Well this trojan tried to fool me in Msn Messenger by sending me a message making me think that one of my contacts sent it. The message was [color=\"blue\"]omg this is funny![/color] <UrlHere/cute.pif> i didnt place the url cause i dont want no one to get infected. Heres some information on the trojan
A moderately dangerous Trojan horse that might let an outsider take over someone's computer is circulating by e-mail, two anti-virus companies warned Wednesday.
According to Symantec and McAfee, the e-mail in question has the subject line: "Thoughts..." with a message that reads, "I just found this program, and, I don't know why...but it reminded me of you. Check it out."
If the user is tricked into double-clicking the attachment, which carries the file name "cute.exe," the Trojan is installed on their PC.
Craig Schmugar, a virus researcher for McAfee's AVERT (anti-virus emergency response team), said the primary aim of this "back door" Trojan is to give the attacker a way to take control of the user's system.
"The person can move the mouse as if he was sitting in front of the computer, or make the CD-ROM drive door open and close," said Schmugar. "The program also tries to cripple anti-virus programs and firewalls."
Dee Liebenstein, product manager for Symantec Security Response, told Newsbytes the Trojan sends a message to the author with the IP (Internet protocol) address of the infected PC.
Symantec and McAfee describe the Trojan as a variant of the "Backdoor.Subseven" Trojan horse. Symantec named the Trojan W32.Tendoolf, while McAfee dubbed it W32/Floodnet@MM.
The two companies said they were watching it's spread closely, though they mark it as a low risk for now. McAfee's Schmugar said the Trojan has some characteristics that give it the potential to cause harm.
"Some Trojans have the ability to propagate," he said. "Floodnet has the ability to spread by different methods, including through a person's address book by e-mail, or by MSN Messenger or AOL Instant Messenger."
Schmugar and Liebenstein repeated the oft-told admonition - don't open attachments marked .EXE.
"Back door Trojans are a big risk to personal identification and information," said Schmugar. "Not only do we tell people not to double-click on .EXE attachments, we also are warning them to be alert to e-mails promising an immunity tool for viruses that is infected with the Klez virus."
"If you receive an anti-virus tool by e-mail, be leery," he added.
"The message in the e-mail that carries the cute.exe attachment is an example of social engineering," said Liebenstein. "Trojan horse writers try to get people to click on an attachment by getting on their good side and being friendly."
[url=\"http://www.wilderssecurity.com/showthread.php?t=1609\"]Source Were i got it From[/url]
[url=\"http://www.computeruser.com/news/02/05/09/news1.html\"]Original Source[/url]
New 'Cute' trojan could take over your PC
Moderators: Moderator, Global Moderator
New 'Cute' trojan could take over your PC
Last edited by LATIN on Mon Mar 07, 2005 8:48 am, edited 1 time in total.

New 'Cute' trojan could take over your PC
[color=\"green\"]yeah..i had something like this <img src=\'http://www.killanet.net/forum3/public/s ... el_not.gif\' class=\'bbc_emoticon\' alt=\'(not)\' /> ..i just went to [url=\"http://www.symantec.com\"]http://www.symantec.com[/url] and followed their instructions, cant remember what it was called though <img src=\'http://www.killanet.net/forum3/public/s ... #>/cry.gif\' class=\'bbc_emoticon\' alt=\':(\' /> lol [/color]
New 'Cute' trojan could take over your PC
This was also posted on mess.be news, pretty much the same information about how it's sent etc..
[quote name=\'Mess.be\'][url="http://mess.be"]source[/url]
Judging from the reports, a probable new Bropia variant is spreading over MSN Messenger like wildfire. If you receive a message similar to: "omg this is funny!" followed by a hyperlink to cute.pif (located at a random domain) do NOT click the link and inform the sender he or she is infected. You can take it as a general rule never to accept or click .pif files.[/quote]
[quote name=\'Mess.be\'][url="http://mess.be"]source[/url]
Judging from the reports, a probable new Bropia variant is spreading over MSN Messenger like wildfire. If you receive a message similar to: "omg this is funny!" followed by a hyperlink to cute.pif (located at a random domain) do NOT click the link and inform the sender he or she is infected. You can take it as a general rule never to accept or click .pif files.[/quote]
Last edited by Josh on Mon Mar 07, 2005 12:30 pm, edited 1 time in total.
[align=center]

“If you stop learning, you stop living.” ~Tami Quiring
“It's the rare man who understands the value of a single perfect rose.”
[/align]

“If you stop learning, you stop living.” ~Tami Quiring
“It's the rare man who understands the value of a single perfect rose.”
[/align]
New 'Cute' trojan could take over your PC
The reason why it spreads is because of gullibility and mainly stupidity. Nonetheless, I never accept .pif files and I've told several people already that they are infected.


