A Twitter virus shows up: StalkDaily

By CurtMonash on Sat, 04/11/09 - 5:31pm.

A Twitter virus has shown up.  Tweetstreams, including mine, send out the message:

Hey everyone, join www. StalkDaily. com. It's a site like Twitter but with pictures, videos, and so much more! :) 

(Of course, the URL link is live in the original.)

Update: Twitter now claims to have patched the hole that allowed the virus to spread. And I've posted a simpler version of the whole story.

Nobody seems to know yet exactly what is going on. is getting a lot of attention with advice to stop it, but basically just says "Change your password and clear your cookies and browser cache; that should work."

Some people are assuming the virus is contracted by actually visiting the site, but I'm sure I got it WITHOUT visiting the site.

I'll try to get more information here, in the main post or comment thread, when I can.

Edit: Mark Hawker is figuring out how this works, and updating the comment thread below. He's posting more detail yet in his own Twitter stream.

Edit: @pilot suggests disabling scripts via NoScript in FireFox.  But this has painful side effects.

Edit: @anowheels thinks clicking on the GangsterBoy Twitter account can cause infection -- and I did click there right before getting hit. The theory is plausible for other reasons.

Specifically, there's a profile broken in a way I haven't seen before, looking like:

View Source right now gives:

Edit: A Malwarebytes scan comes up with three instances of malware.  One is the Seneka rootkit (ouch!).  I don't immediately know whether all three boil down to that. The logfile is below. I've bolded selectively.

Malwarebytes' Anti-Malware 1.36
Database version: 1969
Windows 5.1.2600 Service Pack 3

4/11/2009 6:49:38 PM
Malwarebytes log mbam-log-2009-04-11 (18-49-21)

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 209851
Time elapsed: 34 minute(s), 30 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\cs41275 (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\seneka (Rootkit.Trace) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



Searching on Seneka rootkit turns up very different pages than searching on cs41275, so I suspect them of being two different infections.

As of this posting I haven't yet sorted out what to DO about these infections, but there's advice on the Web, especially about Seneka.

At a guess they're unrelated to StalkDaily, but I can't be sure at the moment.

On The Web