FirefoxRocks
May 13 2007, 04:44 PM
Have you ever gotten a message from your friends that say something like this: its you on this photo http://uglyhuman.net/photo***.phpI have received that from at least 3 people. Without knowing what it was (and the surprise from the domain name with the message  ), I clicked on the link and Firefox prompted me to download a file. It was a COM file so I thought that was strange. I rechecked the URL it was a PHP web page, so I assumed it was telling me to download the photo, so I opened it in Firefox. Windows Live OneCare prompted me that Windows Live Messenger was about to run (with something that said updated program or something similar). I found that strange so therefore I clicked on Block this Program. So after my next reboot, Windows Live OneCare said that it still blocked Windows Live Messenger. I assumed it was now safe to run Windows Live Messenger now, so I clicked the option to allow, closed Windows Live OneCare and opened Windows Live Messenger. Boy was I wrong! The virus started opening up windows of both online and offline people and started sending that message to them. It opened and closed windows so much that it was impossible to use ALT+TAB, ALT+F4 or even bring up Task Manager. I unplugged the cable from my Internet modem and Windows Live Messenger disconnected. I quit the program then looked on Firefox to see if there was any instructions to remove this. The only results that come up were; Yahoo! Answers - Weird Virus (no one got the answer there) TechGuy Forums - Security (it was suggested to use HijackThis, but it didn't help) So the virus isn't even in the definitions yet but it is spreading among buddies quite quickly. For the domain name, uglyhuman.net, McAfee SiteAdvisor has no rating for it. It would definitely be red for sure. The virus isn't a running process, I couldn't find it in Task Manager or Process Log. However (not sure if the virus caused this), my explorer.exe process ended abruptly and had to restart a few times. Now I am stuck in Ubuntu (Linux) on a Live CD and OpenOffice.org really slowly (I need Microsoft Word). Anyone have suggestions to get rid of the virus? It isn't a running/startup process, it operates within Windows Live Messenger. Do I need to reinstall Windows XP? 
Reply
mvs.en
May 13 2007, 05:35 PM
I wish I had something constructive to say... I don't mean to sound rude, but I wasn't stupid enough to fall for it. XD I apologize for the implication regarding your intelligence there. Anyway People have been sending me that thing for months now... I never click or open things from anyone on MSN unless they've told me they were sending it or I question them about it when it comes out of no where (This pretty much eliminates the whole... Automated MSN Messages to transmit viruses) That, and the first person who sent it to me was someone I hadn't talked to in like a year anda half so them suddenly popping up with this link was... Well, I've seen viruses like it before so I wasn't quite that clueless. I dunno, I wish there was something I could say to help, but I have very, very little experience with any sort of virus... I don't think I've had any noticeable viruses on mycomputer in years... Which is strange, since I'm on windows and have every possible security measure turned off. Ah well I'll tell you if I find anything out about the virus/how to repair it and stuff.
Reply
FirefoxRocks
May 13 2007, 07:23 PM
Turns out that the virus did damage explorer.exe. It won't even start in safe mode. I still can use the computer, just without the taskbar and desktop. I run stuff through Task Manager. I can start a lot there, but it is annoying. Dell told me to reinstall Windows XP (I don't have system restore points), which I am doing. My files are now done backing up. But please do contribute more information about this virus, I would like to know more about it.
Reply
pyost
May 13 2007, 08:22 PM
Strangely, I haven't received this message yet. I say "strangely" because it is common practice to get "Click this link" messages. To make matters worse, minutes after getting it from one contact, it is highly probable that you'll receive it a few more times  It's sad how people aren't cautious enough, especially Internet users. Thankfully, English is not my mother tongue, so receiving these messages always makes me suspicious
Reply
mvs.en
May 13 2007, 08:29 PM
QUOTE(pyost @ May 13 2007, 05:22 PM)  Strangely, I haven't received this message yet. I say "strangely" because it is common practice to get "Click this link" messages. To make matters worse, minutes after getting it from one contact, it is highly probable that you'll receive it a few more times  It's sad how people aren't cautious enough, especially Internet users. Thankfully, English is not my mother tongue, so receiving these messages always makes me suspicious  Yeah English is my only tongue but... It's still pretty easy to tell if it's a virus or not... If you're like me at all, after talknig to people a little while you can pretty much get to know their typing style... My typing style is usually pretty recognizeable, I put crazy spacing between/in the middle of my sentences to indicate pauses... Like... Enter-hitting-spaces... I also have a strang attraction to ellipsises <__< Anyway... I just thought I'd add that, it's easy to tell something isn't right when you get a message from someone that you can right away tell isn't really them who typed it... And what's this? THere's a link with the message to boot!
Reply
Grafitti
May 14 2007, 08:24 AM
Plus, aren't COM, EXE, and PIF the most common types of virus files? That should set off a red flag whenever you see one. Have you tried using something like ERD commander to access windows? You can run a system file repair.... and then deleting MSN, run a regcleaner and get rid of anything you find from MSN Messenger. It might be a running/startup process, because you say that your explorer.exe crashed several times. or did you open MSN and then it started crashing? Edit: On this forum they seem to have successfully gotten rid of it: http://www.bleepingcomputer.com/forums/topic91879.html
Reply
ethergeek
May 14 2007, 04:49 PM
I love reading about viruses...it reminds me of how happy I am that I run Linux.
Reply
kgd2006
May 14 2007, 10:46 PM
I rarely use msn as my communication tool of choice because it seems lately that microsoft is the target of most of the attacks. Although other programs that I occasionally use is AIM is also a target of virus attacks, I just do the common sense thing that was mentioned in posts above, which is question the file that is being sent so that you would get bit by the internet spider. If your friend questions it himself then cleary its a virus trying to trick you into clicking and downloading some spyware or keylogger onto your computer system. The internet may be the very source of good information and a haven for many people, but it is also a burden of hell when there are people out there that is trying to use the internet for there own evil purposes. But if you are pretty cautious and well informed of the type of virus attacks that are going on out there you are very unlikely to get bit by them. The ones that usually and occasionally get attacked are those that are not so computer literate so to say. That would be the source of the contagious infection of viruses, those that dont know what just popped on their screen and is curious to find out what it is. If people are more well informed of what type of viruses are out there viruses would not be much of a problem other than a nuisance on the internet, but there is always a very curious person to fall for their traps. Im saying this in the general sense, because I know that viruses now are harder to detect and can be very very sneaky when it comes to attacking your system. But if you avoid areas such as porn sites, p2p, or any places that you normally wouldnt go to that isnt official, you should be more than safe.
Reply
hazemmostafa
May 14 2007, 11:47 PM
Hello everyone , I am not involved in virus and exploits analysis or so , I was hardly tring to understand the trojans and how they work and never complete this course although my teacher is one of the world famous experts in the field her nickname is fruitloop and she is irc oper / server admin you may check her website http://www.fruitloop.net/virushelp/ ... I hear that most of the good hackers are now up to hacking unix source code and they are very proud about that so only you mention windows in front of them and they will start laughing and say it is for script kiddies and not for us I was very happy hearing this and thought windows is going to more safe for at least a couple of years .. Which is like a dream to windows users . Frankly I am a windows user sience windows 95 and every time microsoft introduce a newer version to the computer world I find some expert talking about the holes and security issues in this new version , then these tweaker programs show explaining how they can close ports and fix security problems to windows user - Also hide/show resycle bin Dont now why ?  - now some guys said norton is not good and processor consumer go get kaspersky or avg or nod whatever So all linux users are safe with no -as windows - software available and ugly command write /bin/user/*** ( who's bin ? ) and all windows users are not safe forever no matter how nice/easy xp/vista looks .
Reply
FirefoxRocks
May 16 2007, 01:12 AM
The virus created 2 files in my user account stuff, golgi.exe and ra*.exe. I thought EXE and PIF were the dangerous executables, but I didn't know what COM was, I assumed it was Component Object Model which is used by Internet Explorer to display stuff (I think), and the site was IE-compatible. I find it strange that the virus has been around for so long and that no anti-virus company has any information about it.
Reply
Latest Entries
xboxrulz
Jul 30 2007, 04:08 AM
You can simply still access your Hotmail box by using another web browser like Firefox or Opera. It won't download anything unless you authorized it to do so. xboxrulz
Reply
mitchellmckain
Jul 28 2007, 12:32 PM
QUOTE(mitchellmckain @ Jul 26 2007, 10:20 PM)  Starting today, going to the inbox of my hotmail email account triggers the download of program that avast identifies as a virus. Of course I click on the disconnect to stop the download. This means my hotmail account is inaccessible however. Well either hotmail or avast has apparently fixed the problem. I would guess that the problem was at the hotmail site since I do not recall there being an avast update since I had the problem.
Reply
kgd2006
Jul 28 2007, 07:00 AM
Its common practice and if you are a frequent user you should know that clicking random links from people you dont know is very bad. And should be avoided at all times. I am very cautious when it comes to clicking links from even my freinds, I ask them what this link is before I click it because I hear many occurences of how viruses are passed through messengers and how it deals damage to your computer that results in making you reformat your computer. But from your experience Im sure you will probably be more cautious the next time around, and its good that you made this post. Because for those that dont already know that is being passed around the internet these days would know now and will eventually get to them as a caution.
Reply
mitchellmckain
Jul 27 2007, 04:20 AM
I have a problem that I suspect might be related to this virus. Starting today, going to the inbox of my hotmail email account triggers the download of program that avast identifies as a virus. Of course I click on the disconnect to stop the download. This means my hotmail account is inaccessible however. Unfortunately I do not have much substantial evidence to present that this is the same virus/worm because soon I cannot go to the hotmail site at all presumably because avast is blocking it. Nor did I write everything down that occured but I think that the word "photo" popped up somewhere along the line. Here is the Avast warning log entry 7/26/2007 9:20:14 PM SYSTEM 112 Sign of "VBS:Malware [Script]" has been found in "http://by131fd.bay131.hotmail.msn.com/cgi-bin/HoTMaiL?&curmbox=00000000%2d0000%2d0000%2d0000%2d000000000001&a=f11cb5f006346f7a3c2e80bee020e37d5ed1575d992867657fd49a174e522f15" file.
Reply
Chesso
Jul 10 2007, 07:48 AM
Yeah I haven't copped any of these messages recently, although I do somewhat remember getting a link from someone saying it was me, but I don't know if it was related to this or not.
Reply
Recent Queries:--
"t.com.exe" - 8.68 hr back. (1)
-
msn random group chat windows virus - 16.14 hr back. (1)
-
uglyhuman - 77.94 hr back. (1)
-
how do i fix a worm virus in msn? - 89.96 hr back. (3)
-
the reason for the apperance of new viruses - 122.00 hr back. (1)
-
how to deal with latest rontok win32 virus - 150.23 hr back. (1)
-
msn new computer virus alerts - 160.42 hr back. (1)
-
mac msn viruses - 174.40 hr back. (1)
-
msn virus mac? - 229.83 hr back. (1)
-
mac msn link virus firefox - 244.49 hr back. (1)
-
"component object model" wlm - 279.19 hr back. (1)
-
new msn virus starts norton from nowhere - 282.53 hr back. (1)
-
how to get random people to stop sending msn viruses - 311.62 hr back. (1)
-
how to get rid of msn virus on mac - 323.19 hr back. (1)
Similar Topics
Keywords : virus, uglyhuman, msn, virus, worm, isnt, virus, definitions,
- Some Weird Virus
(8)
Storm Worm Adds Millions Of Computers To Botnet
(0) The storm worm has built a botnet of perhaps as many as 10 million PCs using a revolving strategy of
current events and eye-grabbing "headlines" to lure victims into what may be the single largest
operating botnet. http://arstechnica.com/news.ars/post/20070...-to-botnet.html ....
Yahoo Group Worm
Worm infecting Yahoo Group users through attachment. (7) Those of you who use Yahoo Groups may or may not have already heard this, but about three days ago,
I received an update from one of the groups I am a member of. Inside this notice I found two "New
Graphic Site" messages and one "Virus Warning". The previous two came with attachments. Luckily, I
read the virus warning first before opening them. In the virus warning was this piece of advice:
QUOTE Just a quick warning to members about a virus that is sweeping Yahoo groups. It contains a
number of attachments and the subject line reads "New Graphic Site". Don....
MSN "Thank You For Using" And Sharing
AN MSN virus ? (17) MSN now opens a window where wee see things happening : It starts a frame with with the words Virus
- (1513 kB) Then it says "scanning C disk" Then "installing" Then "propagating" Then it ends with
"Thank you for usin' and sharin'" What is that thing ? Is it a fake ? Or is it a ral virus ?
I must confess I'm a little bit afraid. A goggling made me find a german site saying roughly
"probably a fake". However, even if it's a fake, it behaves like a trojan because it's a
program residing on your computer and activated evrytime you open a new window. If....
My Windows Isn't Genuine?
(16) Ugggg, I just found out (from my computer!) that my Operating System (XP Pro) isn't
genuine /mad.gif" style="vertical-align:middle" emoid=":angry:" border="0" alt="mad.gif" /> I
got a great deal on a used computer from a Swap Meet a few months ago. Will Microsoft accept a
letter or something, along with a little toy cash register receipt and give me a license key, or
will I have to buy a new copy? Dang, I should have known better, from now on, I'm building my
own systems (I've been studying!) ....
Quick Virus Question
(4) I've always have run a tight ship so I very rarely get a virus, but I've got a client who
has somehow managed to get some sort of mailer Trojan horse on their computer HOWEVER, Norton
Antivirus has the virus isolated and ready for removal. From the instruction sheet (I'm
assuming they got it from Symantec), they updated Norton and did a full system scan. The virus
shouldn't do anything since Norton has it quaritined, correct? Now, it may have injected values
into the Registry (which is why they want me to do it as they don't know what the registry ....
Asta Worm ALERT: Exploit.Win32.WMF-PFV Trying To Infect
(4) WARNING: To all members While browsing the forums, you might face a strange pop-up asking
you to download a .wmv file. DO NOT download and/or try to play this. The pop-up looks somewhat like
this (provided by Dha: I believe this is being spread through one of the Ads displayed at Asta.
Some guy has this worm embedded in his ads - that's the only logical explanation I can find..
Different anti-virus might identify it with different names - but essentially, it's a variant of
the following worm. Most likely it's coming from an ad of taalkzforum.....
Very Easy But Very Dangerous Virus
(15) QUOTE The only thing you need is Notepad . Now, to test it, create a textfile called
TEST.txt(empty) in C:\ Now in your notepad type "erase C:\TEST.txt" (without the
quotes). Then do "Save As..." and save it as "Test.cmd". Now run the file
"Test.cmd" and go to C:\ and you'll see your Test.txt is gone. Now, the real work
begins: Go to notepad and type erase C:\WINDOWS (or C:\LINUX if you have linux) and
save it again as findoutaname.cmd. Now DON'T run the file or you'll lose your WINDOWS map....
Locally Virus From Indonesia
(3) Does anyone know or better infected and succesfully cleaned the virus called as rontok.bro, it's
came from Indonesia as well and has made many variant. Please help me I was infected. regards
/ohmy.gif" style="vertical-align:middle" emoid=":o" border="0" alt="ohmy.gif" />....
Lol MS Excel Is/Was A Virus
(10) Thanks to a McAfee update the users was warned by them that Microsoft Excel is a Virus. Last Mars,
10 2006 Microsoft Excel was pointed as W95/CTX Virus. This mistake happened because an error
accoured with the new definitions sent to users. McAfee solved the problem a few hours later,
thanks to the complains sent by a large group of McAfee Clients. LOL, I thinks is Funny , LOL....
Virus For Mac Arrives!
(18) The first virus for Macs has appeared on the scene. Known as Leap - A, it is a low level threat,
but almost certainly the harbinger of future threats. For years, Mac users have claimed the o/s to
be safe and secure, with no virus problems, even 'tho the reason for that was simply because of
the small amount of users, not the difficulty of creating a virus for the o/s. Now, as with
Firefox, as the number of users grows, so the creators of virus , malware etc will begin to target
the Mac. ....
Files Recovery Overwritten By Blackmail Worm
Files recovery overwritten by Blackmail (1) I have an HDD 40 GB all of its MS Word, excel and PP files and Acrobat Reader files have been
overwritten by the Blackmail Worm on 3rd Feb 2006.. Any suggestions for recovery the overwritten
files....
Feb Virus Warning!
Feb Virus Warning!!! (1) There were a couple of Virus warnings released by Major Anti Virus manufacturers regarding the
outbreak of Two (or are they the same??) worms. One is the Black Worm and other is the 'Kama
Sutra' virus....... QUOTE It has been observed that the Black Worm also known as W32.Vb.i
or W32.Nayem.E has been actively spreading in India since last two weeks now. It’s a mass-mailing
worm that also spread using remote shares. After a long gap there has been an outbreak kind of
situation as this worm was successful in spreading all over the globe within few hours when....
Sober Virus Plummets
(0) QUOTE The latest Sober virus (known as W32.Sober.X@mm, Sober.Y and W32/Sober@MM!M681) has
passed its January deadline for updates without incident. The Sober virus and its variants have
been one of the most prolific of 2005 and has topped the charts again in recent months. In early
December, anti-virus vendors cracked the algorithm the virus uses to search for updates, allowing
the next set of Web sites to be blocked and Web hosting companies to be notified. The virus was set
to search for updates from thirty unique websites, fifteen each on January 5th and Janu....
AOL Instant Messenger Chain Virus
Has anyone else been hit by this? (12) yesterday, i was chatting with a friend and she sent me a link to what looked like a photo file...
when i opened it, it turned out to be a virus... which in turn, automatically messaged all the
people online on my buddy list the link and then closed all chat windows..... does anyone know what
this is? and if so, how do i fix it?....
Worm Found In Zen Neeons?
(4) I do not wish to copy the whole article so I'll post the link and summarize it here:
http://www.pcmag.com/article2/0,1895,1854769,00.asp PC magazine has reported that Creative's
Zen Neeon released from a company factory in late July contained a Windows Worm. The name is
W32.Wullik.B Although this worm itself is not exactly harmful, it is proven that worms and viruses
can now be transfered and hacked through company mainframes. This a serious problem because it could
pose a threat to future developments. More hackers would try to modify the worm or create thei....
How To Know If You Have A Virus Or Trojan/spyware
(2) How to know if you have a virus or trojan or spyware in xp open task manager by presing ctrl+alt+del
an close all applacations now look at your cpu usage if it is above 4-5% you have a problem.
/smile.gif' border='0' style='vertical-align:middle' alt='smile.gif' /> ....
Worm Alert - W32.zotob.a
new worm to hit Windows PCs (8) A new worm has been detected by multiple antivirus and security specialists. It's called ZOTOB
and is exploiting security holes that have been earlier highlighted in Microsoft Security Bulletin
MS05-039 . The worm affects Win2000 systems and newer. Win 98, ME etc. are not currently thought to
be at risk although, one must always keep the holes plugged. Details regarding what it does exactly
and removal instructions can be found at Symantec's site and also at Microsoft's ZOTOB
Advisory page The hole allowing Zotob to infect and spread can be fixed by i....
Cws Also Being Used For Identity Theft
Spyware isn't a good thing (1) Here's one more reason to be on the lookout that you don't get infected by CWS . At last
count there were well over 50 variants loose in the wild! Sunbelt is a software company that
makes the well known anti-spyware called CounterSpy. While investigating a new mutation of the
CoolWebSearch trojan, a Sunbelt researcher was astounded to discover that it was being used for
identity theft. All manner of personal information is being uploaded to a publicly-viewable web
server, including eBay passwords, Paypal passwords and passwords for bank accounts worth ....
Music Video Web Site W/ Virus
(3) If you are looking to put a music video in your MySpace or what ever you choose avoid using the
site www.musicfeet.com This web site gives you a Trojan virus each time you access this site.
So if you have a good virus scan and firewall dont go there ....
Click To See Which Anti-virus Is The Best
(7) Well, i didn't invent this. I saw this ranking in other sites and I conducted a survey by
myself. Here is the ranking: 1. NOD32. 2. Kapersky Anti-Virus. 3. Norton Anti-Virus. 4. Other free
software. Well, hoped this helped /smile.gif' border='0' style='vertical-align:middle'
alt='smile.gif' /> ....
Ranking Virus
(4) According to TrendMicro NETSKY was the most affective virus of June here the ranking 1.
Worm_Netsky.P 2. HTML_Netsky.P 3. Java_Bytever.A 4. Worm_Sober.S 5. TSPY_Small.SN 6. SPYM_Gator 7.
SPYM_Dashbar.300 8. Troj_Dyfuca.I 9. Worm_Netsky.D 10. SPYW_Websearch.A....
Aim Virus Messing Around With My C:\windows Folder
(10) Okay, so I was talking to my friend on IM yesterday and then she sends me a message saying OMFG LOOK
AT HER or something like that and then a link. I stupidly opened it and then two seconds later she
IMs me telling me not to cause it seems to be a virus. Usually I don't accept those kind of
things but it was from her so I let my guard down. Apparently she had got it from another one of her
friends. It's a .pif virus I know that much but it doesn't do much, I can still open AIM
and my task manager with no weird things but when I reboot my computer, my C: ....
Virus Alert (hoax)
(6) Recently a new virus was discovered that was classified by MICROSOFT www.microsoft.com and by MCAFEE
www.mcafee.com to be the most damaging of all time! This virus was discovered by MCAFEE and
still there is no development of a vaccine! This virus simply writes zeros on the hard drive,
where the vital information for the operation of the PC is kept. The virus activates in the
following manner: 1. By email it is received with the title 'A VIRTUAL CARD FOR YOU', when
opening the message, it sends itself to all in the address list soon... 2. It hangs th....
New Version : Virus Sober Q
What's rong with internet ? (1) This new Virus Sober.Q is automaticly loaded by the computer from prevoius versions of Sober.Virus .
this virus manifest him self in germany and works like a SPAM , that it's not a spam by default
but he can be in few time. Protect your self :::: Cheers ! Update you Anti-Virus....
New Aim Virus - I Think
(4) Today, my friend, who almost never messages me, sent me a message saying "look at my pictures "
Now, my computer-whiz friend is always joking about things like this, saying, "Hey, check out my
cool pictures from the beach." So, I was sort of cautious. I sent him a message back saying,
".pif?? What is that??" And I started to Google it, but I decided to open it anyway since he
wasn't responding. So, it was supposed to message everyone on my buddy list, but I don't
think it did. Just in case, I messaged everyone and said, "Don't open anything I send you.....
New Sober Virus
(4) The Trend Micron launched alert on the appearance of a new version of the celebrity virus Sober,
arriving of this form at the variant S and that already it received the classification from being as
a threat of average risk. This plague, is to spread quickly in Germany and the United States, and
dissimulates to be an official message of the FIFA on the championship of World to carry through in
2006 in Germany. The contaminated email arrives at the user with an annexed malicious
filing-cabinet where it is promised as being carrying of information on the Championship of t....
Worm Nopir-b - Delete Mp3 Files
watch out ! (0) The Worm Nopir-B spreads in nets of allotment of filing-cabinets (P2P) and erases MP3. according to
British company, Sophos, the Nopir-B will have been created in France. The invader is offered as
being a tool to copy DVD. When executed, it shows an image with messages against the piracy and
tries to erase all the joined filing-cabinets mp3 in the computer. The desactiva Nopir also
utilitarian of the operative system as the access to the Manager of Tasks, the Panel of Control and
the Register. ....
Worm Sober It's Back
(3) It comes by email watch out this little ******f*cker You may receive an email with this subject :
"I've got your e-mail on my account" . Inside there are this file : Your_text.zip DONT OPEN
This Virus affects all the Operative Systems Take care....
Avast!
Free anti-virus software! (12) hey, i got avast! since a few days, it's a free anti-virussoftware. it protects against
computer viruses, worms and trojan horses. it's free, as long as it's for personal use. if
you want it for your company, you gotta pay. it's up-to-date, because it's updated
regularly. the newest version is 4.6 you can download it & find more information here:
http://www.avast.com/ ....
Looking for virus, uglyhuman, msn, virus, worm, isnt, virus, definitions,
|
|
Searching Video's for virus, uglyhuman, msn, virus, worm, isnt, virus, definitions,
|
advertisement
|
|