Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Live Messenger > Massive Msn Worm Or Trojan ??

Reply
Thread Tools Display Modes

Massive Msn Worm Or Trojan ??

 
 
Cyberhash
Guest
Posts: n/a

 
      12-23-2007
Recently i started receiving messages from one of my contacts with links to
webpages such as the following examples (have replaced http with **** to
prevent people clicking on these links).


****://ucakcatkisi.info
****://www.free-offers-for-you.com
****://www.dont-miss-this.com
****://www.free-offers-your-clicks.com
****://publicinfoart.info
****://invitesoftware.info
****://heycanbasliyor.info
****://auramin.info
****://suborusu.info

When these messages are received, the infected contact goes from being
online to showing as being busy for a period around 1 minute. Then it shows
them logging off and logging on again.

It became annoying to the point i asked them to run Anti spyware and
Antivirus scans. And after having them visit every online scan engine
possible, and using various locally installed anti spyware packages. None
of them was able to detect whatever was causing this barrage of links

Online scanners Tested
===============
Trend Micro , Eset, Symantec, Kaspersky, Panda, Bitdefender, Avast, Sunbelt,
Prevx CSI

Locally Installed Antispyware Tested
=======================
Windows defender, Superantispyware, Spyware Doctor, Spybot S&D, Adware 2007

Asked them to allow me to provide remote assistance to try and help them
with their problem, as this is causing not only them to be logged out of
msn, but its also crashing windows. And forcing them to restart the pc.

What i observed was that "windows live messenger" was using abnormally large
amount of the cpu before it logged them out and eventually caused the o/s to
crash. By This i mean a instant jump to 99%

When they were being logged out, a message with wording similar to "you have
been logged out of messenger and logged into another version that does not
support multiple login".

I then checked all running processes and not only was "windows live
messenger" running, but also "windows messenger" , the one XP installs by
default (Also using large amounts of Cpu time). And thinking of the popup
message from "live messenger" i thought that maybe somehow the old version
of "windows messenger" was in some way related to this problem and removed
it from their system.

This action has stopped my contact from sending me links , but has not
resolved the whole issue. As 4 of their contacts are sending the same links
to them , that in turn still causes them to be signed out of "windows live
messenger" (using lots of cpu time again) and have to log in again.

In short.... These links crash"windows live messenger" and somehow use
"windows messenger" to propagate the message onto everyone on your contact
list.

I use vista x64 , and these links do not cause my pc to crash or for cpu
usage to go up. Whether that's down to whatever is running only affects xp
machines or if its down to the individual piece of code that's been
installed on the xp machine i dont know.

You can observe the behaviour of it when using remote assistance in XP , via
help and support on your startbar. When it brings up your list of messenger
contacts to ask for remote assistance, you can observe it going through your
contact list 1 by 1 messaging them.

My friend and 4 of her friends surely aren't the only 5 people in the world
that's been infected by this

Hopefully this Half fix will help stop some peoples pc crashing but it
wont stop you being logged off or receiving more of these links from your
contacts............ until someone somewhere can deliver a proper fix for
this.



 
Reply With Quote
 
 
 
 
MSNUser
Guest
Posts: n/a

 
      03-05-2008
I recieved the same thing and have a saved file of the virus. Where can I
post it?

"Cyberhash" wrote:

> Recently i started receiving messages from one of my contacts with links to
> webpages such as the following examples (have replaced http with **** to
> prevent people clicking on these links).
>
>
> ****://ucakcatkisi.info
> ****://www.free-offers-for-you.com
> ****://www.dont-miss-this.com
> ****://www.free-offers-your-clicks.com
> ****://publicinfoart.info
> ****://invitesoftware.info
> ****://heycanbasliyor.info
> ****://auramin.info
> ****://suborusu.info
>
> When these messages are received, the infected contact goes from being
> online to showing as being busy for a period around 1 minute. Then it shows
> them logging off and logging on again.
>
> It became annoying to the point i asked them to run Anti spyware and
> Antivirus scans. And after having them visit every online scan engine
> possible, and using various locally installed anti spyware packages. None
> of them was able to detect whatever was causing this barrage of links
>
> Online scanners Tested
> ===============
> Trend Micro , Eset, Symantec, Kaspersky, Panda, Bitdefender, Avast, Sunbelt,
> Prevx CSI
>
> Locally Installed Antispyware Tested
> =======================
> Windows defender, Superantispyware, Spyware Doctor, Spybot S&D, Adware 2007
>
> Asked them to allow me to provide remote assistance to try and help them
> with their problem, as this is causing not only them to be logged out of
> msn, but its also crashing windows. And forcing them to restart the pc.
>
> What i observed was that "windows live messenger" was using abnormally large
> amount of the cpu before it logged them out and eventually caused the o/s to
> crash. By This i mean a instant jump to 99%
>
> When they were being logged out, a message with wording similar to "you have
> been logged out of messenger and logged into another version that does not
> support multiple login".
>
> I then checked all running processes and not only was "windows live
> messenger" running, but also "windows messenger" , the one XP installs by
> default (Also using large amounts of Cpu time). And thinking of the popup
> message from "live messenger" i thought that maybe somehow the old version
> of "windows messenger" was in some way related to this problem and removed
> it from their system.
>
> This action has stopped my contact from sending me links , but has not
> resolved the whole issue. As 4 of their contacts are sending the same links
> to them , that in turn still causes them to be signed out of "windows live
> messenger" (using lots of cpu time again) and have to log in again.
>
> In short.... These links crash"windows live messenger" and somehow use
> "windows messenger" to propagate the message onto everyone on your contact
> list.
>
> I use vista x64 , and these links do not cause my pc to crash or for cpu
> usage to go up. Whether that's down to whatever is running only affects xp
> machines or if its down to the individual piece of code that's been
> installed on the xp machine i dont know.
>
> You can observe the behaviour of it when using remote assistance in XP , via
> help and support on your startbar. When it brings up your list of messenger
> contacts to ask for remote assistance, you can observe it going through your
> contact list 1 by 1 messaging them.
>
> My friend and 4 of her friends surely aren't the only 5 people in the world
> that's been infected by this
>
> Hopefully this Half fix will help stop some peoples pc crashing but it
> wont stop you being logged off or receiving more of these links from your
> contacts............ until someone somewhere can deliver a proper fix for
> this.
>
>
>
>

 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Trojan/Worm suspect in Vista Yulia Windows Vista Security 5 06-01-2008 12:59 AM
winlogon trojan/worm??? lilmommaof3 Windows Vista Security 8 03-02-2007 10:51 PM
Re: winlogon trojan/worm David H. Lipman Windows Update 0 01-24-2007 09:40 PM
Re: winlogon trojan/worm PA Bear Windows Update 0 01-24-2007 06:52 PM
Re: winlogon trojan/worm realcestmoi Windows Update 0 01-24-2007 06:07 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59