New MSN Messenger Virus/Trojan – March 2009

For the last couple of days a friend has been bringing their laptop over to my place for me to try and clean this darn msn virus/trojan, which seems to be one tough SOB because everything i have tried hasnt worked. The laptop (Windows XP SP3) has AVIRA AntiVir for antivirus and i have installed and scanned the pc with every single anti-spyware/anti-malware software out there, which includes Ad-Aware, Spyware Terminator, Super Antispyware, Malwarebytes’ Anti-Malware, Rootkit Revealer, and Spybot – Search & Destroy which i chose from Download.com’s top 20 list and from Filehippo’s Anti-Spyware category . Unfortunately none of these great removal software was able to find or remove it.

Well this new MSN virus/trojan posts messages to your contacts like the ones found below.

YOU ARE ON THE FRONTPAGE OF THIS WEBSITE!! http://www.gallery-pictures.com
NO FUCKING WAY!! LOL WHAT HAVE YOU BEEN UP TO?! http://solox99.photodropperz.com
how is this possible?! i just found u through my profile (?!?!?) http://sarfar.gallery-pix.com/

PICS FOR MSN FRIENDS v2_0cWhat the virus/trojan does is send links to what seem to be an MSN login page asking you for your email and password for the purpose of “spread the word about this new 100% real and upcoming Messenger Community Site” which is stated in there terms of use at the bottom of the page. The links sometime have the infected user’s msn username in the subdomain (ex. http://username.gallery-pix.com) and will always look like the image to the right with the heading “PICS FOR MSN FRIENDS v2.0c” or “Pics & Photos 4Frenz v.2.5″.

Alternatively, the messages will link to a sex dating signup webpage with the title “Meet Real Sex Partners TONIGHT – JOIN FOR FREE! — Swingers, Free Adult Chat & Adult Personals Site” which are found at the http://www.fastxxxnow.com/new4/ and http://www.fastxxxnow.com/new5/.

Google Help
After some checking on google, it picked up some of the post messages from what seems to be a group board at this chinese website http://www.365groups.com/

After doing some more digging in google i found a discussion on a dog bulletin board about it.
http://www.labradorforums.co.uk/ftopic-57428-days0-orderasc-0.html
The infected person stated that they formatted the pc and it still didnt solve the problem as the virus/spyware seems to have attached itself to MSN.

Removal Attempts
So after all the scanning with anti-virus/spyware/malware, i decided to remove MSN messenger and all its dependances and installed them again. Didnt help. I tried the various MSN removing softwares like MSN Virus Removal, MSN Virus Cleaner, and IMP Fix suggested in the dog bulletin board with not luck.

Infected Domains
Below is a list of domains which have the same MSN login page.
http://www.areyou-onthisphoto.com/
http://www.dontstayin-pics.com/
http://www.flicker-photoz.com/
http://www.flicker-pics.com/
http://www.galleri-support.com/
http://www.galleryshotz.com/
http://www.greaterpics.com/

Infection Behaviour
My friend told me that when she was infected that MSN Messenger would continously disconnect and reconnect and it seems within the time it was disconnection and reconnecting that the virus/trojan would send these messages to her contacts. That is what she told me but i have no way to verify it, but one thing to keep in mind is whether the virus/trojan is sending the messages to your contacts when you are online or not, and you can know this by the date and time stamp MSN Messenger attaches to each chat post.

Update – Finally Removed
Well what i noticed when i signed into my own MSN Messenger (Windows Live Messenger) account from my friend’s infected pc, that it wasnt sending out the same type of messages to my contacts, which lead me to believe that the account itself is infected and not the pc. So i did some more digging around and was able to finally remove the darn thing by doing the following (not sure what part of this did the trick though). I ran Rootkit Revealer and noticed it brought up MSN Messenger results in the

C:\Documents and Settings\user account\Local Settings\Application Data\Microsoft\Messenger\email@host.com folder

(of course “user account” and “email@host.com” will differ for you on your pc), which you wont be able to reach to in window explorer unless you have hidden files and folders showing [instructions how to do this]. So in that folder i simply deleted all the files and folder. Then i noticed that MSN Virus Removal suggested the changing of my password, so i did that. It must be one of these two that did it but i believe the changing of the password would have done it, but i wont know for certain unless she gets infected again. :) Hope this helps someone out there and if so, drop me a comment below.

2nd Update
Would like to thank everyone who commented and was happy to hear from all those who were helped by this post as i never dreamt that it would be so popular. Well most people said the changing of the password worked, so do try that first before the removal of the files from the computer. I came across a good blog on how to remove some other windows live messenger viruses, so i case you werent able to find a solution with what i have given here, do check out this post.

http://www.mydigitallife.info/2009/06/10/clean-and-remove-windows-live-msn-messenger-virus-removal-tools-or-msn-fix/.

Sphere: Related Content

Comments March 18th, 2009

Get AVG 7.5 Professional AntiVirus for FREE

avgantivirus Ofcourse we all know that AVG provides a full featured AntiVirus suite for free, but they also have a pro version where there is a broader scanning options and scheduling scans more than once a day, and many other features.

Computeractive is giving away free licensed copies, AVG 7.5 Professional is usually sold for $29.95, now you can get it for free until the 18th of January 2008.

But it seems that it is difficult to get the Computeractive download link to work, but CyberNet have provided 2 mirror links, one hosted on Rapidshare and the other on Megaupload, the program is supposed to automatically provide you the serial while the installation.

For residents of the UAE I recommend using the Megaupload link, Rapidshare just does not work well in the UAE.

[Via CyberNet]

Sphere: Related Content

Comments December 27th, 2007

Firefox 3 Beta 1 is out.. Whats good and whats not?

Don’t even think of replacing your current Firfox with this, no, just give it time this is still Beta. I downloaded it yesterday and I didn’t want to quickly write any post just saying its out, i wanted to have a look at it first. Make sure its a real Beta. This is a real Beta release. Thank God.

Although you will hear praises all over the net of how great this version is, but still some things don’t change, yes you guessed it, MEMORY usage. Its still not fully dealt with, of-course I already told you before of an add-on for Firefox 3 that helps with this problem, but i was wishing that maybe the issue would be resolved directly by Mozilla. After using this beta for couple of hours Firefox ended up eating 825,636k of my memory (as shown in the pic below) . So the issue is still there. Am not saying that there was no improvements at all, of-course there are several enhancements. (Continue reading after the jump)

Firefox now uses the Gecko rendering engine, which makes things smoother, but not as smooth as we want yet!. In addition of security features that alerts you while visiting insecure websites and allows you to automatically virus scan your downloads with your Anti-Virus scanner (as shown in the pic below).


I am sure tho, the most beloved new feature by web surfers would be the “PLACES” feature, where it makes it easier to find websites you have visited recently or more often or even starred them for later browsing.

Download it and give it a try…

 

Sphere: Related Content

Comments November 21st, 2007

The Perfect Storm in Cyberspace… The “Storm Worm”

Nobody is talking about it, I never heard about anything like this until now. I am talking about the “Storm Worm”. We all know worms, Sasser is a famous example, but these worms we know are simple and easily noticeable, simply because they were fastly spread.

Apparently this worm appeared in January and is spreading steadily since then, this worm affects machines that run windows, which means around 90% of the machines used in the world. It first appeared hidden in email attachments with the subject “230 dead as storm batters Europe”. The infected machines became part of a BotNet, no one knows how big is this BotNet but professionals estimate that it might be between a million and 50 million computers worldwide by now.

Yes, it is pretty scary, because until now this person or organization is not using this BotNet heavily or for anything big, which means they are waiting for the right time, maybe the right price who knows?!

To get the full picture and read dull details , please read this article written by John Naughton in “The Observer”.

http://observer.guardian.co.uk/business/story/0,,2195730,00.html

Sphere: Related Content

Comments October 22nd, 2007


Enter your email address:

Delivered by FeedBurner


Lijit Search

Lijit Search

Categories

Calendar

March 2010
S M T W T F S
« Nov    
 123456
78910111213
14151617181920
21222324252627
28293031  

Recent Posts

Recent Comments

Archives

Tags



Search for Jobs in Dubai, UAE Search for Properties in Dubai