Jump to content

New MSN worm


Recommended Posts

Wouldn't normally post this, but there is a very nasty worm spreading via MSN at the moment.


The format is roughly you will get a message from one of your contacts which will say something like "Is this you in the picture" and a link to a .jpg. When you click on it the site redirects you to a file of the same name but with a .pif extension (old format for windows icon files) which is executable by default. If you open this you are screwed.


The worm itself is being called a bunch of things depending on who you listen to :-


[koho 1] ~ > clamscan photo656.pif

photo656.pif: Trojan.MSNMaker FOUND


Most sites are calling it MSNMaker.something


The vulnerability is ages old, but this one drops a very nasty worm on your machine :- http://virusinfo.prevx.com/viruscenter.asp?GRP=4804300017


It can log keystrokes, activate other vulnerabilities and all sorts, nasty thing.


Just be warned (most AV scanners can't detect it yet, norton which is a pile of **** certainly doesn't)

Link to comment
Share on other sites

speaking of norton... I have the professional norton antivirus and firewall.... along with windows own firewall...

what do you reccomend.... anything free?:look:?

because my wife keeps paying them a hundred or so to update our system... (mug) anyway thats my wife.


I am tired of norton slowing my pc down to a unbearbale crawl.


please help almight computer one.

Link to comment
Share on other sites


http://www.grisoft.com/ (avg)




Ditch norton, it will be causing you more headaches than its capable of fixing for you. McAffee used to be good, they have the best engine out there but **** software round it :lol: I have a guy that works for me that came from McAfee and he's **** hot, they know their stuff :look:

Link to comment
Share on other sites

Will you know if this is on your computer?


The thing it drops (might drop more than one thing) is covert, you probably wouldn't notice it, no.



I use Kerio Personal Firewall. I assume it does the job! (and for free). And as mentioned AVG for Anti Virus.


Since this requires you to click on a link, no firewall will help you. As always keep bang up to date with the updates for whatever you use and regularly scan your machine.

Link to comment
Share on other sites

One of my lot got a message off a contact, it had this link in it :-


http://www.photogbase.com/pictures.php?photo656.jpg (please don't click this :good: )


wget http://www.photogbase.com/pictures.php?photo656.jpg


=> `pictures.php?photo656.jpg'


HTTP request sent, awaiting response... 302 OK

Location: photo656.pif [following]



It masks this redirect and downloads the .pif file instead, so this is what you are watching out for. It might be that this link comes to you in an email or a forum post, just be careful and always set your browser to ask you what to do each time you click (don't auto download) - and check the name of the file its downloading. In this case I spotted that it was .pif instead which screams WARNING :lol:


substituted http with hxxp. so no one gets zapped by it on here

Edited by Teal
Link to comment
Share on other sites

Hey all,


about this worm!! i was once silly enough to fall for it about this time last year!!! once you select the .jpg that it has posted on the msn chat window it will then automatically send itself to all the 'online contacts' that you have,


i found the only way to get rid of it was to 'system reboot' to either the day before or the day before that.


if you delete the file on its own it will reappear about 5 mins later or when you next use the computer, another way of getting rid of a 'few' (you will find maybe six shortcut looking things in the MY COMPUTER window) is to make a folder, put them into the folder then delete the folder.


I have Norton 2006 and so far my computer is completely healthly.......so far lol



Jim :good:

Link to comment
Share on other sites

Ive just installed that prevx scanner, should this pick it up?




http://virusscan.jotti.org/ is an online scanner which you send stuff too, and it tells you what AV scanners can find and clean it :-



Found Backdoor-Server/MSNMaker.W.9 backdoor


Found nothing


Found nothing

AVG Antivirus

Found nothing


Found nothing


Found Trojan.MSNMaker


Found BackDoor.Oscar

F-Prot Antivirus

Found nothing


Found W32/MSNMaker.W!tr.bdr

Kaspersky Anti-Virus

Found Backdoor.Win32.MSNMaker.w


Found a variant of Win32/MSNMaker

Norman Virus Control

Found nothing


Found nothing


Found Nothing




Hey all,


about this worm!! i was once silly enough to fall for it about this time last year!!! once you select the .jpg that it has posted on the msn chat window it will then automatically send itself to all the 'online contacts' that you have,


i found the only way to get rid of it was to 'system reboot' to either the day before or the day before that.


if you delete the file on its own it will reappear about 5 mins later or when you next use the computer, another way of getting rid of a 'few' (you will find maybe six shortcut looking things in the MY COMPUTER window) is to make a folder, put them into the folder then delete the folder.


I have Norton 2006 and so far my computer is completely healthly.......so far lol



Jim :good:


The payload is different this time, and nasty, its called Backdoor.Oscar and :-


Backdoor.Oscar runs in the background and connects to an IRC

server. The threat will then give attackers full access to the

infected system. The threat is capable of File Transfer,

Keylogging, Denial of Service, Packet Sniffing, can scan the

infected system for information and update itself.



Like I said before this is an old exploit but with a new and NASTY payload

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Create New...