as a matter of course ;) :lol1:

pimmo2000 08 December 2007 11:27 PM

1 Attachment(s)
:wonder: Warning us all nice and early ... you ******* :lol1:


attached actual message and file ... lucky I dont trust you aint it lol

exvaux 08 December 2007 11:28 PM

its ok i dont have many friends anyway lol but thanks for the heads up

Luminous 08 December 2007 11:30 PM


Originally Posted by pimmo2000 (Post 7470383)
:wonder: Warning us all nice and early ... you ******* :lol1:


attached actual message and file ... lucky I dont trust you aint it lol

I got the warning out before you did :smug: :razz:

pimmo2000 08 December 2007 11:32 PM


Originally Posted by Luminous (Post 7470389)
I got the warning out before you did :smug: :razz:

I mean you didnt get the warning out before you tried to send it to me :lol1::lol1:

I wasn't gonna warn anyone... if you're stupid enough to use NOD LOL

Luminous 08 December 2007 11:33 PM

I'll get you next time :p :D

Turbohot 08 December 2007 11:52 PM


Originally Posted by Luminous (Post 7470367)

If you get this worm, it will try to pass it on to all other members in your address book. You will be unaware that you machine is sending messages to your friends, pretending to be you.

I am one of the infected ones :(

Someone just told me that I sent them my baby cousin's pic (????) and they were trying to open it. I shouted " DON'T!!! I NEVER sent you any baby cousin's pic, and I never asked for your permission to put your pic on Myspace! I don't even visit Myspace FFS!" :brickwall

My apologies to my fistful contacts if they have received any random rabbitting from me on MSN, it was actually dpb :thumb:

LOL only joking, Duncan! :D

This virus needs sorting. Any MSN whizkids here to tell me how to handle it? :confused: I am so close to breaking this fecking laptop! :mad:

Sonic' 09 December 2007 12:02 AM


Originally Posted by Turbohot (Post 7470421)
I am one of the infected ones :(

Someone just told me that I sent them my baby cousin's pic (????) and they were trying to open it. I shouted " DON'T!!! I NEVER sent you any baby cousin's pic, and I never asked for your permission to put your pic on Myspace! I don't even visit Myspace FFS!" :brickwall

My apologies to my fistful contacts if they have received any random rabbitting from me on MSN, it was actually dpb :thumb:

LOL only joking, Duncan! :D

This virus needs sorting. Any MSN whizkids here to tell me how to handle it? :confused: I am so close to breaking this fecking laptop! :mad:

:D

You only asked me twice TH , it hasn't happened since though :thumb:

I have no idea how you can get rid of it though

Luminous 09 December 2007 12:14 AM

I believe the answer for removal is here:
MSN Hijacked by .com file wrapped up inside .zip - Tech Support Guy Forums

However, it is not for the faint of heart :( It will take you a while to work through all of that. Even when you are done, there is no guarantee there is nothing left.

I am hoping someone will analyze the files I sent to get a quick fix for the issue.

Turbohot 09 December 2007 12:18 AM


Originally Posted by Sonic' (Post 7470428)
:D

You only asked me twice TH , it hasn't happened since though :thumb:

I have no idea how you can get rid of it though

A couple of members somehow got some weird files from me yesterday, Steve. :( Bleddy pain in the @rse it is :mad: I have found a PC doctor in my village newsletter. I shall give him a call tomorrow.

Sonic' 09 December 2007 12:25 AM

Oh dear, I dont think I have sent anything out, when I got the messages from you there wasn't any files attached, but I do have MSN setup to virus check any files first

corradoboy 09 December 2007 12:28 AM

When you're next considering a new computer, a little advice.... http://www.graphicdiscount.co.uk/aca...logo-apple.jpg

+Doc+ 09 December 2007 12:38 AM


Originally Posted by corradoboy (Post 7470471)
When you're next considering a new computer, a little advice.... http://www.graphicdiscount.co.uk/aca...logo-apple.jpg

apple smapple

Shark Man 09 December 2007 01:44 AM


Originally Posted by corradoboy (Post 7470471)
When you're next considering a new computer, a little advice.... http://www.graphicdiscount.co.uk/aca...logo-apple.jpg


YouTube - Wild hogs alternative specs :razz:

pimmo2000 09 December 2007 12:04 PM


Originally Posted by Shark Man (Post 7470540)


LMFAO... excellent clip

SwissTony 09 December 2007 12:14 PM

brilliant clip....shame he didnt impress the tasty bird with his PC :lol1: :lol1: :lol1:

SwissTony 09 December 2007 12:14 PM


Originally Posted by corradoboy (Post 7470471)
When you're next considering a new computer, a little advice.... http://www.graphicdiscount.co.uk/aca...logo-apple.jpg

dont tease the natives, they get upset :smug:

Luminous 09 December 2007 12:55 PM

apples only last a week or two before they go rotten :razz:

jjones 09 December 2007 01:19 PM


Originally Posted by corradoboy (Post 7470471)
When you're next considering a new computer, a little advice.... http://www.graphicdiscount.co.uk/aca...logo-apple.jpg

yah because apple don't have problems with trojans :lol::Whatever_

SwissTony 09 December 2007 01:41 PM

:thumb: yes we dont :smug:

anyway back on topic, thanks for the heads up. I wonder how prevalent this is,because I havent seen any information on the virus boards as of yet , symantec dont seem to have it on theirs etc ??

Luminous 09 December 2007 03:09 PM

No idea how popular it is the wild. I just know it was going round a few SN members, or at least had the potential to.

pimmo2000 09 December 2007 03:13 PM

Its an old issue to be fair.. its being making its way around for a while !

MSN Messenger Virus Removal, MSN Virus, Happy-Messaging.com

Fuzz 09 December 2007 03:20 PM

What the fcuk were you thinking when you opened a zip file from an unknown source. lol

pimmo2000 09 December 2007 03:53 PM


Originally Posted by Fuzz (Post 7471296)
What the fcuk were you thinking when you opened a zip file from an unknown source. lol

:iamwithst

It comes from people on you MSN list.. thus.. not unknown

corradoboy 09 December 2007 05:11 PM


Originally Posted by Luminous (Post 7471019)
apples only last a week or two before they go rotten :razz:

8 years with no virus protection whatsoever and still running fine :smug:

It really is so simple I can't understand why MS find protecting you guys so difficult. Any downloaded file is checked by the OS and if it detects an application or installer you are warned and asked if you want to continue. On opening the file, if it contains either you get another warning before you authorise using your admin ID and PW. Any app which utilises key OS protocols requires authorisation on its first activation, after that, if you've still not realised that that JPEG called 'Britney DP Creampie' isn't what it seems then you deserve all the trouble it brings TBH.

Most home users need a web browser, email client, image, music and movie manipulation and convenient storage, and personal contact and diary control. All this ships with every new Mac, and almost every other task the home user could ever need to do is easy and available. If you really need to have an environment exactly like your workplace then fair enough, but in the same vein do you decorate your home to look like your office too ? Why not try something different, you never know, you might like it, being fast, efficient, reliable, productive, easy and pleasing to use, safe, and even stylish. I use both in my work and choose Mac, most whom use other systems don't do so by choice :cuckoo:

BOT - Have fun with your worms :D

Fuzz 09 December 2007 05:41 PM

If iTunes is anything to go by I'll never get a Mac, God awful bit of software.
(having only recently been brought kicking and screaming to it because of my iPod)

Luminous 09 December 2007 05:58 PM


Originally Posted by pimmo2000 (Post 7471282)
Its an old issue to be fair.. its being making its way around for a while !

MSN Messenger Virus Removal, MSN Virus, Happy-Messaging.com

Same principle, but a different bug. We will just have to wait for the files to be analyzed.

As for Apples, when 80%+ don't use them people cannot be bothered to write viruses for them. Just not enough profit to bother with :p

pimmo2000 09 December 2007 06:36 PM


Originally Posted by corradoboy (Post 7471497)
8 years with no virus protection whatsoever and still running fine :smug:

It really is so simple I can't understand why MS find protecting you guys so difficult. Any downloaded file is checked by the OS and if it detects an application or installer you are warned and asked if you want to continue. On opening the file, if it contains either you get another warning before you authorise using your admin ID and PW. Any app which utilises key OS protocols requires authorisation on its first activation, after that, if you've still not realised that that JPEG called 'Britney DP Creampie' isn't what it seems then you deserve all the trouble it brings TBH.

Most home users need a web browser, email client, image, music and movie manipulation and convenient storage, and personal contact and diary control. All this ships with every new Mac, and almost every other task the home user could ever need to do is easy and available. If you really need to have an environment exactly like your workplace then fair enough, but in the same vein do you decorate your home to look like your office too ? Why not try something different, you never know, you might like it, being fast, efficient, reliable, productive, easy and pleasing to use, safe, and even stylish. I use both in my work and choose Mac, most whom use other systems don't do so by choice :cuckoo:

BOT - Have fun with your worms :D


:wonder: I have no protection on my PC... been like this since 98.. never had a single issue.

Oh and I'm sure Vista comes with basically all the stuff you just listed !

hux309 09 December 2007 06:46 PM

Steve jobs himself admitted several years back that the pc won the war.

NotoriousREV 09 December 2007 07:02 PM


Originally Posted by corradoboy (Post 7470471)
When you're next considering a new computer, a little advice.... http://www.graphicdiscount.co.uk/aca...logo-apple.jpg

http://www.babytux.org/gallery/images/tux500.gif


All times are GMT +1. The time now is 04:55 AM.


© 2024 MH Sub I, LLC dba Internet Brands