MSN VIRUS!!!!!!!!!!!!!!!!!
#11
RE: MSN VIRUS!!!!!!!!!!!!!!!!!
ORIGINAL: deej
DO NOT OPEN ANY FILE FROM ANYONE!!!!!!!
DO NOT OPEN ANY FILE FROM ANYONE!!!!!!!
<friend> says: Hey, isn’t this YOU?? :S http://mainmsn.com/images/viewimage.php?=your@email.com
With "your@email.com" replaced with your msn messenger address (part of the reason why I don't use a valid address for my msn messenger).
Here is the release from some folks on what it is and how it spreads:
Your MSN Contacts May Be Sending You Viruses (mainmsn.com)
Posted on January 23, 2008 - Filed Under Uncategorized |
If you receive this instant message through MSN, DO NOT CLICK IT:
<friend> says: Hey, isn’t this YOU?? :S http://mainmsn.com/images/viewimage.php?=your@email.com
Clicking this message downloads a virus onto your computer (except that the link above goes to VirusTotal’s results for the file). This virus appears to take control of MSN and send the same message to everyone on your friends list. However, it may do other virus-like things on your system. I’m not running Windows so I can’t see the full effects, but the person who sent it to me is now contemplating a full reformat of their hard drive to eliminate the infection.
Who is mainmsn.com? There’s scant information on the internet. The downloaded file name is PIC006.JPG-www.photoshare.com. Besides program code, the file contains a section of HTML code that appears to display a hardcoded error message: “Warning: fopen(cnt) [function.fopen]: failed to open stream: Permission denied in /home/a7095595/public_html/images/viewimage.php on line 9″
What does the virus actually do? Among other things, the payload seems to contain a variation of the IRCBot worm, which causes your computer to monitor a remote IRC channel for commands from a hacker. Depending on the commands given, this could have dire consequences.
How does the infection happen? It must be executed after being downloaded. It will then propagate itself to other people in your friends lists.
Here’s an object lesson in security: trusted sources are the most dangerous attack vectors. This virus - in the grand tradition of the ILOVEYOU virus - relies on personal relationships and trust to make people perform a typically dangerous action unawares. Keep your shields up and beware random messages!
---
Essentially - avoid anything with mainmsn in the link name... all their A records have been purged from worldwide DNS as of last night - so once it propagates - everyone should be safe, at least from this incarnation.
#13
RE: MSN VIRUS!!!!!!!!!!!!!!!!!
ORIGINAL: markmeinteil
F'ing Microsoft!
F'ing Microsoft!
#15
RE: MSN VIRUS!!!!!!!!!!!!!!!!!
Again - it is not an attachment... it is a link to an executable, which disguises itself as a jpg. As MSN doesn't show the hidden source code underneath what is presented, it is easy for people to mistake it as a genuine jpg and just click on it. Then it tries to download a file, which 90% of the computer users have set to "allow" because they don't know any better, and 9% of the remaining think it is a file for showing the picture....
As it is also coming from someone you know and trust and have likely accepted jpg's from them before - most people assume that this one is safe too.
As it is also coming from someone you know and trust and have likely accepted jpg's from them before - most people assume that this one is safe too.
#17
RE: MSN VIRUS!!!!!!!!!!!!!!!!!
Look for the Song Blame it on the Rain. They where made famous with that song until they were discovered to lip sync the whole thing and the album. They tried to put out a nother record with them singing and it totally bombed.
#19
RE: MSN VIRUS!!!!!!!!!!!!!!!!!
ORIGINAL: rocketrotary
Wow, I though Deej was the only one here old enough to remember that! j/k
Wow, I though Deej was the only one here old enough to remember that! j/k