1. This forum is in read-only mode.


Discussion in 'Non-Emulation Help' started by Loonylion, Mar 16, 2007.

  1. Loonylion

    Loonylion Administrator Staff Member

    I have come across a file on MSN/Windows Live Messenger that I strongly suspect to be a virus/malicious. I have submitted it to Computer Associates for an analysis. Below is a copy of the email I sent them:

    Please be wary, guys and I'll update you if and when CA respond.
  2. Prototype

    Prototype Well-Known Member

    I would advice you not to log into your msn anymore, this file seems to be a lag mitter...or other words a spyware...which when you click on it, it installs it self into your system similar to the last virus called spammer.............althought this is a new upgrade to that 1.......basically what this program does is it send feedback to the user that created it or to an unknown server thats no longer in use but is active for someone.,.....it will gather information bout your computer and anything you do in it...so I suggest you no longer log into msn til you figure out the problem......and ofcourse no antivirus will detect because its neither virus nor spyware.............its a unknown virus file that contradicts with ms dos.......I download the file but I have no intention installing it cuz of I still need to check for more feed back bout this file......i dont have enought knowlendge bout this file yet...so I also suggest you report this to msn, or hotmail staff bout this....by the way add me to your msn, I wanna try something
    this is my e-mail
    [email protected]

    Ill be on MSN Messenger
  3. Loonylion

    Loonylion Administrator Staff Member

    Im gonna try running it in a sandbox (=isolated machine with nothing on it and no network connection) at some point, I'll let you know if I uncover anything
  4. Prototype

    Prototype Well-Known Member

    good luck mate and safe mission, in the mean time Ill search for this file online........... by the way whats the actual name that it says on the file.......that you downloaded?
  5. Seph

    Seph Administrator Staff Member

    msn=[recipients MSN username]


    * will then be the filename suffixed by .com
  6. Prototype

    Prototype Well-Known Member

    huh?....................explain :p
  7. Seph

    Seph Administrator Staff Member

    The filesnames are determined by your email address. If you're MSN email is [email protected] then the filename will be that.

    A filename is actually very dynamic, the files on the server doesn't have to be what your browser suggest to call it, if I wanted to I could make all files from romulation download as "seph is the l33t!.yarr"
  8. Loonylion

    Loonylion Administrator Staff Member

    An update on this: CA's automatic system has not found any virus in the file, however it has forwarded it onto their human researchers, who will get back to me. If you encounter this or any other file you suspect to be a virus; download it, but DO NOT run it. Instead, put it in a passworded zip file with the password 'virus' (all lower case) and email it as an attachment to: [email protected]. In the email detail how you came across the virus, and give any other information that you think may be useful to the people analysing the file. You will receive an automated response, then later a follow-up report from a researcher once the file has been fully analysed.
  9. Loonylion

    Loonylion Administrator Staff Member

    Here is the response from CA:

    Do NOT run this file if you encounter it.
  10. Prototype

    Prototype Well-Known Member

    thats because it is a worm, an undetectable worm..........not a virus but an unknown worm, worms arent really considered to be viruses, just pests
  11. Loonylion

    Loonylion Administrator Staff Member

    Final verdict:

    It cannot be detected by AV programs at this time.
  12. Prototype

    Prototype Well-Known Member

    huumm...interesting...guess I dont have to find it.....I guess that site I gave you isnt worth looking at since this is just a spammer but a serious file, not to deep but deep, malware isnt good to have,.....on a small file like that.........ofcourse you already know the answer

    malware cant be detected by antivrus program of any such......the only thing is prob a good anti spyware,.....but then I wonder if that will even detect it............because malware acts as such to a virus same caracteristics that steals information from your computer and sends it to a botserver......just like a trojan would..........(quoting: not a virus but malware interesting) whats the decoding on that file?..............
  13. Seph

    Seph Administrator Staff Member

    this would be more serious than malware, it is essentially a virus as it's made to spread itself. A virus does not have to be malicious in order to be classified as a virus.
  14. Prototype

    Prototype Well-Known Member

    but this isnt a virus of some sort, this is a malicious malware program if you read ontop it desplays that its malware(malware content) were not talking bout a serious virus were talking bout malware that steals information.....all malware do that...........
  15. Seph

    Seph Administrator Staff Member

    it spreads like a virus though.
  16. Prototype

    Prototype Well-Known Member

    I would have to agree with you there

    I would have to say that Loony got screwed big time in the ARSE!!!! :p

    ::) Sorry Loony but I had to say it.........lol :p
  17. Seph

    Seph Administrator Staff Member

    lol why? He's not infected or anything. :)

    Neither Loony nor I have executed the code, we merely had a little look at it in a hex editor before Loony sent it in to CA.
  18. Prototype

    Prototype Well-Known Member

    loony did get infected............... read ontop were it says............

    have come across a file on MSN/Windows Live Messenger that I strongly suspect to be a virus/malicious. I have submitted it to Computer Associates for an analysis. Below is a copy of the email I sent them:

    this suspicious file is spreading over MSN/windows live messenger, the instant message pops up with the following text:

    *cough* http://www13.im-profile.com/member.php?msn=[recipients MSN username]
    where the email address in [] is the recipients MSN username. Following the link prompts you to download a file named like the recipents MSN username. Neither CA eTrust or AVG recognise anything wrong with it, but opening in notepad confirms it is an executable. This is just too suspicious to ignore, especially since a lot of the people on my friend's (the one who 'sent' me the link) messenger are naive enough to download and run it. My friend confirmed he did not intentionally send me the link. I have advised him to uninstall and reinstall live messenger as a precaution.

    Please could you let me know if it is a virus, as I run an number of online communities where members are heavy MSN users, and I would like to warn them if possible.

    Thank you for time,

    or atleast I pressume he did get infected ;D
  19. Seph

    Seph Administrator Staff Member

    No I'm telling you he didn't get infected. :)

    You have to download and then execute the file, and Loony isn't stupid enough to execute a file like that. Well at least not in the afternoon, he might be early morning and late night though.
  20. Loonylion

    Loonylion Administrator Staff Member

    And another update:

    And no I didnt execute it. I'm not that stupid. :p