KezNews.com
DownloadsOther NewsForumBlogsWallpapersJokewareSearch

News letter:


Enter Your E-mail:

New MSN Messenger Trojan Spreading Quickly


section: microsoft, for your questions: KezNews forum, 19.11.2007

An MSN Messenger Trojan is growing a botnet by hundreds of infected PCs per hour.




A Trojan is introducing malware into thousands of computer systems worldwide, and the number is growing by the hour.

The malware is being introduced by MSN Messenger files posing as pictures, mostly seeming to come from known acquaintances.

The files are a new type of Trojan that has snared several thousand PCs for a bot network within hours of its launch earlier on Nov. 18 and is being used to discover virtual PCs as a means of increasing its growth vector.

The eSafe CSRT (Content Security Response Team) at Aladdin—a security company—detected the new threat propagating around noon EST on Nov. 18. At 18:00 UTC (Coordinated Universal Time), eSafe had detected 1 operator and more than 500 on-command bots in the network. Less than three hours later, or by 2:30 EST, when eWEEK spoke with Roei Lichtman, eSafe director of product management, the number had soared to several thousand PCs and was growing by several hundred systems per hour.

eSafe is monitoring the IRC channel used to control the botnet. The only inhabitants of the network besides the operator are in fact infected PCs.

The Trojan is an IRC bot that's spreading through MSN Messenger by sending itself in a .zip file with two names. One of the names includes the word "pics" as a double extension executable—a name generally used by scanners and digital cameras: for example, DSC00432.jpg.exe. The Trojan is also contained in a .zip file with the name "images" as a .pif executable—for example, IMG34814.pif.

The files are infiltrating new systems by using either known contacts from which the Trojan has harvested instant messaging names, as well as from the systems of unknown users.

The infection vector—an IM program—isn't new. But the Trojan is the first that eSafe has tracked that has tried to scan for VNC (Virtual Network Computing) instances, likely in order to multiply the botnet's number of connections.

View: KezNews Discussion - New MSN Messenger Trojan Spreading Quickly

source: eweek.com

send email Send link 2 friend  |  Permalink
<< previouse article
Windows 7 top feature request list leaked to the public
next article >>
Antispyware Protection – Is It Really Possible?

MORE RELATED ARTICLES:
Hackers quickly move to exploit Bhutto assassination || Microsoft's limited Zune 80 Stock sells out way too quickly || MS: Trojan Horses Increase 300 Percent || Microsoft Backtracks, Allows MSN Music Access Until 2011 || Windows Live Messenger 9.0

Comments(5)

my computer's safe - now

By Grandpa on 19.11.2007 - 22:11
just read article and then threw computer
computer off the 10th floor balcony...

let's see msn infect it now :)

Grandpa

By ur Son on 19.11.2007 - 22:11
you should have thrown urself out of the building and not worry about ur computer.

friends gots it

By ai.. on 20.11.2007 - 02:11
my friends have the trojan = = just so dumb to fall for it. if it was a pic itll be jpg png etc. any way to fix this?

Shitty

By dubb on 20.11.2007 - 11:11
that happened to me, but i didnt download it, its an obvious virus if its 200k's exactly, and my buddies don't type like fruitcakes.

Size of the virus

By ai... on 20.11.2007 - 18:11
well the size for the virus was only 77k's for us, packed in a zip or rar


No new comments are allowed for this article.

For your questions use our KezNews Discussion - New MSN Messenger Trojan Spreading Quickly