Using
Avast Pro 5
Program Version : 5.0.462
Virus definitions version: 100325-0
Symptom:
Every time the infected PC turned on yahoo messengers, it will start sending message to all her ym friends
one of this message:
CAUTION THE LINK BELOW IS A VIRUS, DO NOT DOWNLOAD AND EXECUTE
Have you ever seen me drunk before? Someone snapped a pic last night at the party. hxxp://www2.hostingpics4free.com:88/uploads/zij248afd/DSV-PartyPicture028.JPG.zip
- I just found this pic of you last night, and I think you might want to save it, looks amazing. srv034.imageshares.info:88/cache/user2940/DVS-Picture009.JPEG.zip
- Would you care if I tagged you in this picture? Or would you get upset at me? srv057.imageshares.info:88/DisplayPics/user3052/DVT-NewPhoto009.JPG.zip
- This picture is creepy and disturbing! You have to check it out. hxxp://srv034.imageshares.info:88/cache/user2940/DVS-Picture009.JPEG.zip
- I was at the mail, and you will never guess who i saw! hxxp://srv057.imageshares.info:88/DisplayPics/user3052/DVT-NewPhoto009.JPG.zip
- I found the perfect wallpaper. You’ll love it, what do you think? hxxp://viewmorepics.facebookgallery.info:88/ImageView&profileID=1390/DVS-MyPhoto14.JPEG.zip
- Have you seen my new glasses? I just found out I had to get new ones. Do they look ok?? hxxp://viewmorepics.facebookgallery.info:88/ImageView&profileID=1390/DVS-MyPhoto14.JPEG.zip
- Why do I even bother taking pictures when they turn out to be like this. Don’t show it to anyone please. hxxp://img284.dlimageshack.info:88/img284/43930/MVC-NewPhoto12.JPG.zip
- I finished editing this picture last night for my facebook profile… How do you like it? hxxp://img425.dlimageshack.info:88/~ProfileView/user4729/DVS-NewPhoto13.JPG.zip
- The pics from my new digital camera keep coming out strange. Can’t you tell it doesn’t look right in this one? hxxp://c2ac-b.myspace-pics.info:88/images03/4986051/DVT-Picture004.JPG.ZIP
- If you decide to open this picture you have to promise not to show it to anyone. ok? hxxp://c2ac-b.myspace-pics.info:88/images03/4986051/DVT-Picture004.JPG.zip
CAUTION THE LINK ABOVE IS A VIRUS, DO NOT DOWNLOAD AND EXECUTE
Infected PC will do :
- Attempting to connect / contacts to a remote server / IRC (Internet Relay Chat) with a variety of IP.
- Attempting to connect to several websites and try to synchronize the time.
- Attempting to connect to some websites Mail Exchanger (MX). Including Microsoft.com, Yahoo.com, Google.com and Mail.Ru (service provider free e-mail the largest in Russia)
- Attempting to connect to some websites using a variety of ports.
- Synchronize to remote server / IRC server and communicate.
- Downloading a file virus and a list of messages to be sent via the chat application. One link can get up to 50 different messages sentences.
- ends a message to all existing contact address at the chat application.
- Trying to access the network and spreading the virus. In this case even try to get through IPC $.
Its been spreading through Yahoo messenger since january 2010, though it not confirmed yet that it can spread through Skype, GTalk (Google Talk), Windows Live Messenger and MRA (Mail.Ru Agent).