Slashdot Mirror


New Worm Spreads Via MSN Messenger

vxone writes "Anti-virus experts are watching a new worm that spreads through Microsoft Corp.'s MSN Messenger client. The worm is not harmful to infected machines and has infected only a few PCs at this point, according to an analysis by Trend Micro Inc. Known as Jitux, the worm is self-propagating and contains a link to a Web site that automatically downloads an executable file named 'jituxramon.exe' to the PC. Once the file runs, the worm begins sending out copies of itself to all of the names in the user's Messenger contact list."

10 of 380 comments (clear)

  1. solution by Barbarian · · Score: 5, Insightful

    Uhhh, shut down the website that the "worm" is sending a link to?

  2. NOT A WORM by Zork+the+Almighty · · Score: 4, Insightful

    This thing is not a worm, no matter how much you want it to be one.

    --

    In Soviet America the banks rob you!
  3. Re:So what does it actually do? by wa5ter · · Score: 5, Insightful

    A friend of mine, who knows a bit about this kind of thing (no, he isn't) suggested that this is the kind of thing someone would do if they wanted to cause a lot of damage, but not get caught. The harmless version will be widely propogated, and then it's only a matter of time before some script kiddie loads up a far more harmful payload. This will probably be the person that takes the rap for the whole thing, leaving the original virus creator scott free.

  4. Re:This is why we use linux by Sarojin · · Score: 5, Insightful

    Linux doesn't protect users from being idiots. Nothing can.

    --
    HOW'S MY POSTING? CALL 1-800-POSTING
  5. Re:What about... by AuMatar · · Score: 4, Insightful

    Nothing. However privlidge separation on a Unix box would prevent a harmful payload in a worm of this sort, unless the user was running as root. In which case, he needs to be shot.

    --
    I still have more fans than freaks. WTF is wrong with you people?
  6. Self propagating? by RogueProtoKol · · Score: 4, Insightful

    I thought self propagating worms involved no direct user interaction (ie a tard clicking a link), doesn't that make this just a plain old (really simple) trojan if anything being as it pretends to be something else (i assume the link comes with a message like click here to see me holiday pics !)?

  7. Re:why is MS always the target? by Anonymous Coward · · Score: 5, Insightful

    AIM and YIM have been around a lot longer and no one ever wrote a "worm" (debatable label in this case) for those...

    Yes, they have.

    Did you actually check before making that claim?

  8. Don't run this blindly by anti-NAT · · Score: 4, Insightful

    do you trust ./'ers to only write innocent, good willed code ?

    --
    The Internet's nature is peer to peer - 20050301_cs_profs.pdf
  9. Re:Low risk by Sycraft-fu · · Score: 4, Insightful

    Things like this have been on IRC, e-mail, MSN, AOL, ICQ and any other chat type application you can think of. It's the classic n00b getter. Send them a message that warns of imminent doom, promises something wonderful or what have you and try to get them to run your app. That app then does as you please.

    This is the kind of vunerability that we'll basically never be able ot get rid of, barring some kind of orwellian palladium thing. Dumb users will run shit they shouldn't, and infect their boxes. You can do things to reduce the probability, but you can't eliminate it.

    I deal with this at work all the time. We have a user that just loves to run every damn attachment she gets her hands on. Despite a virus scanner and as restrictive privledges as we are allowed to give her, she STILL gets infected form time to time. There's just no stopping it. The only way would be to disallow her to run apps that admins don't install, which we aren't allowed to do (adn doesn't apply to home users).

    So we just have to accept this crap. Hopefully OS/app makers will do what they can to make it as hard as practical for this to ahppen, but you'll never eliminate it. YOu also have to be careful not to go too overboard. I mean I can think of many measures that would make these things much safer. However they generally involve things that would make them a bitch to use and piss people off.

  10. User intervention Part 2 by ChocolateCheeseCake · · Score: 5, Insightful

    Why is it when some one does something stupid on UNIX and screws their HDD, its the user that is blamed but when the user CHOOSES to run Windows and CHOOSES to run MSN and CHOOSES to have their default browser to be Internet Explorer, for some reason they're immune to this barrage of RTFM and instead it is Microsoft who gets the blame.

    Sure, I love the Microsoft bashing mosh pit just as much as the next Mac/FreeBSD user, however, in all honesty, when is the end user going to take responsibility for their actions? doesn't this sound like the a-typical senario in the "real world", something bad happens and the government is blamed for not stopping the idiot from hurting themself.

    The fact remains that the end user does VERY little to protect themselves. Sure, we'll have a chorus of ranters claiming that in their zyx operating system world, they would *NEVER* need that and through some miracle, some how their operating system of choice is immune to all vunerabilities.

    The fact remains that no matter what operating system you run, you HAVE to take precautions. Run an anti-virus, make sure your software and virus definitions are updated, run a GOOD firewall and actually learn how to use the computer so that you can set up the firewall so that is it beneficial rather than a hindrance.

    If you follow these VERY basic precautions, I would be VERY surprised if you get infected.

    In a perfect world, one WOULDN'T need to take these precautions, software would be bug free, everyone would be honest Joe's and Jane's, however, that isn't the case, the fact is, the world is filled with losers, script kiddies and other parasites and unfortunately the only way to defeat these people is to make their conquests so meaningless that they'll go back to nicking car badges off cars and boasting to their friends about what level of "Rainbow Islands" they got up to on their SEGA.

    Btw, does any one remember that game?

    --

    Erotic uses a feather; Pornography uses the whole chicken