New MSN Messenger Trojan Targets VNCs Too [updated]
Created 2007-11-19 20:37

RELATED ARTICLES
  • Think Before You Click on That Great "Job Offer"
  • I Practice Safer Browsing
  • How To: Protect Yourself from Phishing and Pharming
News
  • Asus Traces Eee Box PC Virus to Chinese OEM
  • Super Printer Prints 8-Inch OLED Screens
  • No Surprise: Firefox 3.1 Beta Is Even Faster Than Firefox 3
  • Study: Googling Good for the Brain, Better Than Reading Archaic Book Technology
  • Microsoft Survey Alludes to Instant-On OS Concept
SEE MORE NEWS

New MSN Messenger Trojan Targets VNCs Too [updated]

Posted 11/19/07 at 09:37:25 PM |  by Mark 'Marcus Soperus' Soper

comment Commentsprint Printemail EmailDeliciousDiggStumbleUponReddit

eWeek reports that a new MSN Messenger Trojan is infecting hundreds of PCs per hour since it was launched yesterday. The speed of infection's a big concern, but what's even worse is how it works.

Double-Extension Blues

One of the methods this new IRC bot uses is the old double-extension trick: the Trojan executable disguises itself as a digital camera file such as DSC00452.jpg.exe. Users see the .jpg "extension" and figure all is well (some versions of this threat use a file called IMGxxxxxx.pif instead).

Trick Number Two: Contact Harvesting

The Trojan gathers contacts from infected PCs, and uses them to spread itself to new victims. In the best social-engineering tradition, users who are expecting to get a picture from a friend wind up getting infected instead.

[Corrected per updated eWeek article- see comment below]

Kicking It Up a Notch: Gunning for VNCs VMs

The infection and distribution techniques are all too familar, but the difference is that this Trojan isn't just gunning for physical PCs, but also for virtual network connections (VNCs). VNCs are widely used for remote support.machines (VMs). VMs are becoming very popular for hosting guest operating systems (Windows on MacOS, Vista on XP, etc.), in security appliances, and elsewhere.

Stop That Bot!

So, what can you do to stop this threat?

  • If you use MSN Messenger, don't assume that file attachments are actually being sent by an actual friend. Don't accept a file until you check with your contact.
  • Make sure your antivirus program checks IM file attachments for threats.
  • Suggest your friends using MSN Messenger switch to another IM client with better security.
  • If you use VNC connections, make sure you know who's on the other end of the connection.
  • And, finally, "think before you click."
COMMENTS:
2
TAGS: 
Security, virus, malware, phishing, social engineering, threats
comment Commentsprint Printemail EmailDeliciousDiggStumbleUponReddit
COMMENTS
  • Login or register to post comments
  • Technology News

  • Computer Cooling Fans

  • Computer Cases

  • PC Game Controllers

  • PC Games

  • Computer Hardware

  • Headphones

  • MP3 Players

  • Stream Video

  • Computer Mouse

  • Monitors

  • Motherboards

  • NAS Storage

  • Networking

  • Laptop Computers

  • DVD Burner

  • Digital Cameras

  • Portable Storage

  • Computer Accessories

  • Smartphone

  • Antivirus Software

  • Sound Cards

  • Speakers

  • Computer Systems

  • Thumb Drives

  • Video Cameras

  • Video Card Reviews

  • Water Cooling

  • Gadgets

  • Keyboards
  • Contact Us
  • Advertising
  • Privacy Policy
  • Terms & Conditions
  • RSS Feeds
  • Site Map
  • Customer Service
Future © 2008 Future US, Inc. All Rights Reserved.

Source URL: http://www.maximumpc.com/article/new_msn_messenger_trojan_targets_vms_too

Links:
[1] http://www.eweek.com/article2/0,1759,2218894,00.asp
[2] http://www.smith.edu/its/tara/smith_network/vnc.html
[3] http://www.maximumpc.com/article/think_before_you_click_on_that_great_job_offer
[4] http://www.maximumpc.com/article/safer_browsing
[5] http://www.maximumpc.com/article/How-To--Protect-Yourself-from-Phishing-and-Pharming
[6] http://www.neowin.net/news/main/07/11/19/new-msn-messenger-trojan-spreading-quickly