PDA

View Full Version : virus that distribute itself through MSN



RayDream
2007-04-17, 00:28
Hi there,

Please forgive me if this question is unrelated to system malware, but I am not able to find any better forum ask this.

My friend has infected with a (virus?) on msn. I am unable to identify it with Norton Antivirus, so i can only do a little investigation. Once affect, it starts sending a link to everyone in the list. The link is:

68.ratemynuts.net/view_nuts.php?msn=test@hotmail.com

where 'test' appears to be my msn account. [/B]

Once clicked the link, it will direct and attempt to download a file to be open with 'test@hotmail.com'. I have not open it, but I wonder how does it affect and get the contacts from msn. I managed to use a program to download the file, appears in .com and scan it with Norton, which is not able to identify it.

My question is, does it affect the system? Or affect msn's server acc? How do I remove it so that it will stop distributing itself?

The file can be download here:


I'm not a programmer but I wish I could trace it. Another interesting investigation is, the links that distribute it trace to 68.ratemynuts.net which exist itself. I searched the internet an user got the same thing from 44.ratemynuts.net. And this link will redirect to grassfire.org? Is that some work of a hacker that cover himselves up with other ppl's sites?

tashi
2007-04-17, 01:42
Hello.

Please read this sticky: "BEFORE you POST" Mandatory Steps Before Requesting Assistance (http://forums.spybot.info/showthread.php?t=288)


Please do not attach or link to infected files!
If a helper requests files they will give you a link to upload them. :eek:

If you can find the file/s, please zip and send to: detections(AT)spybot.info (Replace AT with @)

If you or your friend need assistance, please follow the procedure in the link I provided; especially running the on-line anti virus scan. Then a helper will advise you.

Thanks. :)

RayDream
2007-04-20, 09:32
Oh some trojans were found. THanks!

tashi
2007-05-03, 20:12
This topic has been archived.

If you need it re-opened, please send me a private message (pm) and provide a link to the thread. Applies only to the original poster, anyone else with similar problems please start a new topic.