Ezud.com - Trolling Assistance Forum

Ezud.com - Trolling Assistance Forum (http://ezud.com/forum/index.php)
-   Ezud Discussion (http://ezud.com/forum/forumdisplay.php?f=5)
-   -   Trojan Going around on MSN (http://ezud.com/forum/showthread.php?t=3122)

Lust 11-22-2008 03:42 PM

Trojan Going around on MSN
 
DELETE SERVICE.EXE

There is a new trojan going around on MSN that has hit about 11 Ezud Members so far.

The virus in question is sent like this:
Quote:

haha lol
http://msncams.ohost.de/play.php?=yourmsnadress
Quote:

is this you?
http://msncams.ohost.de/play.php?=yourmsnadress
where yourmsnaddress is your email.

DO NOT GO TO THIS LINK, it takes you to a site that loads a Java Applet which downloads files to your computer. My Nod32 detected it, and I downloaded the files and uploaded to 4 virus scan sites so that it could become detected.

DELETE SERVICE.EXE IF YOU HAVE THIS!!!

Mezala 11-22-2008 03:45 PM

yeah its becoming REALLY bad...Also the ones that like sign off 1 second after they say that piss me off

EDIT: 2 SECONDS AFTER I WROTE THIS

[15:45] [Ezud.com]Avenger.: haha lol http://msncams.ohost.de/[email protected]

EndOfStory? 11-22-2008 03:47 PM

Yeah, Ben has this. Thanks for the warning.

EDIT: Ah, you already know :D

EDIT2: Wait a sec, I followed that link but declined the download?

Gah i hope i'm not infected

Svew 11-22-2008 03:49 PM

lildude is going around trying to use it on people

DeadOwnage 11-22-2008 03:58 PM

Rofl i havent been on msn at all today luckly.

:0 Thanks for the info =rep

-DeadOwnage

EskimoANM 11-22-2008 04:10 PM

Quote:

Originally Posted by DeadOwnage (Post 31746)
Rofl i havent been on msn at all today luckly.

:0 Thanks for the info =rep

-DeadOwnage

Same here, i barely go on MSN.

Thanks for the warning Lust, much appreciated.

Lust 11-22-2008 04:15 PM

Quote:

Originally Posted by EndOfStory? (Post 31733)
Yeah, Ben has this. Thanks for the warning.

EDIT: Ah, you already know :D

EDIT2: Wait a sec, I followed that link but declined the download?

You probably still have it, Nod32 disconnected me before I even got a download.

Lust 11-22-2008 04:25 PM

Quote:

Originally Posted by Beitsafafa (Post 31734)
yeah its becoming REALLY bad...Also the ones that like sign off 1 second after they say that piss me off

Those are phishers, they aren't as bad as an actual virus.

Avenger 11-22-2008 04:40 PM

I got my computer infected, and I infected about all my friends xD

juvenilepunk 11-22-2008 04:42 PM

thanks for the warning ill keep a look out.

Dorito 11-22-2008 05:07 PM

Yes, it uses an exploit that is currently unfixed at the moment, hopefully there will be some security patches released soon enough and/or updates to certain software that allow the exploit to run.

BrokenSoul 11-22-2008 07:11 PM

Ben has sent me like 20 messages with this. LUCKLY I never clicked on them. I thought something was funny. but meh

Robin Hood 11-22-2008 07:16 PM

who started this? and whoever did = TEHBANNAHAMMA

Lust 11-22-2008 07:33 PM

Quote:

Originally Posted by Robin Hood (Post 31771)
who started this? and whoever did = TEHBANNAHAMMA

It doesn't necessarily have to be someone on this forum. Ben could have run an .exe from some site or got it from someone on his list.

The website has now been shutdown, but those that are infected are still in the botnet, and may be used to spread some other time.

Taylor 11-22-2008 08:02 PM

I'm 94% sure these are botnets... I know this is how you would go about connecting someone to your botnet.

Edit: Didn't read all the posts.

But yeah, if anyone sends you a link to a Java applet you don't know, don't accept it.

Lust 11-22-2008 09:13 PM

Quote:

Originally Posted by Taylor (Post 31784)
I'm 94% sure these are botnets... I know this is how you would go about connecting someone to your botnet.

Edit: Didn't read all the posts.

But yeah, if anyone sends you a link to a Java applet you don't know, don't accept it

You didn't read, it's an exploit for arbitrary file download(download without having to accept the sign.)

Sanjuro 11-22-2008 09:15 PM

Quote:

Originally Posted by svew (Post 31738)
lildude is going around trying to use it on people

Wrong. Once infected, that account becomes a spreader.
Its basic MSN spreading. Seriously if you have never seen it you have to be like new as hell to the internets.

It always starts off with one person. Then Domino Effect.

Peetu 11-22-2008 11:23 PM

Thanks for information, going to be careful.

EndOfStory? 11-23-2008 01:48 AM

Not seen any signs I'm infected yet so I'm hoping...

colin 11-23-2008 02:18 AM

yea this has been around for soo long, who clicks them lol.

EndOfStory? 11-23-2008 02:21 AM

Gtfo, You've spammed about 10 threads now and its obvious why someone would click it.

1) Their friend says it.
2) Its only clicking a link - what harm could that do?
3) The url is personalised; it says your email address at the end of the URL.

colin 11-23-2008 02:42 AM

Quote:

Originally Posted by EndOfStory? (Post 31863)
Gtfo, You've spammed about 10 threads now and its obvious why someone would click it.

1) Their friend says it.
2) Its only clicking a link - what harm could that do?
3) The url is personalised; it says your email address at the end of the URL.

stop crying you troll.

all i said it was old and i thought no one feel for it anymore. its old thats why i guessed no one would click it anymore. so stop crying lad.

GfMyS0n 11-23-2008 04:44 AM

No i didnt start it, i got it from lildude :(
Anyway am i safe or not? :S

Lust 11-23-2008 06:11 AM

Quote:

Originally Posted by Ben (Post 31877)
No i didnt start it, i got it from lildude :(
Anyway am i safe or not? :S

No, you're still in the botnet even though they stopped advertising.

EndOfStory? 11-23-2008 07:05 AM

What if they didn't start :O

Csg999 11-23-2008 11:32 AM

well I havnt been infected but I now know not to click on that :)

Thanks alot man

Sanjuro 11-23-2008 12:52 PM

Guys, the way I deleted it when I was infected was log off, and instantly started a computer scan.
Then depending on your protection it should pick it up.
I did a quick scan with McAffe and it has messenger protection soo.
If you clicked the link, log off MSN immediately and Scan your computer.

Dice 11-23-2008 03:57 PM

Ya, I know theres tons of these that have been going around for a long time on msn. Just never click them, you can tell it's a shitty site by the domain.

Avenger 11-23-2008 06:23 PM

The infected file that you need to delete is called either
Service.jpg
or
Server.jpg
its one of those, I forgot which one.

EDIT:
It is Service.exe

Dice 11-23-2008 06:42 PM

Just don't click it in the first place, I mean come on why would you randomly download a random file?

Avenger 11-24-2008 04:01 AM

Quote:

Originally Posted by Dice (Post 32075)
Just don't click it in the first place, I mean come on why would you randomly download a random file?

Dice you honestly have no clue how this works,
It opens a Java App asking for your permission,
You would then think, "Oh well it can't do anything to me lets
see what this site is that my best friend just sent me"
Next thing you know you computer gets super slow and
it spams all of your msn with the link.

Lust 11-24-2008 01:20 PM

Quote:

Originally Posted by Avenger (Post 32067)
The infected file that you need to delete is called either
Service.jpg
or
Server.jpg
its one of those, I forgot which one.

EDIT:
It is Service.exe

Service.exe IS the trojan.
Quote:

Originally Posted by Dice (Post 32075)
Just don't click it in the first place, I mean come on why would you randomly download a random file?

The file is automatically downloaded due to a Java exploit.. please read next time.

Avenger 11-24-2008 01:31 PM

Quote:

Originally Posted by Lust (Post 32178)
Service.exe is NOT the trojan. OMG this is one of the main windows OS files, are you crazy!

The file is automatically downloaded due to a Java exploit.. please read next time.

service.exe is a process belonging to the Dell Solution Center which offers worldwide technical support and training for it's products. This program is important for the stable and secure running of your computer and should not be terminated. This process is also installed alongside Adaptec SCSI cards, and again should not be terminated unless causing problems.

...
Its not a main OS file.

EDIT:

Proof

http://i33.tinypic.com/9gdp3a.jpg

Lust 11-24-2008 07:09 PM

Ok service.exe is the file, I've found the irc and have sent an email to get it shutdown.

Dragon 12-01-2008 08:41 PM

Hopefully it gets taken out soon.
I never accept links before verifying that my friend stated the website, not a trojan.


All times are GMT -8. The time now is 12:34 PM.

Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.