Digital Point Forums
westernunion

Go Back   Digital Point Forums > The Digital Point > General Chat
Google Analytics
Log In to view
your analytics

Reply
 
Thread Tools
  #1  
Old Oct 9th 2006, 8:14 am
-Abhishek-'s Avatar
-Abhishek- -Abhishek- is offline
Regaining my Momentum!
 
Join Date: Mar 2006
Location: India
Posts: 2,109
-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of
New Yahoo Messenger Hijacker Trojan - An Indepth Explanation And Solution

So today, like any other day, I logged on to Yahoo Messenger only to be stormed by PMs from about 7 of my clients (serious people, for that matter) with kiddish text, smilies and a link to a common site. It didn’t take time for me to realise that something was very-very wrong here.

I began exploring and researching about it and even tried the link on various browsers on an old machine I have. My research drew a few conclusion. A few of you might be interested to read on.

This apparently is a new trojan that infects Internet Explorer and is a bait to get ad revenue.

Conclusions (Confirmed)
1. It uses msinet.ocx and web browser control for communicating with websites or downloading more file.
2. It begins by adding an unusual taskkil.exe in your System32 directory, which is a program to kill System Processes.
3. Creates a batch script located at C:\killav.bat to kill antiviruses.
4. It accesses XXX, where the developer may enter commands for the application to update itselves.
5. It then begins access to XXXX, which shows adbrite ads when opened in Firefox, maybe there is an autoclicking feature encoded.
6. It downloads the executable from YYY which it then renames to svchost32.exe
7. It also downloads the executable at YYYY

The developer seems to want this trojan to be termed “Termex” since he owns the domain Mytermex(dot)com (Donot Visit this Site) and has directories named “Termex” on the server where he hosts his Executables!

The code is no doubt a good one, but I’d have preferred if he must’ve used this knowledge for good. Now apparently this doesn’t seem to affect FireFox/Mozilla and Opera Browsers (Note the apparently) but IE users are doomed.

I am Infected! Now what ?
Don’t Panic Tech Guru has written a nice tutorial to save yourself from this Trojan, I haven’t tried it yet, but from the look of it ,it appears that it’ll work. So go ahead and find it here
http://www.newsfactor.com/blog_article.php?aid=305161

How does this spread ?
I am not aware of the other mediums but yes, I mselves have witnessed this propogating through Yahoo Messenger, and there is a possibility that it may send your Yahoo ID/Password to the attacker.
Possible PMs that you may get are

Quote:
damn, she is so cute hxxp://nsl-school.org?id=miss_world (Donot Open this URL in your Browser)
Quote:
have you ever seen such a silly man like this ? hxxp://nsl-school.org?id=stories (Donot Open this URL in your Browser)
Quote:
Download Free MP3s at hxxp://nsl-school.org?id=mp3 (Donot Open this URL in your Browser)
These Message are generally very tempting and make you click on the link, but once you do, You’re doomed!

!!!WARNING DONOT OPEN THE URLS BELOW IN YOUR BROWSER OR YOU MAY GET INFECTED!!!
XXX = hxxp://giftshop.vn/update.txt
XXXX = hxxp://www.myglobal-news.com
YYY = hxxp://italiandirectory.com/termex/host2.exe
YYYY = hxxp://italiandirectory.com/termex/host.exe

Possible Domains Owned by the Developer of this Trojan
hxxp://www.nsl-school.org
hxxp://www.giftshop.vn
hxxp://www.myglobal-news.com
hxxp://www.italiandirectory.com

I have managed to accumulate the above data, and will go on updating this post as I find more stuff.

If you found this article then please DIGG IT

Original Article on my Blog

Abhishek
Reply With Quote
  #2  
Old Oct 9th 2006, 8:21 am
dotcompals's Avatar
dotcompals dotcompals is offline
of the Nightfall
 
Join Date: Dec 2005
Location: www.World-Click.com
Posts: 2,435
dotcompals has much to be proud ofdotcompals has much to be proud ofdotcompals has much to be proud ofdotcompals has much to be proud ofdotcompals has much to be proud ofdotcompals has much to be proud ofdotcompals has much to be proud ofdotcompals has much to be proud ofdotcompals has much to be proud ofdotcompals has much to be proud of
Abhishek, thank you very much for this useful information
__________________
Quality Link Building services from dotcompals
Submit your URL to all the NEW directories announced at DP Solicitations & Announcements Forums.
Reply With Quote
  #3  
Old Oct 9th 2006, 10:27 pm
-Abhishek-'s Avatar
-Abhishek- -Abhishek- is offline
Regaining my Momentum!
 
Join Date: Mar 2006
Location: India
Posts: 2,109
-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of
You're Welcome dotcompals ... Glad I could be of help!

For other's, to prove my point on how fast this trojan has been spreading!
You might want to see this,
http://www.alexa.com/data/details/tr...nsl-school.org

Abhishek
Reply With Quote
  #4  
Old Oct 10th 2006, 12:37 am
fordP's Avatar
fordP fordP is offline
Twilight Vanquisher
 
Join Date: Jul 2006
Location: Dallas, Texas
Posts: 530
fordP will become famous soon enough
ouch, luckily i dont use IE. Thanks for the info
Reply With Quote
  #5  
Old Oct 10th 2006, 2:10 am
-Abhishek-'s Avatar
-Abhishek- -Abhishek- is offline
Regaining my Momentum!
 
Join Date: Mar 2006
Location: India
Posts: 2,109
-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of
Quote:
Originally Posted by fordP View Post
ouch, luckily i dont use IE. Thanks for the info
Nor do I, possibly this was why I was saved!

When I got the Yahoo! PM, my first reaction was that maybe my client launched a new site and had PMed me to inform about it (though it's quite unusual for him to do that)

But when I checked the link, I immediately found stuff to be wrong here!

When I went back to my offlines, I noticed the same message from a few more of them and so it led me into investigating it and the above report was then created by me!

If someone found it useful, then cheers!

Abhishek
Reply With Quote
  #6  
Old Oct 10th 2006, 2:11 am
Bondat's Avatar
Bondat Bondat is offline
of the Nightfall
 
Join Date: Jun 2006
Posts: 2,400
Bondat is a splendid one to beholdBondat is a splendid one to beholdBondat is a splendid one to beholdBondat is a splendid one to beholdBondat is a splendid one to beholdBondat is a splendid one to beholdBondat is a splendid one to beholdBondat is a splendid one to behold
I hope my sister wont click it. Because sometimes they tend to click it eventhough I've warned them already.
__________________
eWebPages.org
Submission4U Free Directory Alive
Reply With Quote
  #7  
Old Oct 10th 2006, 2:17 am
-Abhishek-'s Avatar
-Abhishek- -Abhishek- is offline
Regaining my Momentum!
 
Join Date: Mar 2006
Location: India
Posts: 2,109
-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of
Quote:
Originally Posted by Bondat View Post
I hope my sister wont click it. Because sometimes they tend to click it eventhough I've warned them already.
That's the primary reason why I have made the URLs Not Clickable! And have given warnings in bold!
If they still goto the URLs ... then ...umm ... well you know it!
Reply With Quote
  #8  
Old Oct 10th 2006, 4:47 am
pro_flash_4_u's Avatar
pro_flash_4_u pro_flash_4_u is offline
Grunt
 
Join Date: Oct 2006
Posts: 38
pro_flash_4_u is on a distinguished road
Solve all your problems, get a mac!
Reply With Quote
  #9  
Old Oct 10th 2006, 4:50 am
RedruM*'s Avatar
RedruM* RedruM* is offline
Twilight Vanquisher
Recent Blog: The Cup Chase
 
Join Date: Sep 2006
Posts: 626
RedruM* is on a distinguished road
do you have to download it , or just go to the link ?
Reply With Quote
  #10  
Old Oct 10th 2006, 6:43 am
Seiya's Avatar
Seiya Seiya is offline
Starcaller
 
Join Date: May 2005
Location: London
Posts: 4,618
Seiya has a brilliant futureSeiya has a brilliant futureSeiya has a brilliant futureSeiya has a brilliant futureSeiya has a brilliant futureSeiya has a brilliant futureSeiya has a brilliant futureSeiya has a brilliant futureSeiya has a brilliant futureSeiya has a brilliant futureSeiya has a brilliant future
With ie,just go to the link for sure lol. Im at school, its so tempting to check those links!

---

ahh lol, i accidentaly got to the site through alexa and IE auto download the virus. however, the school antiviruse caught me and now im being escorted by security to the detention hall! hahah just kidding , but yeh the antivirus got it and delted it!

Last edited by Seiya; Oct 10th 2006 at 6:50 am.
Reply With Quote
  #11  
Old Oct 10th 2006, 7:52 pm
khasmoth's Avatar
khasmoth khasmoth is offline
of the Nightfall
 
Join Date: Jan 2006
Posts: 1,128
khasmoth is just really nicekhasmoth is just really nicekhasmoth is just really nicekhasmoth is just really nicekhasmoth is just really nice
Heres the message I received this morning.
Dont visit the link BTW
Code:
 Use this tool to remove viruses from your PC : http://myglobal-news.com/?id=virus_shield
[/quote]
Code:
sylailing (10/11/2006 9:31:52 AM): oh my god , i've won a 20000 usd lottery :O http://nsl-school.org/?id=winning_list . Come to my house tonight for a party !! >:D<
__________________
Travel Guide | Boats for sale | |
Reply With Quote
  #12  
Old Oct 10th 2006, 8:59 pm
-Abhishek-'s Avatar
-Abhishek- -Abhishek- is offline
Regaining my Momentum!
 
Join Date: Mar 2006
Location: India
Posts: 2,109
-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of
Your Friend has been infected by the very same trojan I mentioned! Give him/her the above link!

Abhishek
Reply With Quote
  #13  
Old Oct 10th 2006, 11:32 pm
khasmoth's Avatar
khasmoth khasmoth is offline
of the Nightfall
 
Join Date: Jan 2006
Posts: 1,128
khasmoth is just really nicekhasmoth is just really nicekhasmoth is just really nicekhasmoth is just really nicekhasmoth is just really nice
Quote:
Originally Posted by -Abhishek- View Post
Your Friend has been infected by the very same trojan I mentioned! Give him/her the above link!

Abhishek
Yeah thanks for this link. Just wondering if she manually send the link to me as well? Or it's automatic?
__________________
Travel Guide | Boats for sale | |
Reply With Quote
  #14  
Old Oct 10th 2006, 11:45 pm
-Abhishek-'s Avatar
-Abhishek- -Abhishek- is offline
Regaining my Momentum!
 
Join Date: Mar 2006
Location: India
Posts: 2,109
-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of
It's automatic, the trojan Hijacks Yahoo Messengers and send IM to the people in the list.

It most likely imports the Address List from your Y! Messenger and utilises the "ymsgr:SendIM?Yahoo ID" to send those IMs to your list! Thereby propogating the link and infecting the people on the list!

Abhishek
Reply With Quote
  #15  
Old Oct 12th 2006, 11:14 pm
Indian's Avatar
Indian Indian is offline
of the Nightfall
 
Join Date: Dec 2004
Location: Mumbai, India
Posts: 1,538
Indian is a jewel in the roughIndian is a jewel in the roughIndian is a jewel in the roughIndian is a jewel in the rough
I was about to click this link which was displayed as a friend's status on Yahoo Messenger. Thought it would be her picture and I use IE
Reply With Quote
  #16  
Old Oct 12th 2006, 11:28 pm
-Abhishek-'s Avatar
-Abhishek- -Abhishek- is offline
Regaining my Momentum!
 
Join Date: Mar 2006
Location: India
Posts: 2,109
-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of
Harry, you use IE ? Firewall pe sabko FireFox use karne bolta tha !!! Haha ...

Yes this affected a lot of people, I was surprised when I got the same PM from about 7 people! Thank your stars ... you're saved! Hehe
Reply With Quote
  #17  
Old Oct 12th 2006, 11:32 pm
Indian's Avatar
Indian Indian is offline
of the Nightfall
 
Join Date: Dec 2004
Location: Mumbai, India
Posts: 1,538
Indian is a jewel in the roughIndian is a jewel in the roughIndian is a jewel in the roughIndian is a jewel in the rough
Quote:
Originally Posted by -Abhishek- View Post
Harry, you use IE ? Firewall pe sabko FireFox use karne bolta tha !!! Haha ...

Yes this affected a lot of people, I was surprised when I got the same PM from about 7 people! Thank your stars ... you're saved! Hehe
I like Firefox but dunno...due to some reason I always click on the IE logo next to the start button. One thing I hate about FF is the tabs at the top...I am used to click multiple tabs at the bottom...Is there a way to bring those tabs below?
Reply With Quote
  #18  
Old Oct 12th 2006, 11:41 pm
-Abhishek-'s Avatar
-Abhishek- -Abhishek- is offline
Regaining my Momentum!
 
Join Date: Mar 2006
Location: India
Posts: 2,109
-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of-Abhishek- has much to be proud of
Tabbrowser Preference Extension Explained

Cheers!

Abhishek
Reply With Quote
  #19  
Old Oct 12th 2006, 11:47 pm
Indian's Avatar
Indian Indian is offline
of the Nightfall
 
Join Date: Dec 2004
Location: Mumbai, India
Posts: 1,538
Indian is a jewel in the roughIndian is a jewel in the roughIndian is a jewel in the roughIndian is a jewel in the rough
Problem solved. Thanx Bro
Reply With Quote
  #20  
Old Oct 13th 2006, 8:50 am
Nida G's Avatar
Nida G Nida G is offline
Champion of the Naaru
 
Join Date: Oct 2006
Posts: 110
Nida G is on a distinguished road
its also try to use our msn..but its not work correctly on it...but shit working on yahoo..I am also infected...thanks abheshak for solution...
__________________
Myspace Codes | Msn Display Pictures | |
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Yahoo messenger v5.6 musicmike Yahoo 23 Jun 19th 2008 8:47 am
Yahoo messenger now interconected with msn live messenger sandossu General Chat 2 Jul 19th 2006 6:45 pm
New emoticons for use in Yahoo Messenger siraxi Yahoo 0 May 27th 2006 11:48 am
Yahoo Messenger tropicalguy Yahoo 1 Nov 21st 2005 10:12 am
Yahoo Messenger ambilyappukuttan Yahoo 2 Mar 29th 2005 1:30 am


All times are GMT -8. The time now is 8:42 am.