Previous Thread
Next Thread
Print Thread
Rate Thread
#1319 08/22/05 05:19 AM
Joined: Mar 2002
Posts: 1,041
I
UGN Elite Poster
UGN Elite Poster
I Offline
Joined: Mar 2002
Posts: 1,041
Anyone seen this kind of behavior before? I got a contact who keeps spamming me with this:

***WARNING*** Do not run the file that the link points at.

Quote:
((23:26:09) if you swear, you'll catch no fish: LMAO! you've got to see this! http://www.warezddls.com/download.php?type=movies&id=446
It points to a file called 45265.exe and when I scan it with NAV it comes back clean. I seriously doubt that assessment though.

Anyone encountered this? Any idea what I'm looking at here?

Sponsored Links
▼ Sponsored Links ▼ ▲ Sponsored Links ▲
#1320 08/22/05 07:07 AM
Joined: Oct 2003
Posts: 1,449
UGN Elite Poster
UGN Elite Poster
Joined: Oct 2003
Posts: 1,449
i have yet to see that...

#1321 08/22/05 07:29 AM
Joined: Nov 2003
Posts: 478
A
UGN Member
UGN Member
A Offline
Joined: Nov 2003
Posts: 478
I had a mate who had a similar problem on his msn. His msn had been hijacked and a virus was sending similar msg's to his contacts telling them to download a file (virus). He said he didnt know it was doing it until people started complaining he was sending them virus's.
I did a google searcg for the exe and didnt find anything at all.


#1322 08/22/05 07:34 AM
Joined: Mar 2002
Posts: 1,041
I
UGN Elite Poster
UGN Elite Poster
I Offline
Joined: Mar 2002
Posts: 1,041
Yeh, I did the same search. After it turned back nothign I started asking wink

After searching for the last hour it looks like this one is brand new. Found some references that are identical to what I saw, but nothing much older than 24 hours.

So there you go people. You heard it here first. New MSn virus out there. Keep your eyes open.

This UGN Security Advisory brought to you by the folks at UGN Security laugh

#1323 08/22/05 01:08 PM
Joined: Dec 2002
Posts: 3,255
Likes: 3
UGN Elite
UGN Elite
Joined: Dec 2002
Posts: 3,255
Likes: 3
I do not use MSmsger because I try to minimize the microsoft products I need to use. If you ask me you are asking for it using messenger.

#1324 08/22/05 03:03 PM
Joined: Oct 2003
Posts: 1,449
UGN Elite Poster
UGN Elite Poster
Joined: Oct 2003
Posts: 1,449
i have 2 friends who ONLY use MSN, so if i never want to hear from them then i have to use it which sucks cause MSN doesnt seem to like my web cam so those 2 friends dont get to see the baby live...

#1325 08/23/05 02:15 PM
Joined: Nov 2003
Posts: 478
A
UGN Member
UGN Member
A Offline
Joined: Nov 2003
Posts: 478
I only have msn but am thinking of downloading trinity cause some of my friends do have AOL.

Still no info on the virus?


#1326 08/24/05 02:52 AM
Joined: Nov 2003
Posts: 478
A
UGN Member
UGN Member
A Offline
Joined: Nov 2003
Posts: 478
Note: I just realised that I said trinity, it should read trillian.


#1327 08/24/05 03:36 AM
Joined: Jun 2005
Posts: 4
J
J-k Offline
Junior Member
Junior Member
J Offline
Joined: Jun 2005
Posts: 4
Ive heard from a friend that its not hard to delete...

#1328 08/24/05 05:17 AM
Joined: Jun 2005
Posts: 4
S
Junior Member
Junior Member
S Offline
Joined: Jun 2005
Posts: 4
I helped a friend clean that from his system. I'm not a whiz at computers, but I do know more than the novice would know, any novice would be caught by this, but the more experienced among us will be able to clean this out with no trouble.

The computer that tried to infect me, and some friends over msn, is known to go by the name "Afroman" e-mail: [email protected]

If someone like that adds you, delete and block.

#1329 08/25/05 07:14 AM
Joined: Mar 2002
Posts: 1,041
I
UGN Elite Poster
UGN Elite Poster
I Offline
Joined: Mar 2002
Posts: 1,041
Quote:
Originally posted by �int��:
I do not use MSmsger because I try to minimize the microsoft products I need to use. If you ask me you are asking for it using messenger.
You know you're talking to the guy who DOES NOT have windows installed on anything he owns right? Linux/Gaim over here :p I'm just looking out for those less fortunate than me who actually use the real MSN client wink

Incedently, I've seen a few news reports and advisories on this now. How about that folks; UGN was prolly the first on the net to issue an advisory on this badboy. Yay us!!! :p

EDIT:

WOOHOO!!! This post is on the FIRST page of results when searching for the name of the file:

http://www.google.com/search?q=45265.exe&start=....mozilla:en-US:unofficial

The other day when I posted this it came back with no results.

I says goddamn!

Second Edit:

kk, looks like this might be our boy:

http://securityresponse.symantec.com/avcenter/venc/data/backdoor.tixanbot.html

Says discovered Aug 22 (notice my aug 21 post :p )

I LOVE BEING BETTER AND NORTON! uNF

#1330 08/25/05 06:19 PM
Joined: Feb 2002
Posts: 7,203
Likes: 11
Community Owner
Community Owner
Joined: Feb 2002
Posts: 7,203
Likes: 11
I dub this "w32.l33terthanyuo.worm" :nod:


Donate to UGN Security here.
UGN Security, Back of the Web, and VNC Web Services Owner

Link Copied to Clipboard
Member Spotlight
None yet
Forum Statistics
Forums41
Topics33,840
Posts68,858
Members2,176
Most Online3,253
Jan 13th, 2020
Latest Postings
Top Posters
UGN Security 41,392
Gremelin 7,203
§intå× 3,255
SilentRage 1,273
Ice 1,146
pergesu 1,136
Infinite 1,041
jonconley 955
Girlie 908
unreal 860
Top Likes Received
Ghost 2
unreal 1
Crime 1
Ice 1
Dartur 1
Powered by UBB.threads™ PHP Forum Software 8.0.0