Published on Maximum PC (http://www.maximumpc.com)


New MSN Messenger Trojan Targets VNCs Too [updated]
Created 11/19/2007 - 7:37pm

Maximum IT
    • Cisco Cranks Out iPhone Security App for IT Managers
    • Verizon Puts Together Telehealth Collaboration Services
    • Ciena Coughs Up $530 Million in Cash for a Slice of Nortel Networks

    Sponsored
SEE MORE MAXIMUM IT
News
  • Chrome Now Open for Extension Uploads
  • iPhone Responsible for Half of All Mobile Traffic, Globally
  • Amazon Boosts Kindle Battery Life, Adds Native PDF Reader
  • Spam King Sentenced to 4 Years in the Slammer
  • BenQ and Fujitsu to Jump on E-Book Bandwagon
SEE MORE NEWS

New MSN Messenger Trojan Targets VNCs Too [updated]

Posted 11/19/07 at 09:37:25 PM  by Mark 'Marcus Soperus' Soper

comment Commentsprint Printemail EmailDeliciousDiggStumbleUponRedditFacebookSlashdot

eWeek reports that a new MSN Messenger Trojan is infecting hundreds of PCs per hour since it was launched yesterday. The speed of infection's a big concern, but what's even worse is how it works.

Double-Extension Blues

One of the methods this new IRC bot uses is the old double-extension trick: the Trojan executable disguises itself as a digital camera file such as DSC00452.jpg.exe. Users see the .jpg "extension" and figure all is well (some versions of this threat use a file called IMGxxxxxx.pif instead).

Trick Number Two: Contact Harvesting

The Trojan gathers contacts from infected PCs, and uses them to spread itself to new victims. In the best social-engineering tradition, users who are expecting to get a picture from a friend wind up getting infected instead.

[Corrected per updated eWeek article- see comment below]

Kicking It Up a Notch: Gunning for VNCs VMs

The infection and distribution techniques are all too familar, but the difference is that this Trojan isn't just gunning for physical PCs, but also for virtual network connections (VNCs). VNCs are widely used for remote support.machines (VMs). VMs are becoming very popular for hosting guest operating systems (Windows on MacOS, Vista on XP, etc.), in security appliances, and elsewhere.

Stop That Bot!

So, what can you do to stop this threat?

  • If you use MSN Messenger, don't assume that file attachments are actually being sent by an actual friend. Don't accept a file until you check with your contact.
  • Make sure your antivirus program checks IM file attachments for threats.
  • Suggest your friends using MSN Messenger switch to another IM client with better security.
  • If you use VNC connections, make sure you know who's on the other end of the connection.
  • And, finally, "think before you click."
COMMENTS:2
TAGS: Security, virus, malware, phishing, social engineering, threats
COMMENTS
  • Login or register to post comments
  • Technology News

  • Computer Cooling Fans

  • Computer Cases

  • PC Game Controllers

  • PC Games

  • Computer Hardware

  • Headphones

  • MP3 Players

  • Stream Video

  • Computer Mouse

  • Monitors

  • Motherboards

  • NAS Storage

  • Networking

  • Laptop Computers

  • DVD Burner

  • Digital Cameras

  • Portable Storage

  • Computer Accessories

  • Smartphone

  • Antivirus Software

  • Sound Cards

  • Speakers

  • Computer Systems

  • Thumb Drives

  • Video Cameras

  • Video Card Reviews

  • Water Cooling

  • Gadgets

  • Keyboards
  • Contact Us
  • Advertising
  • Privacy Policy
  • Terms & Conditions
  • RSS Feeds
  • TechBlips
  • PCHardwareBlips
  • Site Map
  • Customer Service
Future © 2009 Future US, Inc. All Rights Reserved.

Source URL: http://www.maximumpc.com/article/new_msn_messenger_trojan_targets_vms_too

Links:
[1] http://www.eweek.com/article2/0,1759,2218894,00.asp
[2] http://www.smith.edu/its/tara/smith_network/vnc.html
[3] http://www.maximumpc.com/article/think_before_you_click_on_that_great_job_offer
[4] http://www.maximumpc.com/article/safer_browsing
[5] http://www.maximumpc.com/article/How-To--Protect-Yourself-from-Phishing-and-Pharming
[6] http://www.neowin.net/news/main/07/11/19/new-msn-messenger-trojan-spreading-quickly