Username: Save?
Password:
Home Forum Links Search Login Register*
    News: Welcome to the TechnoWorldInc! Community!
Recent Updates
[April 24, 2024, 11:48:22 AM]

[April 24, 2024, 11:48:22 AM]

[April 24, 2024, 11:48:22 AM]

[April 24, 2024, 11:48:22 AM]

[April 03, 2024, 06:11:00 PM]

[April 03, 2024, 06:11:00 PM]

[April 03, 2024, 06:11:00 PM]

[April 03, 2024, 06:11:00 PM]

[March 06, 2024, 02:45:27 PM]

[March 06, 2024, 02:45:27 PM]

[March 06, 2024, 02:45:27 PM]

[March 06, 2024, 02:45:27 PM]

[February 14, 2024, 02:00:39 PM]
Subscriptions
Get Latest Tech Updates For Free!
Resources
   Travelikers
   Funistan
   PrettyGalz
   Techlap
   FreeThemes
   Videsta
   Glamistan
   BachatMela
   GlamGalz
   Techzug
   Vidsage
   Funzug
   WorldHostInc
   Funfani
   FilmyMama
   Uploaded.Tech
   MegaPixelShop
   Netens
   Funotic
   FreeJobsInc
   FilesPark
Participate in the fastest growing Technical Encyclopedia! This website is 100% Free. Please register or login using the login box above if you have already registered. You will need to be logged in to reply, make new topics and to access all the areas. Registration is free! Click Here To Register.
+ Techno World Inc - The Best Technical Encyclopedia Online! » Forum » THE TECHNO CLUB [ TECHNOWORLDINC.COM ] » Computer / Technical Issues » Internet » Websites » Social Networking - OrKutGuide.Com » Non-Technical Orkut
 News: Orkut Virus
Pages: [1]   Go Down
  Print  
Author Topic: News: Orkut Virus  (Read 2355 times)
Taruna
Elite Member
*****



Karma: 13
Offline Offline

Posts: 845

Hi ALL


View Profile
News: Orkut Virus
« Posted: February 11, 2007, 11:06:05 AM »


Orkut Virus


A new worm that attempts to steal online banking credentials is propagating on Google's social-networking Web site.

The worm, dubbed MW.Orc, primarily targets Brazilian users of Google's Orkut Web site. It uses a message in Portuguese to entice people to click on a file that is disguised as a JPEG image, FaceTime Security Labs said in a statement.

The initial file, called "minhasfotos.exe," creates two additional files on a user's system, "winlogon_.jpg" and "wzip32.exe," . When the user, after the initial compromise, clicks on the "My Computer" icon in Windows , an e-mail with his or her personal data is sent to the anonymous attacker.

Additionally, the compromised computer may be added to a network of hijacked PCs, known as a botnet. The pest also tries to propagate by placing a malicious link on the profiles of people in the Orkut user's network.

Google confirmed the worm. "We are aware of this issue and will have a temporary fix in place within the hour," a company representative said in an e-mailed statement. "We are working on a more permanent solution for users to guard against these malicious efforts."

For their protection, Orkut users, just as users of all online services and applications, should always be careful when opening or clicking on anything suspicious, the Google representative said.


Never bother to click on any links that sounds really unfamiliar to you even if it comes from your closest friend.

Here is how the scrap will look like.
?Opa, tudo bom? Eu criei um v?deo com uma sele??o de minhas fotos novas, clica a? pra ver - h t t p :// y e p . i t / ? i k s t t v - Est?o bem legais!!! ?

What should you do?
Simply delete the scrap! As simple as that..

How does it spread?

It spreads through infected contacts. An orkut account gets infected once you click on the link. The Trojan posts a message in your friend's scrapbook area of the Orkut system. The message text is chosen by the attacker and can be a random sentence written in Brazilian Portuguese, such as the following:

Message example 1:
Opa, tudo bom? Eu criei um video com uma selecao de minhas fotos novas, clica ai pra ver - [MALICIOUS_LINK] - Esta bem legais!!!

Message example 2:
Oi... tudo bom? Como o orkut limita a quantidade de fotos que podem ser publicadas na minha conta, eu criei um slide com algumas fotos minhas, pra ver e so clicar clicar no link!!! [MALICIOUS_LINK] - Sei que vai gostar

If users click on the link, a malicious file is downloaded, which is a copy of Infostealer.Orcu.

When Inforstealer.Orcu is executed, it performs a series of actions and infects your system.

What does this scrap in Portuguese mean anyway? I tried using a translator and this is what I got?
Opa, all good one? I created a video with an election of my photos new, clica pra to see there - h t t p :// y e p . i t / ? i k s t t v - I am well legal!

Name of the Trojan: Infostealer.Orcu

Norton?s Description: Infostealer.Orcu is a Trojan horse that attempts to steal confidential information, such as bank and Paypal accounts. It may arrive as a message spammed across the Orkut network.

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP


Hackers are trying to steal Orkut users' bank account information by inserting an automated information theft worm, according to security researchers. The worm, known as MW.Orc, is propagating through Orkut when users launch an executable file disguised as a JPEG.

Google has a temporary fix in place and encourages Orkut users not to open suspicious files.

"We are aware of this issue and have a temporary fix in place. We are working on a more permanent solution for users to guard against these malicious efforts," said a representative from Google in a response emailed to Google Watch.

Logged

« Reply #1 Posted: February 11, 2007, 12:06:59 PM »
Vatsal
Administrator
Super Elite Member
*****



Karma: 603
Offline Offline

Posts: 1392

Vatsal The Great!


View Profile WWW
Re: News: Orkut Virus
« Reply #1 Posted: February 11, 2007, 12:06:59 PM »

thanks 4 the info...
Logged
« Reply #2 Posted: February 20, 2007, 03:18:21 PM »
Mark David
Administrator
Super Elite Member
*****



Karma: 185
Offline Offline

Posts: 1624

!!!Techno King!!!

fabulous_designer
View Profile WWW
Re: News: Orkut Virus
« Reply #2 Posted: February 20, 2007, 03:18:21 PM »

thanks
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Copyright © 2006-2023 TechnoWorldInc.com. All Rights Reserved. Privacy Policy | Disclaimer
Page created in 0.187 seconds with 27 queries.