beatwerk
2009-02-24, 01:27
Hi lads,
Today there is some real nasty fella spreading through MSN and Yahoo messengers. It is acting really fast, within 30 minutes i found everyone on my contact list infected. Fella is smart... it provides a code generated text along "hey, check this out" or "could you help me with this photo, maybe you can make it look better" or... "ricky martin gay fotos", and it's always followed by link to http://www.asdastory(dot)ws/uploadfiles/user0193/DVR-IMAGEN005.jpg.zip and information that you need to open it in Photoshop.
well, anyway it's foolin ppl around easily, including me (however I did'n fell for Ricky Martin thing ;) ), and it's acting fast, almost instantly resending itself to everyone from contact list, but what's worst it's disabling all security and security-related tools, - my PC Cillin and Spybot S&D went down instantly, and now I can't even open Sysinternals Process Explorer or HijackThis.
It's also hidng itself well from Windows Task Manager.
I don't know it it is related, but with netstat I was able to track process named - avirarkm.exe - which is connecting to 208.77.45.92:8764
well.... that's all i know now, running kaspersky online scanner at the moment and I'll keep ya updated.
cheers.
Today there is some real nasty fella spreading through MSN and Yahoo messengers. It is acting really fast, within 30 minutes i found everyone on my contact list infected. Fella is smart... it provides a code generated text along "hey, check this out" or "could you help me with this photo, maybe you can make it look better" or... "ricky martin gay fotos", and it's always followed by link to http://www.asdastory(dot)ws/uploadfiles/user0193/DVR-IMAGEN005.jpg.zip and information that you need to open it in Photoshop.
well, anyway it's foolin ppl around easily, including me (however I did'n fell for Ricky Martin thing ;) ), and it's acting fast, almost instantly resending itself to everyone from contact list, but what's worst it's disabling all security and security-related tools, - my PC Cillin and Spybot S&D went down instantly, and now I can't even open Sysinternals Process Explorer or HijackThis.
It's also hidng itself well from Windows Task Manager.
I don't know it it is related, but with netstat I was able to track process named - avirarkm.exe - which is connecting to 208.77.45.92:8764
well.... that's all i know now, running kaspersky online scanner at the moment and I'll keep ya updated.
cheers.