Archive

Google

Wednesday, December 19, 2007

The Orkut virus - Infostealer.Orcu


Orkut has become a major social networking portal . It is so cool and so addictive ... But there are hidden dangers everywhere . . .
Recently u might have noticed that the hyperlinking feature has been modified . . . That was done to prevent phishing ( hackers stealing ur data - Just use the google search on my sidebar to read up on it )

A recent virus attack was by Infostealer.Orcu

Here is how the scrap will look like.
“Opa, tudo bom? Eu criei um vídeo com uma seleção de minhas fotos
novas, clica aí pra ver - h t t p :// y e p . i t / ? i k s t t v -
Estão
bem legais!!! “

What should you do?
Simply delete the scrap! As simple as that..

How does it spread?

It spreads through infected contacts. An orkut account gets infected
once you click on the link. The Trojan posts a message in your all your
friend's scrapbook area of the Orkut system. The message text is chosen
by the attacker and can be a random sentence written in Brazilian
Portuguese, such as the following:

Message example 1:
Opa, tudo bom? Eu criei um video com uma selecao de minhas fotos novas,
clica ai pra ver - ( suspicious link ) - Esta bem legais!!!

Message example 2:
Oi... tudo bom? Como o orkut limita a quantidade de fotos que podem ser
publicadas na minha conta, eu criei um slide com algumas fotos minhas,
pra ver e so clicar clicar no link!!! ( suspicious link ) - Sei que vai
gostar

If anyone click on the link, it redirects u to the virus URL & asks u to download an .exe file , which is a
copy of Infostealer.Orcu.

When Inforstealer.Orcu runs on a computer, it infects the computer u use and uses your orkut account to scrap everyone in your friends list with the malicious scrap, starting from the first name that comes when u view freinds (at that particular time - the list order changes after some time )

The message is in Portuguese and means :

Opa, all good one? I created a video with an collection of my photos new,click for to see there -( suspicious link ) - I am well legal!

Name of the Trojan:
Infostealer.Orcu

Norton’s Description:
Infostealer.Orcu is a Trojan horse that attempts
to steal confidential information, such as bank and Paypal accounts. It
may arrive as a message spammed across the Orkut network.

Systems Affected:
Windows 2000, Windows 95, Windows 98, Windows Me,
Windows NT, Windows Server 2003, Windows XP


Don't click on any strange links in ur scrapbook ... especially if it asks u to download or run some file

0 Comments: