JiveMasterT Posted May 1, 2005 Share Posted May 1, 2005 (edited) Over the course of the day about 20 people on my buddy list have contracted this virus that is spreading rapidly. You will get a message from someone that says "Hey look at this." and the "this" is a link that points to "http://cesaraceves.com/gallery/gallery.com" DO NOT CLICK ON THAT LINK! You will get the virus and start spreading it rapidly to everyone on your buddy list. Please post here if you know how to remove it. Last I checked, the website it is pointing to is running really slow. I did manage to download the .com file using getright but i dont know how to look at the actual code to see what the thing does. edit... if you want the fix for it... go here: http://www.jayloden.com/ Edited May 1, 2005 by jivemastert Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/ Share on other sites More sharing options...
b0m8er Posted May 1, 2005 Share Posted May 1, 2005 Last I checked, the website it is pointing to is running really slow. I did manage to download the .com file using getright but i dont know how to look at the actual code to see what the thing does. 585857468[/snapback] Just submit that file to major AV company, like Symantec, Kaspersky.... Let them play with it.... Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585857488 Share on other sites More sharing options...
JiveMasterT Posted May 1, 2005 Author Share Posted May 1, 2005 I submitted it to Symantec, waiting for a response... Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585857538 Share on other sites More sharing options...
kyro Posted May 1, 2005 Share Posted May 1, 2005 humm well i couldnt get online with GAIM TRILLIAN and Miranda. my co worker thought i was ditching him. ( mailed him to come on MSN ) whats the prob? Does AIM sucks this much? Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585857664 Share on other sites More sharing options...
Brandon Live Veteran Posted May 1, 2005 Veteran Share Posted May 1, 2005 I haven't seen any of these messages... How does the virus get installed? I assume this only affects systems that are not properly patched? Edit: Looks like it just links to a file called "gallery.com" Wouldn't the user have to accept the download and run the file in order to be affected? Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585857676 Share on other sites More sharing options...
tlogank Posted May 1, 2005 Share Posted May 1, 2005 I had someone send this to me as well, but for some reason, but when I clicked the link, it opened up in Opera (Default Browser) and it wasn't able to affect me. ...Just another reason to use alternative browsers. Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585857679 Share on other sites More sharing options...
JiveMasterT Posted May 1, 2005 Author Share Posted May 1, 2005 im pretty sure it will just ask to download the .com file if it opens in another browser, in which case you could install it. people who have windows that isnt patched are potentially at risk. i did find a website that has a tool that might be able to remove it... http://www.jayloden.com/check.htm go there, follow the directions, get the tool. Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585857688 Share on other sites More sharing options...
Cyber Dog Posted May 1, 2005 Share Posted May 1, 2005 It's already detected by kaspersky... I submitted it to McAfee and their heuristics detected it, so they'll be adding it shortly. Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585857690 Share on other sites More sharing options...
Brandon Live Veteran Posted May 1, 2005 Veteran Share Posted May 1, 2005 I had someone send this to me as well, but for some reason, but when I clicked the link, it opened up in Opera (Default Browser) and it wasn't able to affect me....Just another reason to use alternative browsers. 585857679[/snapback] Umm... it doesn't affect IE any more than it affects Opera from what I can tell... Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585857699 Share on other sites More sharing options...
tlogank Posted May 1, 2005 Share Posted May 1, 2005 This takes care of the problem... EDIT...oh, someone posted it already. Sorry, I didn't refresh the page. Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585857701 Share on other sites More sharing options...
mistical Posted May 1, 2005 Share Posted May 1, 2005 @jivemastert, to help people get rid of this. Could you edit your first post here to include that you can remove the aim virus by downloading AIMFix? here's a direct link to AIMFix: http://www.jayloden.com/aimfix.exe Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585858065 Share on other sites More sharing options...
Valmor Posted May 1, 2005 Share Posted May 1, 2005 Does this automatically execute if your default browser is IE? Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585858279 Share on other sites More sharing options...
JiveMasterT Posted May 1, 2005 Author Share Posted May 1, 2005 @jivemastert, to help people get rid of this. Could you edit your first post here to include that you can remove the aim virus by downloading AIMFix? here's a direct link to AIMFix: http://www.jayloden.com/aimfix.exe 585858065[/snapback] good idea... done. Does this automatically execute if your default browser is IE? 585858279[/snapback] Not nessicarily. I think if you have an older version of IE it might auto execute, but if you stay on top of your updates then you should be fine. Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585858514 Share on other sites More sharing options...
radioboy Posted May 1, 2005 Share Posted May 1, 2005 Umm... it doesn't affect IE any more than it affects Opera from what I can tell... 585857699[/snapback] Actually, it does IE automatically executes the file w/ certain permissions Opera does not Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585858523 Share on other sites More sharing options...
Oompa Posted May 1, 2005 Share Posted May 1, 2005 Yep I got this twice. I started talking to the guy that sent it to me :p. Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585858536 Share on other sites More sharing options...
Homer Posted May 1, 2005 Share Posted May 1, 2005 Seems like there is a similar thing going round for MSN too... next time I get it I'll tear it apart on the mac where I know I'll be safe. :p Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585858547 Share on other sites More sharing options...
Meshuggah Posted May 2, 2005 Share Posted May 2, 2005 been getting a lot of these messages... too bad its always from my non-comp savvy friends :/ Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585858702 Share on other sites More sharing options...
Dane2003 Posted May 2, 2005 Share Posted May 2, 2005 Hello, I have submitted this file to Symantec and to McAfee. McAfee's Heuristic detection assigned the name "new malware.h" to it, and it is currently being Escalated with a McAfee Researcher at this time. Symantec has yet to respond to this file, however, I will post an update as soon as I get more information. Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585858737 Share on other sites More sharing options...
Brandon Posted May 2, 2005 Share Posted May 2, 2005 I got it, but of course didnt install click on it.. just looked at the code and its all jibberish Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585858750 Share on other sites More sharing options...
kylejn Posted May 2, 2005 Share Posted May 2, 2005 Yeah, I got this a few times today. I never downloaded the file, so I'm still OK, right? Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585858757 Share on other sites More sharing options...
Lewkwarm Posted May 2, 2005 Share Posted May 2, 2005 Yeah, I got this a few times today. I never downloaded the file, so I'm still OK, right? 585858757[/snapback] same here, i haven't been infected with it. i'd say you're ok as long as you don't click the link. Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585858764 Share on other sites More sharing options...
RightfulSpire Posted May 2, 2005 Share Posted May 2, 2005 well i opened it in my winME test machine..its the machine i totally trash all the time..and as far as i can tell its doin nuttin..there are no connections goin g out threw the firewall..no files corrupt...i will keep it going to see what happens but this could just be a scare. not a threat of anykind. Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585858782 Share on other sites More sharing options...
Code.Red Posted May 2, 2005 Share Posted May 2, 2005 Yeah, a friend of mine sent this to me, I clicked it and it opened in firefox, asking me to save it or whatnot, I immediatly asked him what it was and he didn't know what I was talking about! So I told him now and he knows he has a virus. Does this do anything harmful to the PC it is on? Or is all it does is just spread itself? Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585858787 Share on other sites More sharing options...
Dean W Posted May 2, 2005 Share Posted May 2, 2005 Hahahaha, Sorry But I dont Use AIM lol It's nice to see other Instant Messengers getting virus :p Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585858795 Share on other sites More sharing options...
stopdroproll Posted May 2, 2005 Share Posted May 2, 2005 AIM bashing in 5...4...3...2... Link to comment https://www.neowin.net/forum/topic/315323-aim-virus-spreading-rapidly/#findComment-585858807 Share on other sites More sharing options...
Recommended Posts