Minggu, 06 Juli 2008

New Virus? Uglyhuman Msn Virus - A worm that isn't in the virus definitions yet?

Have you ever gotten a message from your friends that say something like this:

its you on this photo http://uglyhuman.net/photo***.php

I have received that from at least 3 people. Without knowing what it was (and the surprise from the domain name with the message tongue.gif), I clicked on the link and Firefox prompted me to download a file. It was a COM file so I thought that was strange. I rechecked the URL it was a PHP web page, so I assumed it was telling me to download the photo, so I opened it in Firefox.

Windows Live OneCare prompted me that Windows Live Messenger was about to run (with something that said updated program or something similar). I found that strange so therefore I clicked on Block this Program.

So after my next reboot, Windows Live OneCare said that it still blocked Windows Live Messenger. I assumed it was now safe to run Windows Live Messenger now, so I clicked the option to allow, closed Windows Live OneCare and opened Windows Live Messenger. Boy was I wrong! The virus started opening up windows of both online and offline people and started sending that message to them. It opened and closed windows so much that it was impossible to use ALT+TAB, ALT+F4 or even bring up Task Manager.

I unplugged the cable from my Internet modem and Windows Live Messenger disconnected. I quit the program then looked on Firefox to see if there was any instructions to remove this. The only results that come up were;

Yahoo! Answers - Weird Virus (no one got the answer there)
TechGuy Forums - Security (it was suggested to use HijackThis, but it didn't help)

So the virus isn't even in the definitions yet but it is spreading among buddies quite quickly. For the domain name, uglyhuman.net, McAfee SiteAdvisor has no rating for it. It would definitely be red for sure.

The virus isn't a running process, I couldn't find it in Task Manager or Process Log. However (not sure if the virus caused this), my explorer.exe process ended abruptly and had to restart a few times. Now I am stuck in Ubuntu (Linux) on a Live CD and OpenOffice.org really slowly (I need Microsoft Word). Anyone have suggestions to get rid of the virus? It isn't a running/startup process, it operates within Windows Live Messenger. Do I need to reinstall Windows XP? wink.gif

Tidak ada komentar: