PDA

View Full Version : MSN Messenger Trojan Worm! Not related to Team17 at all.


yauhui
15 Nov 2007, 12:04
Sometimes we get a message from our contacts that says weird stuff like "Have you seen me naked?" or something like that, followed by a ZIP file, e.g. Images.zip or something like that. Ever accepted that file? Regret.

You may be sending out THAT file without knowing it yourself. Lucky for me, I have Kaspersky (and only Kaspersky can detect that trojan worm)

Here's how to remove the trojan: http://www.messenger-trojan.tk/

MrBunsy
15 Nov 2007, 15:20
Prevention is better than the cure. Never accept anything you don't trust, and never, ever, run anything you've been sent unless you both agreed to send it and have both virus scanned it.

It's quite easy, really.

yakuza
15 Nov 2007, 15:29
And remember kids, do not download HALO3_FULL_GAME_FREE.EXE if it's only 2MB.

Kelster23
15 Nov 2007, 16:29
You know the one about myspace photo?
There's two ways right off to tell:
1) The file is a zip. Photos are not zip files.
2) Right on the file it's spelled 'fotos' or something like that.

Tiny ulitmate give-away details.

MtlAngelus
15 Nov 2007, 17:00
I have an awesome antivirus that keeps me away from this type of virus. It's called Common Sense™. :cool:

_Kilburn
15 Nov 2007, 18:49
I have an awesome antivirus that keeps me away from this type of virus. It's called Common Sense™. :cool:

Cool, where can I get it ? :cool:

thomasp
15 Nov 2007, 18:56
I have an awesome antivirus that keeps me away from this type of virus. It's called Common Sense™. :cool:
And while we're on the subject of Common Sense:

Mac users who like to use certain pornographic websites get asked to download an update (well, codec) to quicktime so as they can watch their movies. This is actually a virus/trojan, but requires the user to input their admin password in order to install said "codec".

Melon
15 Nov 2007, 18:57
Cool, where can I get it ? :cool:

Here . (http://forum.team17.co.uk/member.php?u=77459)

Cyclaws
15 Nov 2007, 18:59
Mac users who like to use certain pornographic websites

I know all about those :cool:

MtlAngelus
15 Nov 2007, 19:32
Here . (http://forum.team17.co.uk/member.php?u=77459)
AHAHAHAAA BUUURRRN! :D

I'm sorry, not trying to troll this thread or anything, but this had to be posted for the sake of humanity.

And thomasp: I wonder how you found that out... ;) :p

*runs*

Diablo vt
15 Nov 2007, 21:30
I accepted a "myspace" photo a couple of days ago but suddenly realized that something was wrong. So I canceled it before it finished sending.

Run
15 Nov 2007, 21:37
I accepted a "myspace" photo a couple of days ago but suddenly realized that something was wrong.

that you were on myspace?

Xinos
15 Nov 2007, 22:51
And remember kids, do not download HALO3_FULL_GAME_FREE.EXE if it's only 2MB.

So.. it's okay if it's 3GB?

Diablo vt
17 Nov 2007, 01:03
that you were on myspace?

No! I was on msn and when it asks you if you want to accept a file or not, that freaking file came up but i canceled it.

poninja
17 Nov 2007, 02:35
my friend has a trojan and everytime it post it sound like this '' el lol mi hermana por fartyb ah5 este archivo de photos :p'' also here's is the truth http://i121.photobucket.com/albums/o228/zecasnor/Lollol.png

yauhui
17 Nov 2007, 07:24
No! I was on msn

no, run meant that the worm message said that your pic was on myspace.

Run
17 Nov 2007, 09:32
quick, everyone argue about what i meant

quakerworm
19 Nov 2007, 10:05
oh, great. now they are going to argue over whether you are being sarcastic or not.

yauhui
19 Nov 2007, 10:25
quick, everyone argue about what i meant

i already mentioned what you meant, so just keep quiet unless you have something else to say.

Run
19 Nov 2007, 16:06
so just keep quiet unless you have something else to say.

you say that as though there's some sort of magical third option

FutureWorm
19 Nov 2007, 19:42
you say that as though there's some sort of magical third option
you could just stand by and hum i guess

Kelster23
19 Nov 2007, 21:57
And remember kids, do not download HALO3_FULL_GAME_FREE.EXE if it's only 2MB.

Halo 3 isn't even out for computer yet anyway, is it?

MrBunsy
19 Nov 2007, 22:00
Anyone thick enough to download something like that wouldn't know that.

And Halo 1 is still too damned expensive for PC as well. £15 for an old game and first in a trilogy! Ruddy MS.

yakuza
19 Nov 2007, 22:16
Halo 3 isn't even out for computer yet anyway, is it?

That's one of the reasons you shouldn't download the file.

FutureWorm
19 Nov 2007, 22:32
Anyone thick enough to download something like that wouldn't know that.

And Halo 1 is still too damned expensive for PC as well. £15 for an old game and first in a trilogy! Ruddy MS.
that's why no real pc gamers play halo

tal05
19 Nov 2007, 22:36
Halo 3 isn't even out for computer yet anyway, is it?

nope
...

and there aint gonna be :)

hence the "only for xbox 360" sign on the Halo 3 case :rolleyes:

or some message like that

Plasma
19 Nov 2007, 22:54
And Halo 1 is still too damned expensive for PC as well. £15 for an old game and first in a trilogy!
In all fairness, Halo1 was an utterly, utterly brilliant game for it's time!
Halo 2 and 3 I'm less satisfied about, because they didn't add any more unique feature to the series, which was what made Halo1 so brilliant, they only perfected the older ones instead.

MonkeyforaHead
20 Nov 2007, 00:58
The only MSN-transmuted virus that ever came close to tricking me was one that spread as a pretty innocent-looking Photobucket link or something, which somehow pretends to send itself from a random person on your contacts list, even if they're not infected. I don't know where it came from or how, but I'm glad it gave up after trying to get me three times.

Cyclaws
20 Nov 2007, 01:04
nope
...

and there aint gonna be :)

hence the "only for xbox 360" sign on the Halo 3 case :rolleyes:

or some message like that

Right, and we can ignore the fact that it said "Only for Xbox" on the previous two, can we?

MrBunsy
20 Nov 2007, 08:39
And on Gears of War.

In all fairness, Halo1 was an utterly, utterly brilliant game for it's time!Yeah, but I can get most of the Unreal series for less money :p

tal05
20 Nov 2007, 14:18
Right, and we can ignore the fact that it said "Only for Xbox" on the previous two, can we?

sure :eek:
________

yauhui
20 Nov 2007, 14:24
hmm.. what has MSN Messenger Trojan Worm got to do with Only For Xbox? this topic is straying...

tal05
20 Nov 2007, 14:46
hmm.. what has MSN Messenger Trojan Worm got to do with Only For Xbox? this topic is straying...

trojan worm in this case = halo3.zip

:rolleyes:

robowurmz
21 Nov 2007, 21:46
The message I give out to all people is; if it's a file from somewhere you don't know about, don't download it. It's quite simple, and it's a common feature in Common Sense™

thomasp
21 Nov 2007, 22:55
I have just deleted 47 spam and off-topic posts from this thread (leaving 34 intact...). The next time that kind of thing happens, Being Watched and Banned statuses will be issued accordingly.

Do not spam in this forum. Simple.


And any replies to this post will be spam and therefore infracted heavily.

franpa
26 Nov 2007, 14:11
Sometimes we get a message from our contacts that says weird stuff like "Have you seen me naked?" or something like that, followed by a ZIP file, e.g. Images.zip or something like that. Ever accepted that file? Regret.

You may be sending out THAT file without knowing it yourself. Lucky for me, I have Kaspersky (and only Kaspersky can detect that trojan worm)

Here's how to remove the trojan: http://www.messenger-trojan.tk/
theres a similar virus on msn messenger the file extension is .com and the name of the file is your email. so for me it would be franpa_999.com.

Kelster23
26 Nov 2007, 21:31
I think I found another one yesterday. I got it twice within the same hour from the same person.
The message reads:
HAHA look at this guy's shirt!

Or something like that. Same book-looking filetype though.
Just a heads up.

yauhui
27 Nov 2007, 07:17
book-looking filetype

Files which look like three books, red, blue and green, strapped together with a brown belt are ZIP/RAR files, if you have WinRAR installed (i think.)

MrBunsy
27 Nov 2007, 09:04
Never rely on the icon to tell what a file is, turn file-endings on, that way you can never be caught out. It's rather easy to give an executable any icon you like.

Melon
27 Nov 2007, 12:36
Or, even better, don't use that crappy My Computer and get a real file manager program.

quakerworm
27 Nov 2007, 14:20
Never rely on the icon to tell what a file is, turn file-endings on, that way you can never be caught out. It's rather easy to give an executable any icon you like.
not just an executable. the choice of icons for a file type is stored in registry, so it can easily be modified by other programs. i once saw a vb script worm that tricked you into executing it by replacing your images with copies of itself and posing as an image file.

Kelster23
27 Nov 2007, 19:06
Never rely on the icon to tell what a file is, turn file-endings on, that way you can never be caught out. It's rather easy to give an executable any icon you like.

You don't have to. Usually the people that have them are people who can't type properly, and those virus messages are:
a)usually popping up when you sign in,
b)Either too badly typed for them or really well typed compared to their usual,
c)Most people wouldn't up and send you a file right away anyway without telling you.

MrBunsy
27 Nov 2007, 19:42
You don't have to. Usually the people that have them are people who can't type properly, and those virus messages are:
a)usually popping up when you sign in,
b)Either too badly typed for them or really well typed compared to their usual,
c)Most people wouldn't up and send you a file right away anyway without telling you.

I would still recommend turning file endings on, that way you always know what type of file you're dealing with, whatever context.

Kelster23
27 Nov 2007, 19:45
I would still recommend turning file endings on, that way you always know what type of file you're dealing with, whatever context.

So how do you do that anyway?

MrBunsy
27 Nov 2007, 20:29
Explorer -> Tools menu ->Folder Options -> View Tab ->Untick "Hide file extension for known file types".

yauhui
2 Dec 2007, 14:48
file-endings

sometimes, file endings can be changed too.

lets say (LET'S SAY) i created a JPG image. then i changed the file extension to PNG. but it's still a JPG (Right click > Properties > File type: JPEG file), only that the extension says PNG.

No matter what, dont accept what you didnt request.

MrBunsy
2 Dec 2007, 16:39
sometimes, file endings can be changed too.

lets say (LET'S SAY) i created a JPG image. then i changed the file extension to PNG. but it's still a JPG (Right click > Properties > File type: JPEG file), only that the extension says PNG.

No matter what, dont accept what you didnt request.

Yeah, but that will be an intelligent programme detecting the type of image. Renaming an executable to .PNG should render it pretty useless.

*Splinter*
2 Dec 2007, 22:03
Yeah, but that will be an intelligent programme detecting the type of image. Renaming an executable to .PNG should render it pretty useless.

Unless you then rename it BACK to a .exe, in which case it will work again :p

SupSuper
2 Dec 2007, 22:20
So your point is...?

Pickleworm
3 Dec 2007, 00:36
So your point is...?

If someone sends you THIS_IS_ME_NAkED.png and tells you to rename it to .exe and then execute it, don't

franpa
3 Dec 2007, 03:36
sometimes, file endings can be changed too.

lets say (LET'S SAY) i created a JPG image. then i changed the file extension to PNG. but it's still a JPG (Right click > Properties > File type: JPEG file), only that the extension says PNG.

No matter what, dont accept what you didnt request.

yea, but most images contain a header and its this header that most image editing programs check before checking the file extension which is why you can rename a JPG to a PNG and have it still open perfectly.

pretty much same thing with audio files as well.

Pickleworm
3 Dec 2007, 05:40
yea, but most images contain a header and its this header that most image editing programs check before checking the file extension which is why you can rename a JPG to a PNG and have it still open perfectly.

pretty much same thing with audio files as well.

That's cool but a file with the headers of an image isn't going to hack my computer and read my chatlogs to grandma, so I think it's safe to say files ending with image file extensions are safe as long as you don't rename them to .exe and run them

SupSuper
3 Dec 2007, 17:00
That's cool but a file with the headers of an image isn't going to hack my computer and read my chatlogs to grandma, so I think it's safe to say files ending with image file extensions are safe as long as you don't rename them to .exe and run themHmmm, now there's an idea for a virus:
1. Check for installed IMs.
2. Check settings for chatlog folders.
3. Forward chatlogs to contacts.

thomasp
3 Dec 2007, 22:52
Hmmm, now there's an idea for a virus:
1. Check for installed IMs.
2. Check settings for chatlog folders.
3. Forward chatlogs to contacts.
Wouldn't this be better?

1. Check for installed IMs.
2. Check settings for chatlog folders.
3. Search chatlogs for names of other contacts.
4. Forward relevant chatlogs to said contacts.

Kelster23
4 Dec 2007, 00:45
Why not just not create viruses in the first place? Then everyone's happy!

Plasma
4 Dec 2007, 00:47
Yeah... for some reason, I get the impression that not a lot of people that do make viruses are gonna take your advice...

Pickleworm
4 Dec 2007, 02:27
Wouldn't this be better?

1. Check for installed IMs.
2. Check settings for chatlog folders.
3. Search chatlogs for names of other contacts.
4. Forward relevant chatlogs to said contacts.

This would be such an awesome virus

quakerworm
4 Dec 2007, 02:34
but do you really want to know? i mean really?

you'd still need a propagation vector, though. that's always the trickiest part of writing a virus/worm.
Why not just not create viruses in the first place?
because workers at mcaffe and notrton have families they need to feed.

yauhui
4 Dec 2007, 03:56
wow... you spelt both companies wrongly...

anyways, i received a new type of virus from my friend. This time it doesnt send a file, it links you to a website.. its <something, i dont remember>.blogspot.com

quakerworm
4 Dec 2007, 07:15
wow... you spelt both companies wrongly...
in my defense, it was a typo on norton. and mcafee... i got nothing.

Muzer
4 Dec 2007, 17:26
I went onto Pidgin after months of inactivity and recieved loads of these website things.