SG Complains

Your Say, Your News, Your Complains!

Is username.is-thatt-you.com via MSN virus?

I had been receiving this comment from OFFLINE MSN messages that a single link with my user name and append with is-thatt-you.com behind.

I searched through the goggle and cannot find any details on this domain and quite curious about this message.

It’s obviously sent to me by my friend’s msn without them being online hence very likely to be a virus.

I had clicked once and request me to login using MSN username and password which I did not do it fortunately.

The problem might be they had been hit by the same message and login unknowingly and was infected.

So be very careful when you click on such links.

Read Also:

  1. EULA-gy for a Phishing Victim
Categories: Others
  • PuckCh
    Hello,

    same thing here. I have received this message this morning. Apparently from a friend. And right, he has received this message, and he has logged in. :-(

    The url I have received was like http://username.is-dat-u.com/, and for my friend, it was like yours.

    Another friend has received also the same message…

    So, be carefull… Don’t give your user/pass to a web site.
  • G-Prime
    i’ve been getting this one as well but there’s a 3rd address also

    http://emailaddy.datsyou.com
    http://emailaddy.is-thatt-you.com
    http://emailaddy.is-dat-u.com
  • Jerry
    I found this site aggravating aswell as many of my female msn contacts are quite.. gullible. IF YOU READ what the site says it explains everything, even though what they are doing is against the msn EULA.

    “By filling out this form, you authorize TST Management, Inc to spread the word
    about this 100% real and upcomming Messenger Community Site”

    “By using our service/website you hereby fully authorize TST Management, Inc to send messages
    of a commercial nature via Instant Messages and E-Mails on behalf of third parties via the information”

    “We may temporarily access your MSN account to do a combination
    of the following:
    1. Send Instant Messages to your friends promoting this site.
    2. Introduce new entertaining sites to your friends via Instant Messages.”
  • Mark
    Hey guys, I think if you tell your friend(s) to simply change their msn/hotmail password, everything should be fixed :)
  • Manu
    Hi,
    I’m french, and i’ve received the same thing like you. http://my username.is-thatt-you. Of course I didn’t log. I asked my friend who may send it, and she answered me it’s not her !!!! She will change name and password. Be careful everybody, BE CAREFUL !!!!!
    Friendly….
    (sorry if my english spoken is not good…Bye)
  • Olivier
    same message, same site and i am a french people
  • Anonymous
    Hello,

    I’m form Holland, and i’ve got the same problem. My norton says it is phishing…
  • Amelie
    Yeah, I’ve had this message too…
    Does any of you guys know what actually happens when you click on this link ?
  • Anonymous
    We got it also, a co worker, here in United States, California

    the link was: http://support.is-thatt-you.com/

    i called her over to take a look, and she said she did not send it.. looks like she got hacked. :(

    BEWARE!

    Here’s a screen cap of the site:
    http://i34.tinypic.com/2d7ymg3.jpg
  • Jon
    It’s spreading quickly, in the UK too. Told my friend to change his password and not be careless with his details.

    As the site said to log on I assume it’s only abusing the credentials it gains, and is not actually installing itself (or whatever) on people’s computers, my point being that I assume that by just changing your password you fix all the problems, and there’s no greater problem, can anyone confirm this?
  • Anonymous
    me too guys, I got the same problem few minutes ago!actually I’m in italy…it’s a chain that grows minute by minute ..fuck!..My advise is too install CCcleaner and make a deep analyse of cookies…sometimes these kind of virus are recognised as a normal cookie, but CCcleaner can delete them..
  • Anonymous
    username.is-that-you.com

    I was hit with 14 hours ago then with
    username.is-thatt-you.com

    Once again the user can not remember clicking on such a link, for this site to access address book and send off messages.

    this is the Only site that has any at all info of this issue.


    I created a post on microsft.com/technet in hopes of an answer

    http://forums.microsoft.com/technet/ShowPost.aspx?postid=3704866&isthread=true&siteid=17
  • Anonymous
    I got one too. It came from my boss IM and was first intrigued since maybe my boss was fooling around or something.

    I tried to click the link out of curiosity but the page seems to load really slow until it got forwarded to our site intranet. Which means its an illegal site so lucky me.

    I also checked the microsoft link provided by one who comment here but it seems that msn support are slow in giving feedback. I would suggest (to tommynz1975) to make a link here since there is a screenshot posted about the problem.
  • tommynz1975
    a poster has left the link

    http://www.darkreading.com/blog.asp?blog_sectionid=447&doc_id=160786&WT.svl=blogger2_1

    on the microsoft.com/tech/ link i previosly posted
  • kaon
    I just got one today too.
  • Patricia
    I’m in Brazil. I think I was using a macbook when I’ve received that link too. But, the link has been spreading, even with my msn turn off.
  • Anonymous
    Thanks for that info tommynz1975. Already read that site before it was posted on your thread (the one on MS forum).

    I was anticipating a word of response from the MS tech team itself but there is none so far. Guess they are really slow on their end lol.

    Well the best way would be not to use that phishing site at all so a word of warning to everyone else. Lets just hope this one spam/scam/whatever will be dealt with immediately.
  • Carlos Gaudie
    Just to add something, I’m in Brasil and yesterday, aug 4th, I received this offline message via SKYPE, from a friend who lives in Spain. Today I received another link: “username.myfriendsz.com” from the same friend and source. Then I came to google to check it out…