Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, April 24, 2009

belimantil.info hacked

About 2 days ago, I saw this on belimantil.info:




Astounded my first thought was "What the hell?!". I was looking for a revision text one of my colleagues wrote, and fortunately it was available on another site. medforum2 (a forum created by medical students for general talk, exams and medicine-related discussion) was hosted on that domain, I thought of visiting and saw one of my colleagues complaining about the same thing.

Today I re-visited the site, only to find that it wasn't working! Naturally, my techie side kicked in several minutes afterwards, and I started looking into whether it was their fault (probably) or the web administration (why not?). So the whois command revealed the nameserver, I decided to visit oklopsrbija.com, their hosting provider.

Poštovani klijenti,

Prekjuce je izvrsen napad velike grupe palestinskih hakera koji su "u borbi protiv Izraelaca" uspeli da zaobidju sve zastite na serveru i ishakuju sve naloge. Juce je ceo dan bila rekonstrukcija fajlova i pojacanje zastite.
Nocas je uglavnom proradilo sve. Otezan je jos pristup cPanelu. Klijenti kojima je hakovanjem ostecena indeks stranica a nemaju backup tog fajla, neka ostave ticket sa subjectiom: "backup index fajla" i uradice se parcijalni restore podataka za te klijente, pocevsi od petka ujutru, i samo za klijente koji zatraze restore indeks fajla. U nemogucnosti smo da uradimo full restore svih podataka posto je vecina sajtova, pogotovu foruma, vec online i pregazili bi tim full restore njihove sveze podatke.Probijanje zastite nije nista novo na internetu, postala je nazalost svakodnevnica, igrom slucaja smo prekjuce odabrani mi.
Ako hakeri mogu da provale u NASA ili Pentagon servere, sto ne bi i kod nas. I nismo prvi a na zalost ni poslednji domaci provajder koji je imao komplet ishakovan server.Takodje vas molimo da pratite dalja obavestenja logovanjem na vas oklopov nalog i pregledanje sekcije "Obavestenja".
S poštovanjem,
Vojin Petrović
direktor Oklop Srbija

In short, they are claiming that "Security breaking is nothing new on the internet, it has become an everyday event unfortunately, by chance we were chosen the day before yesterday" and "If hackers can break into NASA or Pentagon servers, why wouldn't they break into ours?". If understood them correctly, they're claiming it's not their fault they're not secure. Not even a single "We are sorry for not being careful" or "We'll take extra security steps to provide you with a safer hosting in the future" sentence. What an arrogance! I guess they should scratch the word on their website title, "Pouzdan" (=Reliable).

P.S. I hope this doesn't happen to me :)

Wednesday, October 15, 2008

Google - 403 Forbidden - "We're sorry"

If you got the "We're sorry" webpage I believe you came to the right place.. I have noticed this error myself :(

Error

We're sorry...

... but your query looks similar to automated requests from a computer virus or spyware application. To protect our users, we can't process your request right now.
We'll restore your access as quickly as possible, so try again soon. In the meantime, if you suspect that your computer or network has been infected, you might want to run a virus checker or spyware remover to make sure that your systems are free of viruses and other spurious software.
If you're continually receiving this error, you may be able to resolve the problem by deleting your Google cookie and revisiting Google. For browser-specific instructions, please consult your browser's online support center.
If your entire network is affected, more information is available in the Google Web Search Help Center.
We apologize for the inconvenience, and hope we'll see you again on Google.

At first I thought that they blacklisted Serbian IP addresses (that would be really spicy!). They may suggest some mumbo-jumbo procedure in Google FAQ, but that didn't do the trick.

The solution was rather easy, I went to http://www.google.com/sorry typed in some characters and voila - redirected to Google web search :)

Monday, September 29, 2008

Firefox: "Secure connection Failed"

Visiting websites with secure connection enabled can sometimes lead to problems in Firefox. Websites just link their https certificate to whatever sub-domain they want or they redirect to another website without registering it properly. Mozilla Firefox 3 detects that "glitch" and adds an extra protection layer by stating the following error:
Page load error
Secure connection Failed

*site* uses an invalid security certificate
The certificate is only valid for *another site*
(Error code: ssl_error_bad_cert_domain)

There's an easy way to resolve this, if you click on "Or you can add an exception" → "Add exception" → "Get certificate" → Read the reason it was invalid and if you're OK with the reason → "Confirm security exception".

Saturday, October 27, 2007

Malware: MSN Messenger imageXX.zip

It's a bit old news, but I've seen it, so I'd like to warn people about it, if you see something similar to this:

..then either don't accept the image09.zip image10 image08 image07 or a similar file. It contains an executable (program) such as image09.JPG-www.photobucket.com - DO NOT GET TRICKED!
I'm saying "tricked" because it appears as if the file has a "www.example.com" website in its filename, which is certainly not the case.

I've updated cwean.exe cleaner to detect them, check out the bfu script. If you saw any other files or registry keys, please reply with a comment.

P.S. Have a nice weekend everyone! I'm off to probably visit Kragujevac, a town in Serbia, a friend of mine invited me to celebrate a family holiday with them. I'll probably return with several photos, I've never been there. :)

Friday, August 31, 2007

Security: gotcha! just a hoax

I forgot jokes, or hoaxes if you will, using javascript exist nowadays, all I ever encounter were malware, badware, c***ware.




MissU!~miau@92.80.144.168 MSG!#bucuresti http://sg.geocities.com/viceadmiralcongo/dont_click.htm

Don't worry, it's a pure annoying javascript joke (at the point of writing). Imagine a lot of windows or info boxes popping up and alerting you one by one... now imagine clicking "OK" each time ;) You can stop imagining and follow the link above. Sometimes this kind of jokes can be educational, making you aware of several dangers hidden to the eye (that is if you don't check the source of the website).

I love the singing part:
...
alert("Jingle bells,");
alert("Batman smells,");
alert("Robin laaaaaid an egg,");
alert("Batmobile lost its wheel,");
alert("And Joker's really gh3y,");
...

Monday, August 20, 2007

Security: Sohanad and win32.VB worms still alive

Sometimes Godaddy and their affiliates, i.e. Servage, make me wonder just how effective their actions are against their own clients that abuse godaddy's ToS (Terms of Service).
One of the things that made me consider this as a blog topic is their apparent inaccessibility to shut down the main domain names. For those who don't know what's going on, the story goes like this:
- thecoolpics.net was ended, after some 6+ months of running the Sohanad.* and win32.VB.* worms
- thecoolpics.com and quicknews.info redirect to a new target as of yesterday, as far as I can tell: http://72.232.123.170/~windy/ auct_photo/temp/ (deliberately put a space between, do NOT visit the website)
- The exploit used here is a VB script exploit, which is actually encoded using Javascript
- The exploit downloads YMworm.exe and worm2007.exe which can be found in the same folder the above mentioned link
- YMworm.exe is actually an AutoIt script and gives a bad name to the good folks of that project. worm2007.exe is just a "backup" program as far as I can tell. It connects to thecoolpics.com and tries to download these two programs from there, probably used when the websites, this lamer (langnghe.net owner) hacked and redirects to, go down.

Final comment: They might be cheap & good in sales, but their abuse team doesn't handle reports very well.

Removal tool: Cwean antimalware package

Update: If you try a Google search for the old hacked website, http://horse.he.net/~dynasty/albums/style/, you'll notice a nice warning message ;) I sure hope they applied that in the Web Forgery system implented in Firefox

I did a google search on the IP of the new one, I found another exploit: http://72.232.123.170/~hotcam /AutoVoLam.html (deliberate space added between) - downloads spider.exe from the same directory.

Thursday, August 16, 2007

Security: undetected trojan - svhost.exe

Some people really believe their antivirus software is the best... Here's a proof that they're not. This malware (trojan) is packed with Themida, which most antivirus companies have not yet bothered to include in their blacklists. Not that I'm saying it's good to blacklist packers, but at times I really wonder if it's better than waiting for someone to use it, pack their malware and start spreading it.

Spammer: Fetitz{-A-}!~Ghici@Lov3You.users.undernet.org
Message: poze cu mine si filumete de sex cu mine http://zenzion.net/filename si pe cine intereseaza id meu sexyandreeeaaa pt cei care vor o noapte frt ieftin :) pt mai multe detali intrati pe id meu :) fac si masturbare prin web ce doriti voi :) http://zenzion.net/filename http://zenzion.net/filename http://zenzion.net/filename (language = romanian, filename = album.rar)

album.rar contained poze.exe, which I've sent to be analyzed using the Anubis project, here are the results.
The executable creates a connection with Undernet IRC Network, waiting for its creator to remotely control and abuse!

Main program: C:\Windows\system32\svhost.exe (the legit one Windows uses is svChost.exe)

MD5 Hashes:
7560272abe35a5b1092779f407c7f03c poze.exe
efc6a66e2884e2d77dab32f7725f31d4 album.rar

I've tried to upload the program to the Kaspersky website, and guess what - it doesn't allow more than 1MB to be uploaded. The archive/executable were about 1.4MB.

Removal tool: Cwean antimalware package

Tuesday, August 14, 2007

Security: @RISK Newsletter

@RISK Newsletter and Tippingpoint warn about the security of the following widely used software:
(1) CRITICAL: Multiple Cisco Products Multiple Vulnerabilities
(2) CRITICAL: VMware ActiveX Control Multiple Remote Command Execution Vulnerabilities
(3) HIGH: HP OpenView Products Multiple Vulnerabilities
(4) HIGH: Symantec Norton Multiple Products ActiveX Controls Buffer Overflow
(5) MODERATE: Microsoft DirectX SDK ActiveX Control Buffer Overflow
(6) MODERATE: Astaro Security Gateway Multiple Vulnerabilities

I'd consider a full update/upgrade along with a set of tutorials on how to do it by the products mentioned above, especially VMWare & DirectX users ;)

I'd also like to recommend to use a Mozilla Firefox addon, NoScript, which I personally endorsed a year back and still love it!

A minor news, a new virus has been found called 'Storm Worm'. Read more about it here.

Friday, August 10, 2007

Bad Websites: summer.7p.com - do not buy!

Sizzlin rip-off! The owner of this website is the notorious scammer Mike Ogden (or mogden) from Canada. This person pretends to be selling goods on the internet at prices that no smart person would sell, as they'd have to used for 10 years to reach so low prices.
In short, if you know what's good for you:
DO NOT BUY ANYTHING FROM MIKE!

The website is marked as bad in WOT, an addon for Mozilla Firefox internet browser. It's a good plugin to check whether a website can be trusted or not.

The Canadian police doesn't give a damn about that, he's spamming on the irc about "cheap sales" and rips off people by receiving the money and never sending any goods.
The email he uses at the moment seems to be summergoods@gmail.com - Send him my "regards" ;)

Sunday, August 05, 2007

Security: Undetected potential malware spammed at IRC

I'm not sure if both of the files are malware, but the latter is surely something, if you take a look at the file analysis by the Anubis project. The files were scanned with Virustotal.

#1 where filename = album.exe
Analysis of the file
OnA|R!~Spumant@OnAIR.users.undernet.org MSG!#bucuresti
care vrea sa vada un album erotic al unei fete de 22 de ani din bucuresti ? romirc.com/site/filename

(Romanian - something about an erotic album of a 22-year old girl from bucharest)

#2 - where filename = Maria_Lena_YouTube_Video.avi.exe
Analysis of the file
maria19d!~maric@ACB173A2.ipt.aol.com NOTCCHAN!#cyprus
hi sou, me lene maria kai ime skyla!! an thes na me deis sto youtube video pou ekana me mia fili GYMNES pata edo ->
http://www.top10asians.com/filenameServer

Anikiti19!anikiti@216.131.100.184 NOTCCHAN!#limassol
hi sou, me lene maria kai ime skyla!! an thes na me deis sto youtube video pou ekana me mia fili GYMNES pata edo -> http://www.top10asians.com/filenameServer


(the actual file that can be downloaded is without Server at the end - the language here is Greeklish [greek using latin characters], it says the file is a youtube video, pretends to be a porn video)

Important executables:
c:\program files\windows media player\wm player.exe
c:\windows\system32\Registry3311.exe
c:\windows\system\Full_Video_View.exe
c:\windows\system32\Uninstal.exe

The file #2 is added in the list Add/Remove programs of Windows as MyProduct

Removal program suggestion: Cwean antimalware package

Tuesday, July 31, 2007

Security: @RISK Newsletter

This time, CA (computer associates) and four of its products parade along with a critical security hole. Quoting @RISK Newsletter:
This week four CA products (eTrust IDS, Unicenter, CleverPath, and
BrightStor) were found to all use a common service that has a critical
buffer overflow error.
The vulnerabilities detected are listed here:
Widely Deployed Software
(1) CRITICAL: Yahoo! Widgets ActiveX Control Buffer Overflow
(2) CRITICAL: Computer Associates Multiple Products Multiple Vulnerabilities
(3) CRITICAL: BakBone NetVault Reporter Scheduler Buffer Overflow
(4) HIGH: Panda Antivirus Products Multiple Vulnerabilities
(5) HIGH: Borland InterBase Create Request Buffer Overflow
(6) HIGH: ESET NOD32 Multiple Vulnerabilities
(7) HIGH: Norman Antivirus Multiple Vulnerabilities


Quite a lot of sensitive programs, especially those of NOD32 and Norman, two mostly respected and widely used antivirus products. I hope they'll get the patches out soon enough to calm down the public and their customers.

Tuesday, July 24, 2007

Security: @RISK Newsletter

Brought to you from the house of the European wieners... (too much Cartoon Network).
As it is stated in @RISK Newsletter, most critical new vulnerabilities were found in Oracle and Trillian. Also, several Computer Associate's security and backup tools also have multiple vulnerabilities as does Firefox.

(1) CRITICAL: Cerulean Studios Trillian URI Handling Vulnerabilities
(2) CRITICAL: Oracle Products Multiple Vulnerabilities (CPU July 2007)
(3) HIGH: Mozilla Products Multiple Vulnerabilities
(4) HIGH: Computer Associates Alert Notification Server Multiple Buffer Overflows
References:
(1) http://www.xs-sniper.com/nmcfeters/Cross-App-Scripting-2.html
(2) http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2007.html
(3) http://www.securityfocus.com/bid/24946
(4) http://www.securityfocus.com/bid/24947

Sunday, July 22, 2007

IRC: TimeWarner AOL RoadRunner and Verizon redirecting to dummy servers

This isn't anything new. I've used Google to search to track down about how many servers are affected. The results are scary, dating back to 2003.
Big internet providers (here ISPs), such as TimeWarner AOL RoadRunner and Verizon (and probably Cox) have been redirecting and/or blocking entirely irc traffic to a dummy server, checking for irc bots. But the problem is that this method will not work unless they're scanning for spam bots (bots that throw URL links, using private query messages or channel messages). rBots and SpyBots that may reply to that sort of messages, but only in their control channel which is certainly not #badbotbad. Maybe this action is used in order to say that they're doing something as an excuse if a 'delink' occurs.

I'd like to quote Anthony here:
We can protect ourselves better than the ISPs can
So very true. At least IRC server personnel can ban or even clean an entire botnet in just minutes, not thanks to ISPs.

I leave you with some screenshots that the AbleNet administrator has acquired: Picture 1 Picture 2 Picture 3 Picture 4 Picture 5

Wednesday, July 18, 2007

Linux: cURL Tutorial and Virustotal uploader (for Linux)

A brief tutorial about cURL, an application that helps you download the source of a website - the very same tutorial which helped me make a bash script to upload suspicious files to Virustotal.

First of all, to use curl you have to install it, if you're using Ubuntu or a Debian-based distribution, try the following (Applications > Accessories > Terminal):
sudo apt-get install curl
You'll have to know the root password (Ubuntu users: the same password with the one you login). Now that you have it, try:
curl --help
Cool, now read the tutorial, you'll need some HTML knowledge for starters and some basic logic to get around in deciding what to use where. I'm not going to explain that, as that's a big chapter to enter :(

On to the Virustotal file uploader; Most of you won't need to upload suspicious windows executables (programs), since you're already enjoying a taste of free software by using a Linux distribution. I must say that the webmaster has pointed me to the wrong direction, using python and the email way to post the file... Well this was a bit more productive - you'll need packages grep and sed installed:
#!/bin/bash
#Released under CC-by: http://creativecommons.org/licenses/by/3.0/
curl --progress-bar -F archivo="@$*" -F enviar=true -F distribuir=1 http://www.virustotal.com/vt/en/recepcionf | grep -i "href" | sed -e 's/.*href="\([^"]*\)".*/Results at: \1/'
Nice? I'm using Regular Expressions (regex) to alter the output and get a clickable link. Here's the script, all zipped up, chmod'ed and ready to be fired up: Download here

Put/unzip the file in your home directory. Usage? Piece of cake (mmm... cheese cake):
~/uploadatvirustotal file.exe
Check out the screenshot to get a sample output.

Tuesday, July 17, 2007

Security: Critical vulnerabilities in Excel and .NET Framework

One of the most critical weeks for this year, Excel and .NET framework are the top, as @RISK Newsletter mentions:

The most critical vulnerabilities announced this week are in Excel and the .NET Framework. Overall, Windows had three, Office had two, and other MS products had one. Microsoft wasn't alone: Sun, Apple, Symantec, Adobe, McAfee, and Cisco also had high-risk vulnerabilities this week. Add to that the vulnerability in Progress Server, used by RSA Security and many other products, and you have a complex week for finding and mitigating vulnerabilities.

(1) CRITICAL: Microsoft Excel Multiple Vulnerabilities (MS07-036)
(2) CRITICAL: Microsoft .NET Framework Multiple Vulnerabilities (MS07-040)

Linux also faces 6 vulnerabilities, but not so critical:
07.29.32 - policyd W_Read Function Remote Buffer Overflow
07.29.33 - Netwin SurgeFTP Multiple Remote Vulnerabilities
07.29.34 - SquirrelMail G/PGP Encryption Plug-in Multiple Remote Command Execution Vulnerabilities
07.29.35 - IBM AIX Libodm Unspecified Buffer Overflow
07.29.36 - Linux PowerPC Kernel Restore_Sigcontext Local Denial of Service
07.29.37 - Linux Kernel Decode_Choices Function Remote Denial of Service

It's not the time to brag about using free software, since you see that Linux is also vulnerable. But at least with a proper router that has a firewall you can use Ubuntu desktop or any Linux/*BSD distribution that is meant for desktop usage, such as PC-BSD. I won't start stating why linux is better, because there is already
a website for that matter: http://www.whylinuxisbetter.net.

Sunday, July 15, 2007

Internet: thecoolpics.net back with another redirection

Same as before, two files, two sites. Same files, different target of redirection link. Looks like some people are persistent. Possible messages of the infected redirection you might see (www.example.com replaced the actual url):

  1. :D who is beside you in this pic www.example.com/friendpic1.jpg so good-looking
  2. ;) 1 of my vacation pictures www.example.com/vacation1.jpg <:-P
  3. hot pics this week www.example.com/hot.jpg :x
  4. ;) 1 of my vacation pictures www.example.com/vacation2.jpg <:-P
  5. Screenshot of my new Ipod www.example.com/vista.jpg so cool :D
  6. Images shot in Iraq _ The war will never end www.example.com/Iraqwar.jpg << :(
  7. :)) I won an iPhone. You will never believe it :O www.example.com/mylottery.jpg <<
  8. never click into the links like something in this image www.example.com/dontclick.jpg #:-S !!!
  9. :( the page cannot be displayed www.example.com/error.jpg Something was wrong !!! Check it again and tell me later. THanks
  10. My pics www.example.com/mypics.jpg b-( <<
  11. New game ;;) sexy beach 3 (man only) www.example.com/MissWorld.jpg !!
  12. Do you realize who is in this image: www.example.com/who.jpg . Just think for a moment and tell me soon ;))

The dude disabled the adbrite click code, but still... he spreads the worm determinated to do something with it. Let's hope the antivirus programmers this time "get the message" and try wipe it out.
The results of the executables, YMworm.exe and worm2007.exe can be viewed here

It sets your home page as www.quicknews.info

Try clean it with Cwean Antimalware Package, I believe it can do wonders for some infections.

Monday, July 09, 2007

Internet: thecoolpics.net makes you download a virus

The website makes you download two files, worm2007.exe and YMworm.exe. I think worm2007.exe is a trojan to control you and YMworm.exe is definitely a worm to spread the.. bad word (the latter is an AutoIT script)! This is a list of some possible messages (wwwlinkcom is the above-named domain):


  1. :D who is beside you in this pic wwwlinkcom friendpic1.jpg so good-looking
  2. ;) 1 of my vacation pictures wwwlinkcom vacation1.jpg <:-P
  3. hot pics this week wwwlinkcom hot.jpg :x
  4. ;) 1 of my vacation pictures wwwlinkcom vacation2.jpg <:-P
  5. Screenshot of my new Ipod wwwlinkcom vista.jpg so cool :D
  6. Images shot in Iraq _ The war will never end wwwlinkcom Iraqwar.jpg << :(
  7. :)) I won an iPhone. You will never believe it :O wwwlinkcom mylottery.jpg <<
  8. never click into the links like something in this image wwwlinkcom dontclick.jpg #:-S !!!
  9. :( the page cannot be displayed wwwlinkcom error.jpg Something was wrong !!! Check it again and tell me later. THanks
  10. My pics wwwlinkcom mypics.jpg b-( <<
As is stated in the autoit script:
Tac Gia: TermeX - ThanatoS
Phan Mem: TermeX Bot
Phien Ban: 2.0
Cong Dung: Quang cao Website thong qua Y!M,MSN,AIM,My Computer
Phat Hanh: 20-9-2006

Imagine.. this worm has survived ever since! Despite the fact that it changes your home page to www.quicknews.info it also "spreads the word" in Yahoo messenger, AOL Instant messenger, MSN/Windows Live Messenger etc... thecoolpics.net is still alive.

A lot of antivirus software do not detect YMworm.exe, it's time they do!

Friday, July 06, 2007

Security: How to bypass antivirus detection

Megasecurity.org is a MEGA archive of malware information. Click here to find out the possible ways of bypassing an antivirus detection. I hope that this an old post and not applicable anymore, but to some new antivirus programmers "in town" this would be a great way to increase their program's protection level.

I'll quote just the contents:

I. Bypassing attachment detection or invalid detection of attachment
type.


1. Encoded filename or boundary in Content-Type/Content-Disposition
2. Multiple filename or boundary fields in Content-Type /
Content-Disposition
3. Exploitation of poisoned NULL byte
4. Exploitation of unsafe fgets() problem
5. MIME part inside MIME part
6. UUENCODE problems
7. Additional space symbol
8. CR without LF
9. Prohibited characters in the filename
10.Skipped file name
11.Endless UUEncoded messages
12.Different filenames for Content-Type and Content-Disposition
13.Case sensitivity of Content-Type and Content-Disposition

II. Bypassing detection of potentially dangerous content

1. Inability to check Unicode (UCT-2) content
2. Inability to check UTF-7 content
3. Inability to check file marked as UTF-7 Content
4. Inability to check content with short Content-Length

III. What should be done?


1. What client software vendor should do.
2. What server software vendors should do.
3. What system administrators should do.

It contains a lot of info of how users as well as software vendors should act against these incidents.

My suggestion? Gmail; it can be used to forward emails to another email address, hence used as a spam-blocking layer. Spam detection in Gmail is mostly user-guided, so if users set something as spam, it's done for others as well!

Tuesday, July 03, 2007

freewebhost.com: Bad abuse handling

I must say I'm not really satisfied with how freewebhost.com allows executable files hotlinked and even not checked with a simple antivirus utility (and there are several of them that are free of charge!). Why not check what your users upload? It could be hurtful to others.

I was looking through the caught spam of the day, when I stumbled upon an "interesting"(i.e. trojan/virus) link:
Jul 03 20:08:49
endys!Endys@3-109.la.cytanet.com.cy MSG!#cyprus
hey watch us army fuck iraqian girl ;s www.freewebtown.com/videozone/.........
(......... represent the file name)

I don't know if this user deliberately spammed that link, but it was very annoying, and risky for other persons on the same network/channel. Imagine some innocent first-timers joining, looking at that and thinking "oh goody, porn!" and *click*! Things on internet are not always what they seem to be. I said that before and I'll keep repeating it!

And some free webhost providers DO NOT SECURE THEIR SERVICES! Someone should write some complaints and make an RFC standard about providing free services without checking uploaded data for virus/malware. Sure you care, sure you say 'thank you' at abuse@ emails, but that's not good enough, at least for me; and I'm a person that cares!

Check out the results of several antivirus software against this file (virustotal.com, image hosted at bayimg.com)
You can have a look at the analysis of that file (analysis.seclab.tuwien.ac.at)

Wednesday, June 27, 2007

Warning: Undetected MSN messenger worm - pic901.com

Hopefully I won't get flagged for this, but it's my duty to warn people about the presence of living or computer virus.

Looking for a sexy 'behind'? Well not here! This is a VIRUS REPORT! The program is NOT DETECTED YET (check out the virustotal.com screenshot) at the time of writing!
likemyass.net (active)
ratethisphoto.net (purged)
ratethisface.net (purged)

I've discovered this while I was checking some links gathered with the help of an eggdrop script of mine
mwrouin-m-!~info@business-67-35.netway.com.cy MSG!#cyprus
hey check :O http://www.likemyass.net/.......

(....... have replaced the filename)
This malware is undetected by most antivirus at the time of writing, so watch it: likemyass.net = BAD

The dude above is not the spammer. The malware somehow is spammed through IRC instead of MSN. This malware/trojan/virus/worm/bad exe, whatever you might want to call it, is spreading around replacing the MSN executable.
Some of my friends believe that this is the 'new' Virtumonde. It might just use its registry keys, but the MSN spamming is a whole new thing I guess!

UPDATE: The website is now down!
UPDATE 2: The website has changed to http://la.gg/UPL/PIC901.COM (but it was down when I was notified)
UPDATE 3: Solutions 1) Vundofix 2) VundoBeGone 3) Uninstall,restart and reinstall MSN Messenger from here: http://g.msn.com/8reen_us/EN/INSTALL_MSN_MESSENGER_DL.EXE
4) Try out one of my generic cleaners, cwean pack: www.erroneous.name

You are encouraged to download the executable and upload it to www.virustotal.com or www.uploadmalware.com

More info about the lil' buger at the Kaspersky's website