Thursday, July 13, 2006

[compilers_nitw] The much awaited Trojan horse reaches India!

Yes, I am talking about the orkut worm. I personally saw it in action in my friend�s scrap book and I thought I�ll write about it.

So, if you are using Orkut, you must read this article�

Never bother to click on any links that sounds really unfamiliar to you even if it comes from your closest friend.

Here is how the scrap will look like.
�Opa, tudo bom? Eu criei um v�deo com uma sele��o de minhas fotos novas, clica a� pra ver - h t t p :// y e p . i t / ? i k s t t v - Est�o bem legais!!! �

What should you do?
Simply delete the scrap! As simple as that..

How does it spread?

It spreads through infected contacts. An orkut account gets infected once you click on the link. The Trojan posts a message in your all your friend's scrapbook area of the Orkut system. The message text is chosen by the attacker and can be a random sentence written in Brazilian Portuguese, such as the following:

Message example 1:
Opa, tudo bom? Eu criei um video com uma selecao de minhas fotos novas, clica ai pra ver - [MALICIOUS_LINK] - Esta bem legais!!!

Message example 2:
Oi... tudo bom? Como o orkut limita a quantidade de fotos que podem ser publicadas na minha conta, eu criei um slide com algumas fotos minhas, pra ver e so clicar clicar no link!!! [MALICIOUS_LINK] - Sei que vai gostar

If users click on the link, a malicious file is downloaded, which is a copy of Infostealer.Orcu.

When Inforstealer.Orcu is executed, it performs a series of actions and infects your system.

What does this scrap in Portuguese mean anyway? I tried using a translator and this is what I got�
Opa, all good one? I created a video with an election of my photos new, clica pra to see there - h t t p :// y e p . i t / ? i k s t t v - I am well legal!

Name of the Trojan: Infostealer.Orcu

Norton�s Description: Infostealer.Orcu is a Trojan horse that attempts to steal confidential information, such as bank and Paypal accounts. It may arrive as a message spammed across the Orkut network.

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP

Pratyush
4/4 B.Tech, CSE
NIT Warangal
Warangal - 506004
E-mail: 
pratyush.kanth@gmail.com
Web page:  http://www.freewebs.com/pratyushkanth/
            


Why keep checking for Mail? The all-new Yahoo! Mail Beta shows you when there are new messages.

__._,_.___
New Message Search

Find the message you want faster. Visit your group to try out the improved message search.

SPONSORED LINKS
.

__,_._,___

No comments:

Post a Comment