msn sender f@mily-williams

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by lupuskio, Dec 22, 2008.

  1. lupuskio

    lupuskio Private E-2

    Good evening,
    my msn just send to evereone from my list this ‘’haha h**p://family-williams.info/image.php? ‘’.
    What’s happend? And the most important how get rid of it???!!!
     
  2. Corporal Punishment

    Corporal Punishment Administrator Staff Member

    Ouch - Could be a general malware or specific to msn. Best to start here:


    Please begin by clicking Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.
    • Scroll down to “Non-plug and Play Drivers” and click the plus icon to open those drivers.
    • Then search forTDSSserv.sys
    • Let me know if you find this or not.
    • If you do find it, right click on it, and select Disable. Do not try to uninstall it.
    • Also if TDSSserv.sys is found and you disable it, then reboot.
    • After reboot continue on with the below cleaning instructions.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:
    1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. lupuskio

    lupuskio Private E-2

    Thank you for the advises,
    I run all the progs you suggested (my pc is in Greek) an nothing was found.
    The TDSSserv.sys is not present in my Non-plug and Play Drivers.
    The οdd thing is that happened only one time and send this auto message to few of my contacts. After that nothing happened.
    But the strange thing happened, when ever I trying to remote control my pc from logmein it freezes.
     

    Attached Files:

  4. lupuskio

    lupuskio Private E-2

    and the mglog
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi and welcome. We are currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Thanks for your patience during this time.

    Kestrel13!
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not seeing any malware in your logs, however, there is a little clean up to be done...


    1) I would like to address the fact that you are running a cracked anti-virus. You would be well advised to get rid of it, and use one of the many very good freeware anti-virus that are available for download. Using a crack to extend the license for Nod32 is going to compromise your security and the security of your computer, and this is something which should be a priority.



    2) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)

    After clicking Fix exit HJT.



    3) Now we need to use ComboFix to remove a file and some avg leftovers

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    
    KILLALL::
    
    File::
    C:\WINDOWS\System32\_r_a_p_.tmp
    
    Folder::
    C:\Documents and Settings\All Users\Application Data\Avg8
    C:\Program Files\AVG
    
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    4) Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    5) Now Run Ccleaner!

    6) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  7. lupuskio

    lupuskio Private E-2

    Good morning.
    Thank you, It’s great that you didn’t find any malware, but that happened when???
    And if my doesn’t have anything wrong with it for what purpose must I do the cleaning?
    As I said previously, the thing happened only once (send whose messages to my contacts and what was all)
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there...could you please attach the 2 requested logs:

    • MGlogs.zip
    • and the log from Combofix

    I would suggest that you create a new ID/fresh account and ditch the account that you have now. You should also tell your friends to block your account that is sending out the bad link(s) to ensure that they do not accidentally click any bad links
     
  9. lupuskio

    lupuskio Private E-2

    Hi, deleting my account is not an option or solution.
    I had already attached the requested logs but once more does not hurt.
    MGlogs
    Code:
    http://forums.majorgeeks.com/attachment.php?attachmentid=103641&d=1230575088
    ComboFixlogs
    Code:
    http://forums.majorgeeks.com/attachment.php?attachmentid=103638&d=1230575032
    my contacts are counting on me/us to find a solution.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If the problem only happened one time and is not happening anymore then there is nothing to do since your logs are basically clean. If you do not want to do the miscellaneous cleanup, that's your decision... and all we have left to do is the below unless you are experiencing any other malware problems:

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  11. lupuskio

    lupuskio Private E-2

    thank you so much
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're most welcome :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds