Read the Beforeitsnews.com story here. Advertise at Before It's News here.
Profile image
By Alexander Higgins (Reporter)
Contributor profile | More stories
Story Views
Now:
Last hour:
Last 24 hours:
Total:

Beware! New Virus Spreading via Facebook Chat Messaging Window

% of readers think this story is Fact. Add your two cents.



A new computer virus is spreading though the Facebook instant messenger chat window. Exercise caution when clicking such links!

A new computer virus, known as Steckt.Evl, is making its way around the Internet is being spread by cloaking itself as a harmless looking link being sent as an instant Facebook chat message.

Once user click on the link it directs users to download infected software which overrides protect software and deletes any anti-virus software that is running on the target computer.

If your friend’s computer is infected, this worm will automatically use their Facebook account to send you a link in a chat window so don’t assume that just because it is a link a friend sent it is safe to click.

Before to verify directly with your friends that they actually sent you any links that pop-up in your Facebook chat window before clicking them.

Trend Micro reports:

Worm Spreads via Facebook Private Messages, Instant Messengers

We recently received reports about private messages found on Facebook and distributing a link, which is a shortened URL pointing to an archive file “May09-Picture18.JPG_www.facebook.com.zip”. This archive contains a malicious file named “May09-Picture18.JPG_www.facebook.com” and uses the extension “.COM”.

Once executed, this malware (detected as WORM_STECKCT.EVL) terminates services and processes related to antivirus (AV) software, effectively disabling AV software from detection or removal of the worm. WORM_STECKCT.EVL also connects to specific websites to send and receive information.

Another noteworthy routine is that this worm downloads and executes another worm, one detected as WORM_EBOOM.AC. Based on our analysis, WORM_EBOOM.AC is capable of monitoring an affected user’s browsing activity such as message posting, deleted posted messages and private messages sent on the following websites such as Facebook, Myspace, Twitter, WordPress, and Meebo. It is also capable of spreading through the mentioned sites by posting messages containing a link to a copy of itself.

[...]

Source: Trend Micro

From the Daily Mail:

Beware the new computer virus spreading via chat messaging window on Facebook

A new computer virus is spreading via the chat window on Facebook.

The pop-up window, used for person-to-person chat, pops up with a message from a ‘friend’ which links to an innnocent looking website.

Clicking the link instantly infects your PC with the virus, labelled Steckt.Evl by discoverers Trend Micro.

The virus instantly disables and removes anti-virus software, then spreads itself by opening chat windows on the Facebook friends of the user.

‘The worm propagates via instant messaging applications and social networking sites,’ says security experts Trend Micro which uncovered the new threat.

‘The instant message it sends is a link that downloads a copy of itself.’

Like many other new internet threats, the first thing the worm does is disable programs that might detect and destroy it.

It then actually deletes them, before going on to download further software which compromises the infected machine further.

‘It terminates processes or services that are mostly related to anti-malware programs,’ says Trend Micro.

‘It also deletes the files that are related to the processes or services it terminates. It does the said routine to keep itself running on the affected system.’

Read more: The Daily Mail

If you are infected with this virus, instructions to clean it are here.

File size: 93,184 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 10 May 2012
Payload: Connects to URLs/IPs, Terminates processes, Deletes files

Arrival Details

This worm arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

It may be downloaded from the following remote sites:

  • http://bit.ly/K8sluf?{random}

Installation

This worm drops the following copies of itself into the affected system:

  • %Windows%\iqs.exe

(Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)

Autostart Technique

This worm adds the following registry entries to enable its automatic execution at every system startup:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
Microsoft Firevall Engine = “%Windows%\iqs.exe”

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
Microsoft Firevall Engine = “%Windows%\iqs.exe”

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Terminal Server\
Install\Software\Microsoft\
Windows\CurrentVersion\Run
Microsoft Firevall Engine = “%Windows%\iqs.exe”

Other System Modifications

This worm adds the following registry entries:

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Services\SharedAccess\Parameters\
FirewallPolicy\StandardProfile\AuthorizedApplications\
List
%Windows%\iqs.exe = “%Windows%\iqs.exe:*:Enabled:Microsoft Firevall Engine”

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Services\SharedAccess\Parameters\
FirewallPolicy\StandardProfile\AuthorizedApplications\
List
%Windows%\iqs.exe = “%Windows%\iqs.exe:*:Enabled:MSN Messenger”

Propagation

This worm sends the following messages via instant-messaging (IM) applications:

http://bit.ly/K8sluf?{random} – also detected as WORM_STEKCT.EVL

It targets the following social networking site(s):

  • Facebook

It sends messages that contain links to sites hosting remote copies of itself using the following instant-messaging (IM) applications:

  • AIM
  • Google Talk
  • ICQ
  • MSN
  • Yahoo! Messenger

Backdoor Routine

This worm connects to the following websites to send and receive information:

  • {BLOCKED}.{BLOCKED}.228.202
  • news.{BLOCKED}dio.net
  • safe.{BLOCKED}dio.net

Process Termination

This worm terminates processes or services that contain any of the following strings if found running in the affected system’s memory:

  • AntiVirService
  • AviraUpgradeService
  • MSASCui.exe
  • MsMpEng.exe
  • MsMpSvc
  • WinDefend
  • YahooAUService
  • YahooAUService.exe
  • avgnt.exe
  • avp
  • avp.exe
  • egui.exe
  • ekrn
  • ekrn.exe
  • kavsvc.exe
  • msseces.exe
  • wuauserv

NOTES:

This worm deletes the files related to the terminated running processes.

 

Source: Beware! New Virus Spreading via Facebook Chat Messaging Window ©
Copying or redistribution of this material requires that this license must remain intact with attribution to the content source.

Related Posts

  • No Related Post

Read more at Alexander Higgins Blog


Source:


Before It’s News® is a community of individuals who report on what’s going on around them, from all around the world.

Anyone can join.
Anyone can contribute.
Anyone can become informed about their world.

"United We Stand" Click Here To Create Your Personal Citizen Journalist Account Today, Be Sure To Invite Your Friends.

Please Help Support BeforeitsNews by trying our Natural Health Products below!


Order by Phone at 888-809-8385 or online at https://mitocopper.com M - F 9am to 5pm EST

Order by Phone at 866-388-7003 or online at https://www.herbanomic.com M - F 9am to 5pm EST

Order by Phone at 866-388-7003 or online at https://www.herbanomics.com M - F 9am to 5pm EST


Humic & Fulvic Trace Minerals Complex - Nature's most important supplement! Vivid Dreams again!

HNEX HydroNano EXtracellular Water - Improve immune system health and reduce inflammation.

Ultimate Clinical Potency Curcumin - Natural pain relief, reduce inflammation and so much more.

MitoCopper - Bioavailable Copper destroys pathogens and gives you more energy. (See Blood Video)

Oxy Powder - Natural Colon Cleanser!  Cleans out toxic buildup with oxygen!

Nascent Iodine - Promotes detoxification, mental focus and thyroid health.

Smart Meter Cover -  Reduces Smart Meter radiation by 96%! (See Video).

Report abuse

    Comments

    Your Comments
    Question   Razz  Sad   Evil  Exclaim  Smile  Redface  Biggrin  Surprised  Eek   Confused   Cool  LOL   Mad   Twisted  Rolleyes   Wink  Idea  Arrow  Neutral  Cry   Mr. Green

    MOST RECENT
    Load more ...

    SignUp

    Login

    Newsletter

    Email this story
    Email this story

    If you really want to ban this commenter, please write down the reason:

    If you really want to disable all recommended stories, click on OK button. After that, you will be redirect to your options page.