Shoutbox

New Virus posing as Live Messenger - Printable Version

-Shoutbox (https://shoutbox.menthix.net)
+-- Forum: MsgHelp Archive (/forumdisplay.php?fid=58)
+--- Forum: Skype & Technology (/forumdisplay.php?fid=9)
+---- Forum: Skype & Live Messenger (/forumdisplay.php?fid=10)
+----- Thread: New Virus posing as Live Messenger (/showthread.php?tid=54322)

New Virus posing as Live Messenger by wj on 12-28-2005 at 04:29 PM

quote:
Originally posted by Ars Technica

Windows Live Messenger is in all its glory right now. The application, currently in beta, is in hot demand by IMers everywhere. Since the only way to get into the program is through invitation, even eBay has capitalized on the program's demand by selling the rare invites. Now, a website called msgr8beta.com is capitalizing on the instant messaging program's popularity by delivering a virus disguised as the new beta.

The executable is named BETA8WEBINSTALL.EXE, and it installs a worm that will send invites to everyone on your buddy list, asking them to install via a link to msgr8beta.com. On the backside, the virus connects to a botnet server, which allows remote commands to be executed on infected PCs. F-Secure, the anti-virus company that discovered the worm, has named it "Virkel.F," which stems from its relative named "Kelvir."

The msgr8beta website was registered to a Mark Nicholas of Richmond, U.K. on December 24, 2005. There is a good chance that the site is registered under stolen contact information, but no word has surfaced yet.  Currently, I am not able to reach the site.  It was either taken down by the ISP or overloaded with traffic from people trying to download what they think is the new Messenger.  I'm inclined to go with the latter.

As things currently stand, the only way into the Windows Live Messenger program is through invitation, which can come from someone already involved in the program or from Microsoft directly. Microsoft has made no mention of when the program will be widely available.

RE: New Virus posing as Live Messenger by John Anderton on 12-28-2005 at 04:38 PM

absorbation already posted the exact same article a few days back ;)
But i think you might want to sticky it for some time or something :S
On second thought .... its not like the new users registering for asking invites will read that :-/


RE: New Virus posing as Live Messenger by absorbation on 12-28-2005 at 04:58 PM

Na this is new i still did post about it :P

Other Sources (a):

http://computerworld.com.sg/ShowPage.aspx?pagetyp...pubid=3&issueid=78
http://www.pcworld.com/news/article/0,aid,124087,00.asp
http://www.scmagazine.com/uk/news/article/533778/...n-messenger-users/
http://www.sda-asia.com/sda/news/psecom,id,6192,n...age,Singapore.html
http://www.techtree.com/techtree/jsp/article.jsp?...d=70062&cat_id=582
http://www.channelregister.co.uk/2005/12/28/messenger_virus/

Or my post: (cross referencing the sources)

quote:
Move over Santa Claus Worm and say hello to a huge new worm posing as MSN Messenger 8 beta leak or aka Windows Live Messenger, but called 8 purely for the benefit that people who know nothing about Live click the link.

So, what does this new worm do and why is it so dangerous? Well a website (msgr8beta.com) claimed to host a leaked version of MSN Messenger 8, which lured innocent people into downloading it, by announcing fake features that are sure to get more clicks to the lethal link, it claimed to include real-time smiles and functionality with Windows Media Player 10, of course, this is all a lie.

In reality a worm is installed called "Virkel.F" and spreads to all your Messenger contacts, which you really do not want to get the blame for trust me, burpia (an older, famous worm last year) caused a lot of arguments all around the world by disabling the internet, flashing pornographic images and switching your mouse clicks randomly.

The worm surprisingly is not brand new what so ever but a variant of an older family of IM viruses named "Kelvi". Which source code was posted thus making many coders taking an easy advantage for writing a worm.

The domain, has now been blocked and confirmed to be registered on December 24th by "Mark Nicholas," of Richmond, U.K” however attempts to contact this person were not successful and they may not exist, that being said the worm can still spread via contact by contact so the hype is not yet over.

Remember do not accept anything from your contacts unless your are 100% sure what it is.

RE: New Virus posing as Live Messenger by John Anderton on 12-28-2005 at 05:23 PM

I read the same exact thing on http://msgstuff.com and remembered something about the new virus so i thought you posted it :P


RE: New Virus posing as Live Messenger by absorbation on 12-28-2005 at 05:28 PM

quote:
Originally posted by John Anderton
I read the same exact thing on http://msgstuff.com and remembered something about the new virus so i thought you posted it :P

yeh is easy to get confused by :P two big worms in a week let's hope it's not a repeat of burpia.
RE: New Virus posing as Live Messenger by CookieRevised on 12-28-2005 at 06:18 PM

Goes to show why it is oh so important to only download stuff from official sites!

(and why it is so important to link to official homepages in posts, instead of giving direct download links to some program located on some random server)


RE: New Virus posing as Live Messenger by waters on 01-13-2006 at 11:51 PM

yeah prity much read one site and the other will have the same info just riped from that site! but then again some times inside info gets out and doesnt make it far so i guess we still got to read 1000s of article to get the news updates we need :)

but i hope they kill the vires befor the offical release comes out (but then again its microsoft) ((and but the way from that comment i say sorry to any one who takes offinces to that))

but yeah i guess we will never stop virses ever but eh its fun to kill them but lol


RE: New Virus posing as Live Messenger by nader_group on 03-22-2006 at 12:36 PM

[b]thanke you


RE: New Virus posing as Live Messenger by hikarii on 03-26-2006 at 02:41 PM

It is sad how people always make use of new products or softwares on hot demand to create some malicious virii and harm the generall computing society.

[Quote=dwerg of mess.be]Watch out for fake versions of Messenger Plus! Live currently circulating on forums, filesharing software and sites like Rapidshare. According to reports, a certain file named MsgPlusLive 4.0.2006.0566 is nothing more than a virus with destructive effects on your contact list. UPDATE: The fake also goes by several other names (including MSGPlus Live 4.06.03.21 Patchou Edition).[/Quote]I happen to come by this news and in the same way, I feel sad for the sadistic virii creator making use of the general msgplus! users' interests into scamming them to downloading a virus.

Well, better be cautious..


RE: New Virus posing as Live Messenger by ThunderStorm on 03-26-2006 at 02:46 PM

People they download WLM on untruested site's, they have a much chance for a virus.
Download WLM from the official site!


RE: New Virus posing as Live Messenger by joeh205 on 03-29-2006 at 07:44 PM

lol don't even bother with WLM im in the beta and i went back to 7.5

if you do want it goto http://ideas.live.com


RE: New Virus posing as Live Messenger by Lou on 04-02-2006 at 02:29 AM

quote:
Originally posted by joeh205
lol don't even bother with WLM im in the beta and i went back to 7.5

if you do want it goto http://ideas.live.com
Everyone here knows by now.
quote:
Originally posted by ThunderStorm
People they download WLM on untruested site's, they have a much chance for a virus.
Download WLM from the official site!
That post was hard to read, and what I gathered from it, has already been posted.
quote:
Originally posted by nader_group
[b]thanke you
You're welcome.

As well wj I hate to break it to you but...  Chris Boulton warns about this forum not being a news syndication forum (a)
RE: New Virus posing as Live Messenger by deathadderpt on 05-16-2006 at 07:59 AM

Hi

I live in portugal and in a magazine i view an adress to download msg plus live  but the link doesnīt work i donīt know if works in the past.  Could this link be the virus you are all talking about?  its a famous magazine here.