LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-05-2005, 08:33 AM   #1
Ephracis
Senior Member
 
Registered: Sep 2004
Location: Sweden
Distribution: Ubuntu, Debian
Posts: 1,109

Rep: Reputation: 50
MSN Virus


I keep getting messages on MSN from people saying:

(note: it seems strange that swedish people on my list would write in english to me)

I checked out the url and firefox asks me if I want to download the binary file unknown@hotmail.com from ravo.adamg.cc.

Just wondering if anyone has heard of this, because I searched at google but did not find much. I thought that I may be a virus, but I would like some info on it.
 
Old 05-05-2005, 08:38 AM   #2
trevelluk
Member
 
Registered: Nov 2003
Location: Bristol, UK
Distribution: Debian Lenny, Gentoo (at work)
Posts: 388

Rep: Reputation: 32
It sounds like it might be some sort of virus or other nasty. I suspect that if you were on Windows and using the offical Messenger client and Internet Explorer, you would have been in trouble.
 
Old 05-05-2005, 08:50 AM   #3
frob23
Senior Member
 
Registered: Jan 2004
Location: Roughly 29.467N / 81.206W
Distribution: OpenBSD, Debian, FreeBSD
Posts: 1,450

Rep: Reputation: 48
http://www.trendmicro.com/vinfo/viru...LVIR.Y&VSect=T

This looks like the following worm (or a variant of it). The binary file you would have downloaded has instructions in it to install a RAR extractor (if you don't have one) and extract a rar contained in the file. It could have been doing other stuff as well -- I'm not on a Windows machine and have little experience breaking down stuff like this (nor did I spend much time investigating this fully). The RAR appears to contain that worm... which would have your client sending out the same message to people all the time.

Last edited by frob23; 05-05-2005 at 08:52 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
virus phoenix7 Linux - Security 4 02-22-2005 05:07 AM
Boot virus or Anti-Virus? AVG Free Anti-Virus Software problems SparceMatrix Linux - Security 9 08-02-2004 02:35 PM
trend chipway virus detected boot virus rafc Linux - Security 1 05-13-2004 01:44 AM
MSN to break Linux connection used with msn I think read maximalred Linux - General 1 08-24-2003 12:40 PM
CAN WINE be made to run MSN 8 and MSN Messager maximalred Linux - Software 3 08-24-2003 07:56 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:01 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration