Warning: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in ..../includes/class_bbcode.php on line 2962
MSN Messenger hit by double-whammy worm
Page 1 of 3 123 LastLast
Results 1 to 10 of 29

Thread: MSN Messenger hit by double-whammy worm

  1. #1
    Mentor
    Join Date
    Aug 2004
    Location
    Toronto, Canada
    Posts
    1,159
    MSN Messenger hit by double-whammy worm
    Trend Micro is warning of a new variant of the Bropia worm that uses MSN Messenger to spread.

    The Bropia.F worm is packaged with a second, more damaging worm that tries to exploit poorly patched computers, the antivirus company said on Thursday.

    The latest variant of the Bropia worm was discovered on Wednesday evening, Trend Micro said. It infects systems belonging to users of MSN Messenger by sending itself as a picture of a roast chicken with tan lines to all available or online contacts. It also releases a second more dangerous worm, called Agabot.ajc, on the infected computer.

    Adam Biviano, a senior systems engineer at Trend Micro, said that although there have only been a handful of reported infections, the company has declared the worm a medium risk, because of its potential to spread and steal users' bandwidth.

    "The potential for damage is quite high, because it drops another worm on your machine that is quite nasty and can spread through network by taking advantage of unpatched desktops and servers," Biviano said.

    Biviano said this variant of Bropia can easily be avoided, because it exploits vulnerabilities that could have been patched months ago and relies on people opening a file through MSN Messenger. He advises people to only open files received through the instant messaging program if they are expected--even if they are from a contact. It is very possible that the file is being sent unbeknown to that person, he said.

    "Usually, if you are sending a file using (an instant messaging program), you say 'I'm sending you this picture, have a look at it.' It is never random or out of the blue," Biviano said.

    The worm affects MSN Messenger on computers running Windows 95, 98, ME, NT, 2000 and XP, according to Trend Micro's advisory. The company is advising MSN Messenger users to avoid accepting file transfers coming from an untrusted source.

    Biviano said the second worm--Agabot.ajc--does have the potential to perform a distributed denial-of-service attack on certain services. For example it preys on the same vulnerabilities that were exploited by Slammer, Blaster (MSBlast) and Sasser.

    Biviano said this variant of Bropia is the first worm to use instant messaging that has been given a higher-level alert status. It probably won't be the last, he said.

    "Obviously, the popularity of IM itself is starting to gain the attention of the virus writers, and they are now using it as a tool," he said.

    Source: CNet

  2. #2
    Member
    Join Date
    Aug 2004
    Posts
    213
    This is bad. But i'm not too worried because I have my firewall blocking all files coming in from messengers.

    Still very easy solution is to not accept files from people, specially if it's coming in without a message first.

  3. #3
    Mentor
    Join Date
    Aug 2004
    Location
    Toronto, Canada
    Posts
    1,159
    Of course, common sense is if a person on your contact list sends a file all of a sudden without a message first, you'd ask him what the file is before taking it.

    Getting hit by this worm doesn't worry me all too much as much as the news bit in the first post that suggests there will be a rise in viruses via messengers.

  4. #4
    Newbie
    Join Date
    Oct 2004
    Posts
    1
    Thanks for sharing

  5. #5
    Mentor
    Join Date
    Aug 2004
    Location
    Toronto, Canada
    Posts
    1,159
    You're welcome aamir. Hope this will help many others get aware of the vulnerability.

  6. #6
    Newbie
    Join Date
    Feb 2005
    Posts
    1
    First THX for sharing the info, then, how can he clean them out of our pcs if we get infected?, the anti-virus software companies have developed an update to fix that issue ?

  7. #7
    Mentor
    Join Date
    Aug 2004
    Location
    Toronto, Canada
    Posts
    1,159
    No word on the fix yet, I'm awaiting some news on that too. Will post it here as soon as I get it.

    For now just don't accept files that look wierd.

  8. #8
    Senior Member
    Join Date
    Jan 2005
    Location
    Neer Springfield, MA
    Posts
    443
    That really sucks, but i normally most of the time use AIM. Personally I think it is much better and more organized messenger.
    "If you enjoy what you do, you'll never work another day in your life."

    My man confucius said it well :D

    Why is my signature text blue I did not make it like that??

  9. #9
    Junior Member
    Join Date
    Feb 2005
    Location
    Mississauga, Ontario
    Posts
    54
    that is pretty bad, gen thanks again eh ... dam idiots launching these viruses

    HEY EVERYONE
    http://www.geocities.com/puneet123ca/sigRX7.jpghttp://img.photobucket.com/albums/v4...dancinggir.gif

    EVERYBODY DANCE, EVERYBODY DANCE, everybody look at your pants

    While looking at my sig, my wienie has struck a rigamortis

    victory shall be mine!!!

  10. #10
    Mentor
    Join Date
    Aug 2004
    Location
    Toronto, Canada
    Posts
    1,159
    Hey man, you made it here!

Similar Threads

  1. Double startup problem
    By toastrack in forum Linux - Software, Applications & Programming
    Replies: 0
    Last Post: 11-01-2008, 11:36 AM
  2. Range of a double integer in C++
    By tech291083 in forum Redhat / Fedora
    Replies: 4
    Last Post: 04-28-2007, 07:22 AM
  3. Double spacing
    By geeezeit in forum Windows - General Topics
    Replies: 0
    Last Post: 10-25-2006, 01:09 AM
  4. removed a double post.
    By pbharris in forum Announcements and Suggestions
    Replies: 0
    Last Post: 11-09-2002, 02:13 AM
  5. Am I seeing double??
    By Black666 in forum Linux - General Topics
    Replies: 3
    Last Post: 05-26-2002, 01:19 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •