I just got an IM from a friend on my MSN messenger account that appears to be some sort of backdoor IRC bot.
(05:18:39 PM) UnamedFriend: Hey, isn’t this YOU?? :S http://mainmsn.com/images/viewimage.php?=myusername@hotmail.com
(05:30:55 PM) Jordan: Are you there?
(05:35:35 PM) Jordan: I think you might be infected with a virus
I changed the above url to www.virustotal.com’s antivirus scan of the file.
Needless to say, I’m trying to contact that friend and let them know about their computer’s actions.
Update:
I attempted to contact the domain registrant of mainmsn.com via the whois contact info and the message bounced. I am now attempting to contact the company that mainmsn.com is using for its name servers. I also submitted the URL to Google’s Safe Browsing: Report a malware page